Use SecurityScorecard Connectors to import external vulnerability findings into ServiceNow Vulnerability Response (VR). Imported findings appear as Vulnerable Items (VITs), so your teams can triage and remediate them in existing ServiceNow workflows. For an overview of the integration, see ServiceNow Vulnerability Response (VR) integration.
Data flows in one direction, from SecurityScorecard to ServiceNow. Changes you make to Vulnerable Items in ServiceNow are not sent back to SecurityScorecard. Continue to manage the finding and its remediation status in SecurityScorecard.
Before you begin
Confirm that you have the following requirements. The integration supports the Xanadu, Yokohama, and Zurich ServiceNow releases.
| Area | Requirement |
| ServiceNow | System Administrator access, or the roles required to install and configure applications. |
| ServiceNow | The Vulnerability Response plugin (com.snc.sn_vul) is enabled. |
| ServiceNow | A supported ServiceNow release. |
| SecurityScorecard | Access to the SecurityScorecard Marketplace. |
| SecurityScorecard | A SecurityScorecard API key. Create a dedicated bot-user API token instead of using a personal token, because regenerating a personal token cancels the old one and can break the connector. See Create API tokens for the SecurityScorecard platform. |
| SecurityScorecard | The domains for which you want to synchronize findings. |
Connect SecurityScorecard
Authorize SecurityScorecard as the data source, then copy the credentials that you need for ServiceNow.
- In SecurityScorecard, go to Automation > Integrations to open the Marketplace.
- Search for and select ServiceNow Vulnerability Response.
- Select Connect.
- Enter your SecurityScorecard API key when prompted, and complete the source connection.
- Locate the Client ID and Client Secret that SecurityScorecard Connectors displays.
- Copy both values. The Client Secret might appear only once, so copy it before you leave the page.
- Store both values in an approved password manager.
Treat the Client Secret as sensitive. Do not include it in screenshots, tickets, chat messages, source control, or browser recordings.
Install the ServiceNow application
- Follow the ServiceNow Store listing instructions to install the SecurityScorecard Vulnerability Response Integration application and enable any required prerequisites.
- Confirm that Vulnerability Response (
com.snc.sn_vul) is active in your ServiceNow environment. - Continue with the SecurityScorecard configuration in this article.
Create an integration user (optional)
You can configure the integration with your own administrator account. Create a dedicated integration user if your organization separates administrative and integration responsibilities.
- In ServiceNow, go to Organization > Users > New.
- Enter the user ID, first name, last name, and email address.
- Select Submit.
- Open the new user and select Roles > Edit.
- Assign the following roles, and then select Save.
sn_vul.configure_integrationssn_vul.app_configure_integrationssn_vul.app_read_assignedsn_sec_int.adminx_sesri_ssc_vul.admin
Configure the ServiceNow connection
- Go to SecurityScorecard VR Integration > Configuration.
- Open the configuration that the application creates, or select New.
- Complete the fields in the following table.
- Select Save and Test.
- Confirm that the connection test completes successfully.
| Field | Value | Required |
| Name | Enter a unique name for the configuration. | Yes |
| Active | Enable the configuration to allow synchronization. | Yes |
| Base URL | https://connectors.securityscorecard.io |
Yes |
| Client ID | Enter the Client ID from SecurityScorecard Connectors. | Yes |
| Client Secret | Enter the Client Secret from SecurityScorecard Connectors. | Yes |
| Domains | Enter the domains to synchronize. Separate multiple domains with commas. | Yes |
| Issue Types | Select the issue types to import. Leave this field empty to include all supported issue types. | No |
| Severities | Select Critical, High, Medium, or Low. Leave this field empty to include all severities. | No |
Run and schedule synchronization
| Task | Steps |
| Run a synchronization immediately | Go to SecurityScorecard VR Integration > Integrations. Open the integration that matches your configuration, and then select Execute Now. |
| Schedule recurring synchronization | Open the integration configuration. Change Run from On Demand to Daily or Weekly, set the execution time, and then select Update. |
Verify imported findings
- In ServiceNow, go to Vulnerability Response > Vulnerable Items > All.
- Filter the list by Source = SecurityScorecard.
- Open an imported Vulnerable Item and verify its domain, severity, issue type, and supporting attributes.
SecurityScorecard identifiers prevent duplicates, so later synchronizations update existing findings instead of creating new ones.
To display additional SecurityScorecard details on a Vulnerable Item, open an imported item and select Configure > Related Lists. Add SecurityScorecard Attributes > Vulnerable Item, and then select Save. You typically complete this step once per ServiceNow instance.
Troubleshoot issues
| Problem | What to check |
| Authentication error | Verify the Client ID, Client Secret, and Base URL. Confirm that you copied the credentials without extra spaces and that the integration user has the required roles. |
| No findings are imported | Confirm that the configured domains are monitored in SecurityScorecard. Check that the severity and issue type filters are not too restrictive. |
| Synchronization times out | Narrow the domain, severity, or issue type filters. Confirm that your ServiceNow instance can reach the SecurityScorecard endpoint over the network. |
| Duplicate findings appear | Confirm that the integration uses the same configuration and that existing findings keep their SecurityScorecard identifiers. Review the integration logs. |
| The default integration record is deleted | The application provides one integration record per ServiceNow instance. Reinstall the application to restore it if you cannot recover the record. |
| The connection test fails after credential rotation | Retrieve the current credentials from SecurityScorecard Connectors, update the ServiceNow configuration, and run Save and Test again. |
OAuth2 access tokens refresh automatically when they expire, and the integration stores the Client Secret securely.