| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise Plus,
Industrial OT, or Medical)
Device Security X subscription
One of the following Cortex XSOAR setups:
A free, cohosted, limited-featured
Cortex XSOAR instance
A full-featured Cortex XSOAR server
|
The following are prerequisites for setting
up ServiceNow for integration with Device Security:
A
configured ServiceNow instance with administrative access
A ServiceNow user account that XSOAR will use to form a secure connection with the ServiceNow
instance and send it device attributes, security alerts, and
vulnerabilities
Your ServiceNow URL
When configuring the
ServiceNow instance on XSOAR, you need to enter the
username and password of the ServiceNow user account and the ServiceNow
URL.
On your ServiceNow instance, you must set up one or two tables, depending
on which method you use to map device attributes from Device Security to
ServiceNow.
If you map device attributes into a ServiceNow table, you need two
tables: one to receive device records and another to receive incidents from
Device Security. For ServiceNow to receive device records, you can
either modify an existing table or create a new one. For ServiceNow to
receive security incidents, you must create a new table.
If you map device types, categories, or profiles from Device Security to ServiceNow classes, then you only need to create a new
table to receive security incidents.
ServiceNow configuration instructions are based on Newyork build, 11-04-2020_1502 and
Tokyo build, 12-11-2023_2153.