ServiceNow CIS Vulnerability Response
Vulnerability Response - Answer-The process of identifying, classifying, remediating and mitigating
vulnerabilities.
Vulnerability - Answer-Any weakness that allows exploitation or allows an attacker to further reduce
security posture.
Patch Management - Answer-Process to manage the pushing of fixes or patches to systems. Directly
related to Vulnerability Response.
National Vulnerability Database (NVD) - Answer-Online repository of vulnerability management data,
security checklists, security related software flaws, misconfigurations, product names, and impact
metrics.
Common Vulnerabilities and Exposures (CVE) - Answer-A dictionary of publicly known security
vulnerabilities and exposures.
Common Vulnerabilities Scoring System (CVSS) - Answer-An open framework for communicating the
characteristics and severity of software vulnerabilities.
, Common Weakness Enumeration (CWE) - Answer-A list of software weaknesses.
Vulnerability Entry - Answer-Records of potentially vulnerable software downloaded from the NIST
NVD.
Vulnerability Entry table - Answer-sn_vul_entry
Vulnerable Item - Answer-Pairings of vulnerability entries and potentially vulnerable configuration
items. A single record that captures all collateral related to the vulnerability.
May belong to more than one Vulnerability Group.
Vulnerable Item table - Answer-sn_vul_vulnerable_item
Note: prior to Kingston it was extended from task table.
Vulnerability Group table - Answer-sn_vul_vulnerability
Note: extended from task table
National Vulnerability Database Entry - Answer-NIST (CVE) vulnerabilities imported from third-party.
National Vulnerability Database Entry table - Answer-sn_vul_nvd_entry
Note: extends sn_vul_entry
Third Party Vulnerability Entry - Answer-Vulnerabilities from third parties such as Qualys or Tenable.
Third Party Vulnerability Entry table - Answer-sn_vul_third_party_entry
Note: extends sn_vul_entry
Vulnerability Response - Answer-The process of identifying, classifying, remediating and mitigating
vulnerabilities.
Vulnerability - Answer-Any weakness that allows exploitation or allows an attacker to further reduce
security posture.
Patch Management - Answer-Process to manage the pushing of fixes or patches to systems. Directly
related to Vulnerability Response.
National Vulnerability Database (NVD) - Answer-Online repository of vulnerability management data,
security checklists, security related software flaws, misconfigurations, product names, and impact
metrics.
Common Vulnerabilities and Exposures (CVE) - Answer-A dictionary of publicly known security
vulnerabilities and exposures.
Common Vulnerabilities Scoring System (CVSS) - Answer-An open framework for communicating the
characteristics and severity of software vulnerabilities.
, Common Weakness Enumeration (CWE) - Answer-A list of software weaknesses.
Vulnerability Entry - Answer-Records of potentially vulnerable software downloaded from the NIST
NVD.
Vulnerability Entry table - Answer-sn_vul_entry
Vulnerable Item - Answer-Pairings of vulnerability entries and potentially vulnerable configuration
items. A single record that captures all collateral related to the vulnerability.
May belong to more than one Vulnerability Group.
Vulnerable Item table - Answer-sn_vul_vulnerable_item
Note: prior to Kingston it was extended from task table.
Vulnerability Group table - Answer-sn_vul_vulnerability
Note: extended from task table
National Vulnerability Database Entry - Answer-NIST (CVE) vulnerabilities imported from third-party.
National Vulnerability Database Entry table - Answer-sn_vul_nvd_entry
Note: extends sn_vul_entry
Third Party Vulnerability Entry - Answer-Vulnerabilities from third parties such as Qualys or Tenable.
Third Party Vulnerability Entry table - Answer-sn_vul_third_party_entry
Note: extends sn_vul_entry