ITSM Integration and Controlled Remediation
AppViewX Quantum Trust Hub (QTH) integrates with IT Service Management (ITSM) platform to provide a unified, auditable mechanism for tracking and executing the remediation of cryptographic risks identified in your organization's infrastructure. This integration bridges the gap between cryptographic vulnerability discovery and structured remediation workflows, enabling security and operations teams to act on PQC findings directly from the QTH inventory.
The QTH ITSM integration enables security engineers and operations teams to initiate structured remediation workflows for cryptographic vulnerabilities—such as weak protocols, outdated libraries, and non-quantum-ready certificates—directly from the Configuration Scan Inventory and the Certificate Scan Inventory. Once a remediation ticket is created in ServiceNow, the inventory displays the ticket ID and its current lifecycle status, providing end-to-end visibility without requiring users to switch between systems.
Key capabilities introduced in this release include:
- Creation of ServiceNow ITSM tickets directly from inventory findings
- Intelligent grouping of related findings into a single remediation ticket
- Ticket lifecycle visibility within the QTH inventory
- Bidirectional synchronization of ticket status between QTH and ServiceNow
- Bulk ticket creation for multiple inventory records
- Cross-inventory ticket correlation between the Configuration Scan Inventory and the Certificate Scan Inventory
- Comprehensive audit logging for all remediation lifecycle events
Prerequisites
Before you can create ITSM tickets from the QTH inventory, ensure the following conditions are met:
| Prerequisite | Details |
|---|---|
| ServiceNow instance access | A valid ServiceNow instance with the required credentials (username/password, OAuth, or other supported authentication type) must be available. |
| ServiceNow ITSM integration configured in Integration Hub | A ServiceNow ITSM integration must be added or updated in the AppViewX Integration Hub with the QTH tag. See Configuring the ServiceNow ITSM Integration. (Configuring a ServiceNow Instance) |
| QTH configuration defined | The QTH-specific configuration (ticket URL, payload fields, and assignment group) must be defined within the integration. See Configuring QTH-Specific Settings. |
| ACF permissions | Your user role must have the required ACF permissions to view the Configuration Scan Inventory and the Certificate Scan Inventory, and to create ITSM tickets. |
| Inventory data available | At least one scan must have been completed so that inventory findings are available for remediation. |
For AppViewX configuration and usage of ITSM, see the following topics:
- To add the ServiceNow vendor integration, see the ServiceNow integration with
AppViewX.
Note: To enable PQC evaluation, add the QTH tag to the integration. Integrations without the QTH tag are not evaluated for post-quantum readiness.
- To initiate discovery, see Agentless Scanning or Agent-Based Scanning.
- To track PQC evaluation for each discovery instance, see the Quantum Readiness column in the Configuration scan inventory and Certificate scan inventory.
- For PQC remediation, see the ITSM ticket Evaluation Status column described in Configuration scan inventory and Certificate scan inventory columns Ticket ID and Action.
- To review unified results, see Configuration scan inventory and Certificate scan inventory.
Configuring an Existing ServiceNow Integration for QTH
If a ServiceNow integration was configured in a previous version of AppViewX, you can enable it for QTH without creating a new integration.
- Go to Platform > Integration Hub.
- Locate the existing ServiceNow integration and click Edit.
- In the Tags field, add the tag QTH.
- Configure the QTH Configuration section. See Configuring QTH-Specific Settings.
- Click Save.
Configuring QTH-Specific Settings
The QTH Configuration section within the ServiceNow integration defines how tickets are created and routed for each finding category. This configuration is specific to the Quantum Trust Hub and does not affect other AppViewX modules using the same integration.
Configure the following fields for each finding category (Certificate, Protocol, and Library):
| Field | Description | Example |
|---|---|---|
| URL | The ServiceNow table API endpoint where the ticket will be created. This
determines the ticket type (for example, Change Request, Incident).
Format: /api/now/table/<table_name> |
/api/now/table/change_request /api/now/table/incident |
| Assignment Group | The ServiceNow user group responsible for resolving tickets created for
this category. This value is used when an assignment group is not already
mapped to the asset in the CMDB.
This field is optional. If left blank and no CMDB mapping exists, the ticket is created without an assignment group. See Assignment Group Resolution. |
PKI Team Network Security |
| ITSM Payload Fields | Additional key-value pairs to be included in the ticket payload when creating tickets in ServiceNow. These fields map to ServiceNow table columns and allow customization of ticket metadata. | priority: 2 category: security |
| UI URL (Optional) | A custom URL template used to construct the link to the ServiceNow ticket
when users click View in ITSM. If not configured, the default ServiceNow
URL is used.
Use this field only if your ServiceNow instance uses a non-standard URL format. |
https://<instance>.service-now.com/nav_to.do?uri=change_request.do?sys_id= |
Creating an ITSM Ticket from the Inventory
Once the ServiceNow ITSM integration is configured, you can create remediation tickets directly from the Configuration Scan Inventory or the Certificate Scan Inventory. Ticket creation is supported for individual findings (single ticket) and for multiple findings simultaneously (bulk ticket creation).
Creating a Single ITSM Ticket
To create a remediation ticket for a single inventory finding:
- Navigate to Quantum Trust Hub > Configuration Scan Inventory or Certificate Scan Inventory.
- Locate the finding for which you want to create a remediation ticket. Ensure the Action column displays Create Ticket.
- Click Create Ticket in the Action column for the relevant row.
- The Create ITSM Ticket dialog is displayed. Review and configure the
following fields:
Table 3. Table 3. Create ITSM Ticket Dialog Fields Field Description Integration Select the ServiceNow integration to use from the list of available integrations tagged with QTH. The ticket type is automatically resolved from the URL configured in the selected integration. Ticket Type Automatically populated based on the URL configured in the QTH Configuration (for example, Change Request or Incident). Read-only. Assignment Group Displays the resolved assignment group. This is populated from the CMDB (if a CMDB integration is configured and the asset has a mapped assignment group) or from the QTH Configuration JSON. If neither source provides a value, this field is empty. See Assignment Group Resolution. Short Description Pre-populated with a remediation title based on the finding type and asset details. You can edit this field before submitting. Examples:
- Disable legacy TLS protocols on 10.1.1.5:443
- Upgrade cryptographic libraries on app-server-01
- Renew certificate deployment on 10.5.1.9:443
Description Pre-populated with dynamic remediation guidance based on the finding type and cryptographic details. You can edit this field before submitting. See Dynamic Remediation Guidance for details on how guidance is generated. - Click Create Ticket.
After submission:
- The inventory row refreshes automatically. The Action column displays an In Progress indicator while the ticket is being created in ServiceNow.
- Once the ticket is successfully created, the Ticket ID column is populated with the ServiceNow ticket ID, and the Action column changes to View Ticket.
- If ticket creation fails, an error icon is displayed in the Action column. Hover over the icon to view the failure message. An audit log entry is also generated. See Error Handling.
Dynamic Remediation Guidance
The ticket description is pre-populated with remediation guidance that is dynamically generated based on the finding type. The following table describes the guidance provided for each finding category:
| Finding Category | Finding Type | Recommended Actions |
|---|---|---|
| Protocol | TLS 1.0 / TLS 1.1 |
|
| TLS 1.2 |
|
|
| TLS 1.3 (without hybrid support) |
|
|
| Other legacy protocols | Disable the protocol and migrate to a quantum-safe alternative. | |
| Library | Outdated cryptographic library |
|
| Certificate | Non-quantum-ready certificate |
|
Creating ITSM Tickets in Bulk
You can create remediation tickets for multiple inventory findings simultaneously using the bulk ticket creation feature. This is useful when you need to initiate remediation for several assets or findings at once.
- Navigate to Quantum Trust Hub > Configuration Scan Inventory or Certificate Scan Inventory.
- Select the checkboxes for the rows for which you want to create tickets. You can select up to 100 records at a time.
- Click the Create ITSM Ticket button that appears in the toolbar.
- The Bulk ITSM Ticket Creation page is displayed. This page lists each ticket to be created, numbered sequentially (for example, Ticket 1, Ticket 2).
- For each ticket, review and optionally modify the following:
- Integration — Select or change the ServiceNow integration.
- Short Description — Edit the pre-populated remediation title.
- Description — Edit the pre-populated remediation guidance.
- To remove a ticket from the batch before creation, click the Remove option for that ticket entry.
- Click Create <n> Tickets (where n is the number of tickets in the batch) to submit all tickets.
Viewing ITSM Ticket Details
After a ticket is created, you can view its current details and lifecycle status directly from the QTH inventory without navigating to ServiceNow.
- In the inventory, locate the row with the ticket you want to view. The Action column displays View Ticket.
- Click View Ticket.
- The Ticket Details panel is displayed, showing the following information
fetched on demand from ServiceNow:
Table 5. Table 5. Ticket Details Panel Fields Field Description Ticket ID The ServiceNow ticket identifier. Ticket Summary The short description of the ticket as it appears in ServiceNow. Ticket Status The current lifecycle status of the ticket as reported by ServiceNow (for example, New, Assess, Authorize, Schedule, Implement, Review, Closed). Assignment Group The ServiceNow user group assigned to resolve the ticket. Grouped Findings The list of inventory findings associated with this ticket (applicable when grouping logic was applied). Last Updated The timestamp of the most recent update to the ticket in ServiceNow. - To open the ticket directly in ServiceNow, click View in ITSM. You are redirected to the ticket page in the ServiceNow portal.
Ticket Lifecycle and Status Synchronization
QTH maintains bidirectional synchronization with ServiceNow to keep the inventory's remediation status current. The following synchronization mechanisms are supported:
| Synchronization Type | Description |
|---|---|
| On-Demand Sync | Triggered when a user clicks View Ticket. QTH fetches the latest ticket status, assignment group, and other details from ServiceNow in real time. |
| Scheduled Sync (Background Job) | A background job runs every 24 hours to fetch the latest status of all active tickets from ServiceNow and update the QTH inventory. Status changes made in ServiceNow between job runs are reflected in the inventory after the next scheduled sync. |
| Ticket Creation Sync | When a ticket is created from QTH, the Ticket ID is immediately written back to the inventory row upon successful creation in ServiceNow. |
| Failure Handling | If synchronization fails (for example, due to connectivity or authentication issues), the failure is logged in the audit trail and an error indicator is displayed in the inventory. See Error Handling. |
Grouping Logic for Ticket Creation
To prevent duplicate tickets and ensure that related findings are addressed under a single remediation workflow, QTH applies intelligent grouping logic when creating ITSM tickets. The grouping behavior differs by finding category.
| Finding Category | Grouping Criteria | Behavior |
|---|---|---|
| Protocol | Asset/IP address/FQDN/ asset hostname + Port + Protocol family | All protocol findings on the same IP address and port are grouped into a single remediation ticket. For example, if TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3 (without hybrid support) are all detected on 192.168.1.1:443, a single ticket is created for that endpoint, and the same Ticket ID is populated across all corresponding inventory rows. |
| Library | Asset + Library name | Each unique combination of asset and library results in an individual ticket. No cross-library grouping is applied. |
| Certificate | Certificate serial number or Asset/IP + Port | Each certificate finding results in an individual ticket. No cross-certificate grouping is applied. |
Assignment Group Resolution
When creating an ITSM ticket, QTH resolves the assignment group using the following priority order:
| Priority | Source | Description |
|---|---|---|
| 1 (Highest) | CMDB Integration | If a CMDB integration is configured and the asset has a mapped assignment group in the CMDB, that value is used. The assignment group is populated via the CMDB Business Context Synchronization for Certificates and Endpoint CMDB Business Context Synchronization jobs. |
| 2 | QTH Configuration (Integration Hub) | If no CMDB mapping exists, the assignment group configured in the QTH Configuration section of the ServiceNow integration is used. |
| 3 (Fallback) | None (Empty) | If neither source provides an assignment group, the ticket is created without one. In ServiceNow, the ticket may be automatically assigned to a default group if such a rule is configured, or it may remain unassigned until manually updated. |
Audit Logging
QTH maintains a comprehensive audit trail for all ITSM-related remediation lifecycle events. Audit logs provide visibility into ticket creation, status changes, and synchronization activities for governance and compliance purposes.
The following events are captured in the audit log:
| Event | Description |
|---|---|
| Ticket Created | Logged when a remediation ticket is successfully created in ServiceNow, including the Ticket ID, asset details, and timestamp. |
| Ticket Creation Failed | Logged when ticket creation fails, including the error message and timestamp. |
| Synchronization Failure | Logged when the background sync job or on-demand sync fails to retrieve ticket data from ServiceNow. |
| Ticket Reopened | Logged when a previously closed ticket is reopened in ServiceNow. |
Error Handling
If ticket creation or synchronization fails, QTH provides visual indicators and audit log entries to help you identify and resolve the issue.
| Scenario | Behavior | Resolution |
|---|---|---|
| Ticket creation fails | An error icon is displayed in the Action column next to the Create Ticket button. Hovering over the icon displays the failure message. An audit log entry is generated. | Verify the ServiceNow integration credentials and connectivity. Correct the issue and retry ticket creation. |
| Invalid credentials | Ticket creation fails with an authentication error. The error is displayed in the Action column and logged in the audit trail. | Update the credentials in the ServiceNow integration configuration in the Integration Hub. |
| Synchronization failure | The background sync job logs the failure. The Ticket ID column retains the last known value; the status may be stale until the next successful sync. | Check the ServiceNow integration connectivity. Use View Ticket for on-demand status refresh. |
| Bulk selection exceeds limit | An error message is displayed if more than 100 records are selected for bulk ticket creation. | Reduce the selection to 100 or fewer records and retry. |
