Vulnerability Response Integration with Claroty CTD
The Vulnerability Response Integration with Claroty Continuous Threat Detection (CTD) uses vulnerability data imported from Claroty CTD to enable risk-based action within the production process.
Use this Vulnerability Response Integration with the ServiceNow® Operational Technology Vulnerability Response application to track, prioritize, and resolve vulnerabilities used in the production process.
Before you run the Vulnerability Response Integration with Claroty CTD, you must run the National Vulnerability Database (NVD) integration. The NVD integration fetches published Common Vulnerabilities and Exposures (CVEs) from the NVD and populates them in ServiceNow. Then when you run the Vulnerability Response Integration with Claroty CTD application, the application identifies the vulnerabilities for each device and creates vulnerable items (VITs).
Each VIT has a relationship with an Operational Technology (OT) device, or Configuration Item (CI), and the vulnerability that's detected. The vulnerability integration framework establishes a connection with the Claroty Enterprise Management Console (EMC) and pulls the vulnerabilities for all OT devices.
Note: The Claroty CTD EMC platform insights API has a limitation of 10 CVEs. Therefore, only 10 CVEs are provided to ServiceNow by Claroty. However, the xDome platform doesn't have this limitation.
Key features
- Import common vulnerabilities and exposures (CVEs) associated with Operational Technology (OT) devices from Claroty CTD. Create vulnerable items (VITs) to provide a single view of OT device vulnerability data and how it affects the production process.
- Run imports of newly detected vulnerabilities automatically on your own schedule.
Use assignment rules to route VITs automatically for remediation to local site-based teams that can take risk-based actions.
Install Vulnerability Response Integration with Claroty CTD
Install the Vulnerability Response Integration with Claroty CTD (sn_clarotyctdvr). The application includes installs related ServiceNow® Store applications and plugins if they aren’t already installed.- Assign Vulnerability Response Integration with Claroty CTD roles
Assign roles to your users so that you can control their access to the features, capabilities, and data in the Vulnerability Response Integration with the Claroty CTD application. - Run the National Vulnerability Database integration
Run the National Vulnerability Database (NVD) integration to import data from the National Institute of Standards and Technology (NIST) NVD product. Running the NVD integration helps you determine the severity and details of Common Vulnerabilities and Exposures (CVEs) found in your environment. - Configure the Vulnerability Response Integration with Claroty CTD
Configure the Vulnerability Response Integration with Claroty CTD to begin importing data. - Set the system properties installed for the Vulnerability Response Integration with Claroty CTD
Set the system properties for the Vulnerability Response Integration with Claroty CTD so that you can enable the properties as needed. - Data mapping for the Vulnerability Response Integration with Claroty CTD
This section specifies how fields from the Claroty CTD API are mapped to fields in the ServiceNow tables. - Errors for the Vulnerability Response Integration with Claroty CTD
You may encounter errors that need troubleshooting while you’re working with the Vulnerability Response Integration with Claroty CTD.
Parent Topic:Operational Technology Vulnerability Response Integrations