Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Unified Vulnerability Response Dashboard

The Unified Vulnerability Response dashboard provides a comprehensive view of an organization's vulnerabilities and risks. The vulnerabilities related to infrastructure, cloud, applications, and containers can be viewed in a centralized dashboard for better visibility and remediation.

Watch this four-minute video to learn about the Unified Vulnerability Response Dashboard.[Omitted video] Description: Unified Vulnerability Response Dashboard

Required ServiceNow AI Platform roles

The following roles are associated with this solution. They’re required for viewing, editing, and sharing the reports:

  • sn_vul.app_sec_manager
  • sn_vul.vulnerability_admin
  • sn_vul.vulnerability_analyst
  • sn_vulc.admin
  • sn_vul_container.vulnerability_admin
  • sn_vul_container.vulnerability_analyst
  • sn_vul.app_developer
  • sn_vulc.vulnerability_analyst

Access the Unified Vulnerability Response Dashboard

To open the dashboard, navigate to either:

  • All > Vulnerability Response > Vulnerability Manager Workspace and select the Dashboards icon. Depending on your role, the default dashboard is displayed. To view the Unified Vulnerability Response Dashboard, select the drop-down next to the dashboard name.
  • Workspaces > Platform Analytics Workspace > Dashboards > Unified Vulnerability Response Dashboard.
Image omitted: vr-unified-dashboard.png
Unified Vulnerability Response dashboard

Use cases

For examples of how different people in your organization would use this dashboard, see these use cases.

UsersDashboard use
- Vulnerability Managers - Vulnerability Analysts- Provides real-time visibility of the risks present in infrastructure, applications, configurations, and containers. Enables Vulnerability Managers and Vulnerability Analysts to prioritize and remediate the vulnerabilities in a timely way. - Provides an Attack Surface Overview of critical assets, which can be used to track the remediation progress and efforts. - Provides an overview of risks across business units \(BUs\). You can use filters to select BUs and compare the progress to reallocate resources, as necessary. Role-level access must be provided to the BU head. - Provides visibility into the potential impact by BUs. You can use the Common Vulnerability and Exposure \(CVE\) filter to identify exposures across the organization. - Provides visibility into the EPSS scores attained by vulnerable entries that exist in the CISA KEV catalog for Application, Host, and Container vulnerable items.

Unified Vulnerability Response Dashboard tabs

This dashboard lets you see the vulnerabilities or issues that are present in hosts, cloud, configurations, applications, and containers. You can view the vulnerabilities based on the business unit, assignment group, risk rating, criticality, and whether an exploit exists for the vulnerabilities.

The Asset Overview tab provides the overall status of configuration items (CIs) in the system.

Image omitted: vr-ws-ud-asset-overview.png
Asset Overview tab

The Vulnerability Overview tab provides a status on the types of vulnerabilities such as host, application, container.

Image omitted: vr-ws-ud-vulnerability-overview.png
Vulnerability Overview tab

The Assignment Overview tab provides a status on the assignment of the vulnerabilities.

Image omitted: vr-ws-ud-assignment-overview.png
Assignment Overview tab

The Exception Management tab provides a status on the deferred vulnerabilities.

Image omitted: vr-ws-ud-exception-management.png
Exception Management tab

The Service Level Agreement (SLA) tab provides a status on the service level agreement attained by different assignment groups.

Image omitted: vr-ws-ud-SLA.png
Service level Agreement SLA tab

The Exclusion overview tab provides a status of exclusion rules you have created, as well as those affecting detections that are internet-facing and have available exploits.

Image omitted: vr-ws-ud-exclusion.png
Exclusion overview tab

The Vulnerability Intelligence tab provides a status on the EPSS scores attained by vulnerabilities having the CISA KEV flag true and EPSS Score >= 0.9 for Application, Host, and Container Vulnerable items.

Image omitted: vr-ws-ud-vuln-intelligence.png
Vulnerability Intelligence tab

Filters

You can filter the widgets based on the following:

  • Business unit
  • Assignment group
  • Risk rating
  • Criticality of assets
  • Internet facing
  • Exploit exists

When a filter is selected, the data in all widgets gets updated. However, if a filter is not applicable for a widget, a cross symbol is shown next to the filter name.

Note: Only Business unit and Assignment group filters are available in Tokyo. All the filters are available from Utah onwards.

Indicators

  • Scanned assets

    Formula indicator for assets scanned in the last 60 days. Contains scanned discovered item assets, scanned application release assets, scanned discovered container image assets as contributing indicators.​

  • Assets - Exploit exists

    Formula indicator for assets where exploit exists in the vulnerabilities. Contains Host assets - Exploit exists, Application assets - Exploit exists, Container assets - Exploit exists as contributing indicators.​

  • Infra Asset - Internet Facing

    Indicator for fetching the count of assets, which are internet facing.

  • Discovered items based on Cloud Resource type

    Indicator for fetching the count of assets having an asset category such as cloud.​

  • Base Images

    Indicator for fetching the count of base images​.

  • CISA KEVs Asset Type

    Formula indicator, which gives the count of container and host vulnerable items where the vulnerability has the CISA KEV (BOD 22-01) flag set to true. Contains CISA exists CVR, and CISA exists Vul Items as contributing indicators.

  • CISA Exists Vulnerable Items – Unassigned

    Formula indicator, which gives the count of container and host vulnerable items where the vulnerability has the CISA KEV (BOD 22-01) flag set to true and the vulnerable items are unassigned. Contains Unassigned Container Vul Items, Unassigned Host Vul Item as contributing indicators.

  • CISA Exists Vulnerable Items - Target Missed

    Formula indicator, which gives the count of container and host vulnerable items where the vulnerability has the CISA KEV (BOD 22-01) flag set to true and the vulnerable items have missed the target. Contains CISA exists Vul Items, CISA exists CVR as contributing indicators.

  • Active Host VITs

    Count of active host vulnerable items (VITs).

  • Active Application VITs

    Count of active application vulnerable items (AVITs).

  • Active Container VITs

    Count of active container vulnerable items (CVITs).

  • New VITs

    Count of VITs that opened on a day.

  • New AVITs

    Count of AVITs that opened on a day.

  • New CVITs

    Count of CVITs that opened on a day.

  • New Test Results

    Count of test results (TRs) that were created on a day.

  • Closed AVITs

    Count of VITs closed on a day.​

  • Closed VITs

    Count of AVITs closed on a day.

  • Closed CVITs

    Count of CVITs closed on a day.

  • Closed Test Results

    Count of TRs closed on a day.

  • Open Config Issues - Test results

    Count of all open test results, which are in failed state.

  • Organization Risk Score

    Risk score of an organization from the Rollup Application Risk Score table.

  • Unassigned Application Vul Item

    AVITs with no assignment group or assigned to.

  • Unassigned Host Vul Item

    VITs with no assignment group or assigned to.

  • Unassigned Container Vul Items

    CVITs with no assignment group or assigned to.

  • Unassigned Config Issues

    TRs with no assignment group or assigned to.

  • Deferred VITs

    VITs in deferred state.

  • Deferred AVITs

    AVITs in deferred state.​

  • Deferred CVITs

    CVITs in deferred state.

  • Host SLA - Closed

    Average age closed of closed VITs.​

  • Application SLA - Closed

    Average age closed of closed AVITs.​

  • Container SLA - Closed

    Average age closed of closed CVITs.​

  • Test Result SLA - Passed

    Average age closed of passed TRs.​

  • Host SLA - Closed (Critical & High)

    Average age closed of closed critical and high VITs.

  • Application SLA - Closed (Critical & High)

    Average age closed of critical and high AVITs.​

  • Container SLA - Closed (Critical & High)

    Average age closed of closed critical and high CVITs.​

  • Test Result SLA - Passed (Critical & High)

    Average age closed of passed critical and high TRs.​

  • Aggregate MTTR

    Average age closed of closed VITs, AVITs, CVITs, and TRs.​

  • SLA Missed

    Average age closed of closed and target missed VITs, AVITs, CVITs, and TRs.

  • Vulnerabilities With EPSS Scores >= 0.9

    Count of vulnerability entries with EPSS scores greater than or equal to 0.9.

Breakdowns

  • VIT type (unified)
  • Internet Facing (unified)
  • Risk Rating (unified)
  • Exploit Exists (unified)
  • Discovered Item Cloud Resource Type (unified)
  • CISA Exists (unified)
  • CMDB class (unified)
  • Business Unit (unified)
  • Business Criticality (unified)
  • Deferred Reason (unified)
  • Assignment group (unified)
  • Remediation Status (unified)

Data visualizations

TitleTypeDescription
Attack Surface OverviewSingle score
Image omitted: single-score.png
Single score
Number representing the aggregated score of an organization's security.
CMDB CI CountSingle score
Image omitted: single-score.png
Single score
Number of CIs in the organization that are registered and tracked in the Configuration Management Database \(CMDB\). Provides a breakdown of the following CIs:- Scanned CIs: Number of scanned CIs - Exploit: Number of exploits available - Internet Facing: Number of internet facing CIs
Cloud ResourceSingle score
Image omitted: single-score.png
Single score
Number of CIs with asset category such as cloud. Provides a breakdown of the following cloud assets:- AWS - Azure - GCP
Docker ImageSingle score
Image omitted: single-score.png
Single score
Number of docker images including the number of base images.
ApplicationsSingle score
Image omitted: single-score.png
Single score
Number of applications in the organization.
TitleTypeDescription
CISA KEVsPie ChartNumber of vulnerabilities associated with the CISA catalog and CISA flag as true. Provides a breakdown based on the following:- CISA Vulnerability: Types of vulnerabilities with CISA flag as true - Host CIs - Internet Facing: Internet facing CIs - Unassigned VITs: Unassigned VITs with CISA flag as true - VITs missed target: VITs that missed target with CISA flag as true
Active Vulnerabilities by CriticalityStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Number of active VITs, AVITs, and CVITs based on criticality.
Vulnerability creation and closure trendMultiple Line
Image omitted: line-multiple.svg
Multiple Line
Number of new and closed vulnerabilities for all applications. Provides a trend for the last three months.
Misconfiguration by cloud platformMultiple Line
Image omitted: line-multiple.svg
Multiple Line
Number of configuration issues based on risk rating for each cloud asset.
Cloud ComplianceTableList of resources with the asset category as cloud along with the following details:- Resource name - Class - Vulnerability issues: Number of issues present in the resource that are aggregated based on the risk rating. - Configuration issues: Number of resources with configuration issues along with the risk rating. - Cloud account: Cloud account ID. - Cloud region: Location of the cloud resources. - Cloud provider: Name of the cloud provider.
TitleTypeDescription
Unassigned VITsStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Number of vulnerabilities that aren’t assigned to any group or individual along with the risk rating.
MTTR by Assignment Group - Top 10Multiple Line
Image omitted: line-multiple.svg
Multiple Line
Mean time taken by an assignment group to identify and remediate the security vulnerabilities or issues. The top 10 assignment groups are displayed that have the highest mean time for remediation.
Top 10 Assignment Groups missing SLA \(Critical & High Vulnerability\)Stacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Top 10 assignment groups that missed the target date of remediation of critical and high vulnerabilities.
TitleTypeDescription
Deferred VITsStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar|Number of vulnerabilities in the deferred state based on risk rating.|

|Critical and High Deferred VITs by Assignment Group|Stacked Bar

Image omitted: stacked-column-bkdown-icon.png
Stacked Bar|Number of vulnerabilities with critical and high risk ratings in the deferred state that is categorized based on the assignment groups.|
TitleTypeDescription
Host Vulnerability: SLA attainment by assignment groupMultiple Line
Image omitted: line-multiple.svg
Multiple Line
Time taken by an assignment group to remediate host vulnerabilities. Provides a trend for the last 10 months.
Compliance Issues: SLA attainment by assignment groupMultiple Line
Image omitted: line-multiple.svg
Multiple Line
Time taken by an assignment group to remediate compliance issues. Provides a trend for the last 10 months.
Application Vulnerability: SLA attainment by assignment groupMultiple Line
Image omitted: line-multiple.svg
Multiple Line
Time taken by an assignment group to remediate application vulnerabilities. Provides a trend for the last 10 months.
Container Vulnerability: SLA attainment by assignment groupMultiple Line
Image omitted: line-multiple.svg
Multiple Line
Time taken by an assignment group to remediate container vulnerabilities. Provides a trend for the last 10 months.
TitleTypeDescription
Exclusion rulesTableList of all exclusion rules you have created.
Exclusion rules v/s Internet facingStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Exclusion rules impacting detections which belong to internet facing assets.
Exclusion rules v/s Exploit existsStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Exclusion rules impacting detections that are vulnerable to existing exploits.
TitleTypeDescription
Vulnerabilities with EPSS Score>= 0.9TableComplete list view of all vulnerable entries \(CVEs or TPEs\) that have an EPSS score greater than or equal to 0.9 along with the following details.- ID: CVE ID of the vulnerability - EPSS Score - EPSS Last Modified - CISA KEV BOD 22-01: Indicates if the entry exists in the CISA KEV BOD \(Binding Operational Directive 22-01\) - Total VIs: Total count of VIs that exist for this vulnerability entry. - Total Container VIs: Total count of container VIs that exist for this vulnerability entry. - Severity
External Facing Host Vulnerable Items With EPSS Score >= 0.9Single score
Image omitted: single-score.png
Single score
Number indicating the aggregate count of external facing host vulnerable items with an EPSS score greater than or equal to 0.9. Provides single scores sorted by severity of risk rating.
External Facing Host Vulnerable Items By Risk RatingStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Number of external facing host vulnerable items by risk rating. The stack bars are categorized by EPSS Score >=0.9 and CISA KEV =True.
Vulnerable Items With EPSS Score >= 0.9 By Risk RatingStacked Bar
Image omitted: stacked-column-bkdown-icon.png
Stacked Bar
Number of vulnerabilities with EPSS score greater than or equal to 0.9 sorted by risk rating. Provides a breakdown by host vulnerable items, application vulnerable items, and container vulnerable items.

Scheduled jobs for data collection

Data collection jobs automatically collect scores for automated indicators and breakdowns. The following scheduled jobs are run to collect scores on new data automatically.

Warning: By default, the following data collection jobs are deactivated in the base system:

  • Unified Dashboard Daily Data Collection
  • Unified Dashboard Weekly Data Collection
  • Unified Dashboard Historical Data collection

Before enabling the jobs, refer to the KB.

Scheduled jobFrequencyDescription
Unified Dashboard Historical Data collectionOnceCollects scores and snapshots for existing records.
Unified Dashboard Weekly Data CollectionWeeklyCollects data weekly.
Unified Dashboard Daily Data CollectionDailyCollects data everyday.
Rollup Risk scores to OrganizationDailyCollects the aggregated risk score for an organization.
Populate cloud compliance daily countsDailyCollects data for cloud compliance.
EPSS Daily JobDailyCollects EPSS data from First.org.

A new table Rollup Application Risk Score [sn_vul_cmn_rollup_app_risk_score] is created in the Vulnerability Common Scope. This table is populated using the following rollup calculators via the scheduled jobs everyday.

Rollup calculator nameDescription
Organization Risk Score RollupRolls up the risk scores for all vulnerable items and configuration issues in an organization. It provides an overall risk score for an organization.
Vulnerable Item RollupRolls up the risk scores for all vulnerable items in an organization, to contribute to the overall risk score of an organization.
Application Vulnerable Item RollupRolls up the risk scores for all application vulnerable items in an organization, to contribute to the overall risk score of an organization.
Container Vulnerable Item RollupRolls up the risk scores for all container vulnerable items in an organization, to contribute to the overall risk score of an organization.
Test Result RollupRolls up the risk scores for all test results in an organization, to contribute to the overall risk score of an organization.
Rollup EPSS Scores from NVDs to TPEsRolls up EPSS Scores from NVDs to TPEs, to contribute to the overall risk score of an organization.