Skip to main content

ServiceNow Integration

Applies to:
ServiceNow CMDBSecurity OperationsREST APIIncident ManagementChange Tracking
Sync runs inside DuoKey Cockpit

Publishing findings to ServiceNow is configured and executed inside DuoKey Cockpit against a saved scan result. Any dke-scanner-agent servicenow ... command shown below illustrates the publishing concept but is not a real CLI subcommand — the real, current CLI surface (filesystem, domain, inventory, source-code, ci, cbom, …) is documented in the CLI Reference; the CMDB CI-linking flags (--ci-id, --ci-name, --environment, …) shown further below on this page are real and available on the scan commands.

Architecture Overview​

The scanner reports all findings, vulnerabilities, and compliance status to a comprehensive ServiceNow dashboard through REST API integration. This enables security teams to track, prioritize, and remediate cryptographic risks within their existing ServiceNow workflows.

PQC Scanner to ServiceNow Dashboard Integration

TLS Endpoint Scanner

Scans network endpoints, detects TLS versions & cipher suites

CBOM Generator

Tracks cryptographic libraries like OpenSSL, BouncyCastle, MS CNG

Source Code Scanner

Detects vulnerable crypto functions with file paths & line numbers

Certificate Inspector

X.509 certificate analysis, algorithm & key size detection

ServiceNow Dashboard Panels

Vulnerability Overview

Visual representation by severity with priority indicators

Compliance Status

NIST PQC, BSI TR-02102, CNSA 2.0 readiness scores

Asset Inventory

Endpoints, certificates, keystores, crypto library dependencies

Action Items

Prioritized remediation tasks with automated ticket creation

Key Integration Features​

Real-Time Data Synchronization​

Automated Reporting

  • Scan results automatically pushed to ServiceNow via REST API
  • Real-time updates as new vulnerabilities are discovered
  • JSON-formatted data for seamless integration
  • Configurable sync frequency (continuous, scheduled, or on-demand)

Data Flow Architecture

  • Scanner Components - Comprehensive cryptographic discovery
  • Results Aggregation - Consolidate findings from all modules
  • API Layer - Transform and transmit data to ServiceNow
  • Dashboard - Display, track, and manage findings

ServiceNow Dashboard Capabilities​

  • Visual representation of quantum-vulnerable assets by severity
  • Critical findings (RSA-1024, DSA-1024) highlighted with HIGH priority
  • Medium-term risks (RSA-2048, ECC P-256) tracked for planning
  • PQC migration progress monitoring with status indicators

Dashboard Screenshots​

Vulnerability Dashboard​

ServiceNow Vulnerability Dashboard

The main dashboard provides an at-a-glance view of your organization's cryptographic posture, highlighting critical vulnerabilities and compliance status.

Compliance Report View​

ServiceNow Compliance Report

Detailed compliance reporting shows alignment with industry standards and regulatory requirements, with drill-down capabilities for specific findings.

Scan Results Interface​

ServiceNow Scans Report

Individual scan results are tracked with full context, including affected systems, vulnerability details, and recommended remediation steps.

Integration Configuration​

Prerequisites​

Prerequisites

  • ServiceNow instance with Security Operations module
  • API credentials (OAuth 2.0 or Basic Authentication)
  • Custom table creation permissions
  • Workflow designer access (for automation)
  • PQC Scanner version 1.0 or higher
  • Network connectivity to ServiceNow instance
  • API endpoint configuration
  • Authentication credentials properly configured

Setup Steps​

1

Configure ServiceNow Custom Tables

  • Create custom tables for PQC scan results
  • Define fields for vulnerability data, compliance metrics
  • Set up relationships between tables
2

Generate API Credentials

  • Create ServiceNow API user account
  • Generate OAuth tokens or API keys
  • Configure appropriate permissions and roles
3

Configure Scanner Integration

  • Update scanner configuration with ServiceNow endpoint
  • Add authentication credentials
  • Configure data mapping and sync frequency
  • Test connectivity and data flow
4

Set Up Automation Workflows

  • Create automatic ticket generation rules
  • Configure notification workflows
  • Set up escalation procedures
  • Define SLA policies

CMDB CI Linking​

The scanner supports linking cryptographic findings to CMDB Configuration Items in ServiceNow, enabling end-to-end traceability from crypto assets to business applications.

How CI Linking Works​

When scanning, you can provide a CI identifier and name via CLI flags or environment variables. These are propagated to every finding and mapped to ServiceNow fields during publishing:

SourceServiceNow FieldDescription
ci_idu_related_ciCMDB CI sys_id (32-char hex) — creates a direct link to the Configuration Item record
ci_nameu_business_applicationHuman-readable application display name
environmentu_environmentEnvironment classification (Production, Staging, Dev, Test)

Providing CI Context​

CI context can be provided through multiple methods, in order of precedence:

# Scan with CI linking
dke-scanner-agent filesystem \
--path /etc/ssl/certs \
--ci-id "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6" \
--ci-name "Payment Gateway" \
--environment production \

# Then publish to ServiceNow
dke-scanner-agent servicenow \
--instance https://company.service-now.com \
--token $SERVICENOW_TOKEN \
--input scan-results.json

Web UI CI Linking​

The web dashboard also supports CI linking directly from the UI: you can search your CMDB Configuration Items and link or unlink a cryptographic asset to a CI without leaving the dashboard.

API reference

Detailed API endpoints are documented separately in the Developer Docs.

Note

The CI identifier must be a valid 32-character hexadecimal ServiceNow sys_id for the Configuration Item link to be populated. Invalid formats are silently ignored, leaving the link empty.


API Data Format​

The scanner transmits data to ServiceNow in the following JSON structure:

{
"scan_id": "pqc-scan-20250128-001",
"timestamp": "2025-01-28T14:30:00Z",
"organization": "Example Corp",
"findings": {
"total_endpoints": 1247,
"vulnerable_endpoints": 342,
"critical_findings": 89,
"high_findings": 156,
"medium_findings": 97,
"vulnerabilities": [
{
"id": "VULN-RSA1024-001",
"severity": "CRITICAL",
"type": "Quantum-Vulnerable Algorithm",
"algorithm": "RSA-1024",
"ci_id": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6",
"ci_name": "Payment Gateway",
"environment": "production",
"affected_systems": [
"prod-web-01.example.com",
"api-gateway-02.example.com"
],
"risk_score": 9.5,
"remediation": "Upgrade to RSA-4096 or migrate to PQC algorithm",
"compliance_impact": ["NIST-PQC", "BSI-TR-02102"]
}
]
},
"compliance": {
"nist_pqc_score": 45,
"bsi_tr_02102_score": 52,
"cnsa_2_0_ready": false,
"gaps": [
"342 endpoints using deprecated algorithms",
"89 critical vulnerabilities requiring immediate action"
]
},
"recommendations": [
"Prioritize RSA-1024 algorithm replacement",
"Plan PQC migration for high-value assets",
"Update cryptographic libraries to latest versions"
]
}

ServiceNow Crypto Asset Record​

Each finding is converted to a ServiceNow crypto asset record with the following key fields:

ServiceNow FieldSourceDescription
u_related_cici_idLink to CMDB Configuration Item (sys_id)
u_business_applicationci_nameBusiness application display name
u_environmentenvironmentEnvironment (Production, Staging, Dev)
u_algorithmalgorithmCryptographic algorithm detected
u_risk_scorerisk_scoreQuantum vulnerability risk score
u_severityseverityFinding severity (Critical, High, Medium, Low)
u_sourcesourceScan source (filesystem, domain, agent, etc.)
u_locationlocationAsset location (file path, URL, etc.)

Benefits of ServiceNow Integration​

Centralized Management

  • Single pane of glass for all cryptographic vulnerabilities
  • Integration with existing IT security workflows
  • Unified reporting across all security domains

Improved Efficiency

  • Automated ticket creation reduces manual effort
  • Prioritization based on risk scores accelerates remediation
  • Workflow automation ensures timely response

Enhanced Visibility

  • Executive dashboards for leadership reporting
  • Team-level views for operational management
  • Historical trending for strategic planning

Compliance Assurance

  • Continuous compliance monitoring
  • Audit trail for regulatory requirements
  • Documentation for certification processes
Tip

Integrate PQC Scanner with ServiceNow early in your quantum readiness journey to establish baseline metrics and track improvement over time.