ITSM Integration and Controlled Remediation

AppViewX Quantum Trust Hub (QTH) integrates with IT Service Management (ITSM) platform to provide a unified, auditable mechanism for tracking and executing the remediation of cryptographic risks identified in your organization's infrastructure. This integration bridges the gap between cryptographic vulnerability discovery and structured remediation workflows, enabling security and operations teams to act on PQC findings directly from the QTH inventory.

The QTH ITSM integration enables security engineers and operations teams to initiate structured remediation workflows for cryptographic vulnerabilities—such as weak protocols, outdated libraries, and non-quantum-ready certificates—directly from the Configuration Scan Inventory and the Certificate Scan Inventory. Once a remediation ticket is created in ServiceNow, the inventory displays the ticket ID and its current lifecycle status, providing end-to-end visibility without requiring users to switch between systems.

Key capabilities introduced in this release include:

  • Creation of ServiceNow ITSM tickets directly from inventory findings
  • Intelligent grouping of related findings into a single remediation ticket
  • Ticket lifecycle visibility within the QTH inventory
  • Bidirectional synchronization of ticket status between QTH and ServiceNow
  • Bulk ticket creation for multiple inventory records
  • Cross-inventory ticket correlation between the Configuration Scan Inventory and the Certificate Scan Inventory
  • Comprehensive audit logging for all remediation lifecycle events
Note: ITSM ticket creation is supported only for findings with a Quantum Vulnerable quantum readiness status. Findings with a Hybrid or Quantum Resistant status, as well as certificates with an Expired, Revoked, Suspended, or New status, display Not Applicable in the Ticket ID and Action columns.

Prerequisites

Before you can create ITSM tickets from the QTH inventory, ensure the following conditions are met:

Table 1. Table 1. Prerequisites for ITSM Ticket Creation
Prerequisite Details
ServiceNow instance access A valid ServiceNow instance with the required credentials (username/password, OAuth, or other supported authentication type) must be available.
ServiceNow ITSM integration configured in Integration Hub A ServiceNow ITSM integration must be added or updated in the AppViewX Integration Hub with the QTH tag. See Configuring the ServiceNow ITSM Integration. (Configuring a ServiceNow Instance)
QTH configuration defined The QTH-specific configuration (ticket URL, payload fields, and assignment group) must be defined within the integration. See Configuring QTH-Specific Settings.
ACF permissions Your user role must have the required ACF permissions to view the Configuration Scan Inventory and the Certificate Scan Inventory, and to create ITSM tickets.
Inventory data available At least one scan must have been completed so that inventory findings are available for remediation.

For AppViewX configuration and usage of ITSM, see the following topics:

  1. To add the ServiceNow vendor integration, see the ServiceNow integration with AppViewX.
    Note: To enable PQC evaluation, add the QTH tag to the integration. Integrations without the QTH tag are not evaluated for post-quantum readiness.
  2. To initiate discovery, see Agentless Scanning or Agent-Based Scanning.
  3. To track PQC evaluation for each discovery instance, see the Quantum Readiness column in the Configuration scan inventory and Certificate scan inventory.
  4. For PQC remediation, see the ITSM ticket Evaluation Status column described in Configuration scan inventory and Certificate scan inventory columns Ticket ID and Action.
  5. To review unified results, see Configuration scan inventory and Certificate scan inventory.

Configuring an Existing ServiceNow Integration for QTH

If a ServiceNow integration was configured in a previous version of AppViewX, you can enable it for QTH without creating a new integration.

  1. Go to Platform > Integration Hub.
  2. Locate the existing ServiceNow integration and click Edit.
  3. In the Tags field, add the tag QTH.
  4. Configure the QTH Configuration section. See Configuring QTH-Specific Settings.
  5. Click Save.

Configuring QTH-Specific Settings

The QTH Configuration section within the ServiceNow integration defines how tickets are created and routed for each finding category. This configuration is specific to the Quantum Trust Hub and does not affect other AppViewX modules using the same integration.

Configure the following fields for each finding category (Certificate, Protocol, and Library):

Table 2. Table 2. QTH Configuration Fields
Field Description Example
URL The ServiceNow table API endpoint where the ticket will be created. This determines the ticket type (for example, Change Request, Incident).

Format: /api/now/table/<table_name>

/api/now/table/change_request

/api/now/table/incident

Assignment Group The ServiceNow user group responsible for resolving tickets created for this category. This value is used when an assignment group is not already mapped to the asset in the CMDB.

This field is optional. If left blank and no CMDB mapping exists, the ticket is created without an assignment group. See Assignment Group Resolution.

PKI Team

Network Security

ITSM Payload Fields Additional key-value pairs to be included in the ticket payload when creating tickets in ServiceNow. These fields map to ServiceNow table columns and allow customization of ticket metadata. priority: 2

category: security

UI URL (Optional) A custom URL template used to construct the link to the ServiceNow ticket when users click View in ITSM. If not configured, the default ServiceNow URL is used.

Use this field only if your ServiceNow instance uses a non-standard URL format.

https://<instance>.service-now.com/nav_to.do?uri=change_request.do?sys_id=
Note: The URL and Assignment Group fields must be configured separately for each finding category (Certificate, Protocol, Library). This allows different ticket types and ownership routing for different types of cryptographic findings.

Creating an ITSM Ticket from the Inventory

Once the ServiceNow ITSM integration is configured, you can create remediation tickets directly from the Configuration Scan Inventory or the Certificate Scan Inventory. Ticket creation is supported for individual findings (single ticket) and for multiple findings simultaneously (bulk ticket creation).

Creating a Single ITSM Ticket

To create a remediation ticket for a single inventory finding:

  1. Navigate to Quantum Trust Hub > Configuration Scan Inventory or Certificate Scan Inventory.
  2. Locate the finding for which you want to create a remediation ticket. Ensure the Action column displays Create Ticket.
  3. Click Create Ticket in the Action column for the relevant row.
  4. The Create ITSM Ticket dialog is displayed. Review and configure the following fields:
    Table 3. Table 3. Create ITSM Ticket Dialog Fields
    Field Description
    Integration Select the ServiceNow integration to use from the list of available integrations tagged with QTH. The ticket type is automatically resolved from the URL configured in the selected integration.
    Ticket Type Automatically populated based on the URL configured in the QTH Configuration (for example, Change Request or Incident). Read-only.
    Assignment Group Displays the resolved assignment group. This is populated from the CMDB (if a CMDB integration is configured and the asset has a mapped assignment group) or from the QTH Configuration JSON. If neither source provides a value, this field is empty. See Assignment Group Resolution.
    Short Description Pre-populated with a remediation title based on the finding type and asset details. You can edit this field before submitting.

    Examples:

    • Disable legacy TLS protocols on 10.1.1.5:443
    • Upgrade cryptographic libraries on app-server-01
    • Renew certificate deployment on 10.5.1.9:443
    Description Pre-populated with dynamic remediation guidance based on the finding type and cryptographic details. You can edit this field before submitting. See Dynamic Remediation Guidance for details on how guidance is generated.
  5. Click Create Ticket.

After submission:

  • The inventory row refreshes automatically. The Action column displays an In Progress indicator while the ticket is being created in ServiceNow.
  • Once the ticket is successfully created, the Ticket ID column is populated with the ServiceNow ticket ID, and the Action column changes to View Ticket.
  • If ticket creation fails, an error icon is displayed in the Action column. Hover over the icon to view the failure message. An audit log entry is also generated. See Error Handling.

Dynamic Remediation Guidance

The ticket description is pre-populated with remediation guidance that is dynamically generated based on the finding type. The following table describes the guidance provided for each finding category:

Table 4. Table 4. Dynamic Remediation Guidance by Finding Category
Finding Category Finding Type Recommended Actions
Protocol TLS 1.0 / TLS 1.1
  • Disable legacy TLS protocols (TLS 1.0 and TLS 1.1).
  • Migrate to TLS 1.3.
  • Enable approved hybrid key exchange support (recommended: X25519MLKEM768).
TLS 1.2
  • Migrate to TLS 1.3.
  • Enable hybrid PQC readiness.
TLS 1.3 (without hybrid support)
  • Enable hybrid PQC key exchange support.
Other legacy protocols Disable the protocol and migrate to a quantum-safe alternative.
Library Outdated cryptographic library
  • Upgrade the affected library to the recommended version (for example, upgrade OpenSSL).
  • Restart dependent services after the upgrade.
  • Validate application compatibility post-upgrade.
Certificate Non-quantum-ready certificate
  • Renew the certificate deployment with a quantum-safe algorithm.
  • Replace the legacy certificate chain.
  • Validate TLS compatibility after replacement.
Note: The pre-populated short description and description are editable. You can modify them before creating the ticket to add context specific to your environment.

Creating ITSM Tickets in Bulk

You can create remediation tickets for multiple inventory findings simultaneously using the bulk ticket creation feature. This is useful when you need to initiate remediation for several assets or findings at once.

  1. Navigate to Quantum Trust Hub > Configuration Scan Inventory or Certificate Scan Inventory.
  2. Select the checkboxes for the rows for which you want to create tickets. You can select up to 100 records at a time.
  3. Click the Create ITSM Ticket button that appears in the toolbar.
  4. The Bulk ITSM Ticket Creation page is displayed. This page lists each ticket to be created, numbered sequentially (for example, Ticket 1, Ticket 2).
  5. For each ticket, review and optionally modify the following:
    • Integration — Select or change the ServiceNow integration.
    • Short Description — Edit the pre-populated remediation title.
    • Description — Edit the pre-populated remediation guidance.
  6. To remove a ticket from the batch before creation, click the Remove option for that ticket entry.
  7. Click Create <n> Tickets (where n is the number of tickets in the batch) to submit all tickets.
Important: A maximum of 100 records can be selected for bulk ticket creation. If you attempt to select more than 100 records, an error message is displayed. Also, if any one of the selected record is quantum resistant or hybrid, or already has a ticket, an error message is displayed.
Note: For protocol findings, related findings on the same IP address and port are automatically grouped into a single ticket. See Grouping Logic for Ticket Creation for details.

Viewing ITSM Ticket Details

After a ticket is created, you can view its current details and lifecycle status directly from the QTH inventory without navigating to ServiceNow.

  1. In the inventory, locate the row with the ticket you want to view. The Action column displays View Ticket.
  2. Click View Ticket.
  3. The Ticket Details panel is displayed, showing the following information fetched on demand from ServiceNow:
    Table 5. Table 5. Ticket Details Panel Fields
    Field Description
    Ticket ID The ServiceNow ticket identifier.
    Ticket Summary The short description of the ticket as it appears in ServiceNow.
    Ticket Status The current lifecycle status of the ticket as reported by ServiceNow (for example, New, Assess, Authorize, Schedule, Implement, Review, Closed).
    Assignment Group The ServiceNow user group assigned to resolve the ticket.
    Grouped Findings The list of inventory findings associated with this ticket (applicable when grouping logic was applied).
    Last Updated The timestamp of the most recent update to the ticket in ServiceNow.
  4. To open the ticket directly in ServiceNow, click View in ITSM. You are redirected to the ticket page in the ServiceNow portal.
Note: Clicking View Ticket always fetches the latest ticket data from ServiceNow on demand. For background status synchronization, see Ticket Lifecycle and Status Synchronization.

Ticket Lifecycle and Status Synchronization

QTH maintains bidirectional synchronization with ServiceNow to keep the inventory's remediation status current. The following synchronization mechanisms are supported:

Table 6. Table 6. Ticket Synchronization Types
Synchronization Type Description
On-Demand Sync Triggered when a user clicks View Ticket. QTH fetches the latest ticket status, assignment group, and other details from ServiceNow in real time.
Scheduled Sync (Background Job) A background job runs every 24 hours to fetch the latest status of all active tickets from ServiceNow and update the QTH inventory. Status changes made in ServiceNow between job runs are reflected in the inventory after the next scheduled sync.
Ticket Creation Sync When a ticket is created from QTH, the Ticket ID is immediately written back to the inventory row upon successful creation in ServiceNow.
Failure Handling If synchronization fails (for example, due to connectivity or authentication issues), the failure is logged in the audit trail and an error indicator is displayed in the inventory. See Error Handling.

Grouping Logic for Ticket Creation

To prevent duplicate tickets and ensure that related findings are addressed under a single remediation workflow, QTH applies intelligent grouping logic when creating ITSM tickets. The grouping behavior differs by finding category.

Table 7. Table 7. Grouping Logic by Finding Category
Finding Category Grouping Criteria Behavior
Protocol Asset/IP address/FQDN/ asset hostname + Port + Protocol family All protocol findings on the same IP address and port are grouped into a single remediation ticket. For example, if TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3 (without hybrid support) are all detected on 192.168.1.1:443, a single ticket is created for that endpoint, and the same Ticket ID is populated across all corresponding inventory rows.
Library Asset + Library name Each unique combination of asset and library results in an individual ticket. No cross-library grouping is applied.
Certificate Certificate serial number or Asset/IP + Port Each certificate finding results in an individual ticket. No cross-certificate grouping is applied.
Note: When you click Create Ticket for a protocol finding, QTH automatically identifies all related protocol findings on the same endpoint and presents them as a grouped ticket in the creation dialog. The same Ticket ID is assigned to all grouped rows in the inventory.

Assignment Group Resolution

When creating an ITSM ticket, QTH resolves the assignment group using the following priority order:

Table 8. Table 8. Assignment Group Resolution Priority
Priority Source Description
1 (Highest) CMDB Integration If a CMDB integration is configured and the asset has a mapped assignment group in the CMDB, that value is used. The assignment group is populated via the CMDB Business Context Synchronization for Certificates and Endpoint CMDB Business Context Synchronization jobs.
2 QTH Configuration (Integration Hub) If no CMDB mapping exists, the assignment group configured in the QTH Configuration section of the ServiceNow integration is used.
3 (Fallback) None (Empty) If neither source provides an assignment group, the ticket is created without one. In ServiceNow, the ticket may be automatically assigned to a default group if such a rule is configured, or it may remain unassigned until manually updated.
Tip: To ensure consistent assignment group routing, configure the CMDB integration and run the CMDB Business Context Synchronization for Certificates job under CLM > Job Scheduler. This populates the Assignment Group column in the inventory with values from your CMDB, which are then used automatically during ticket creation.

Audit Logging

QTH maintains a comprehensive audit trail for all ITSM-related remediation lifecycle events. Audit logs provide visibility into ticket creation, status changes, and synchronization activities for governance and compliance purposes.

The following events are captured in the audit log:

Table 9. Table 9. Audit Log Events
Event Description
Ticket Created Logged when a remediation ticket is successfully created in ServiceNow, including the Ticket ID, asset details, and timestamp.
Ticket Creation Failed Logged when ticket creation fails, including the error message and timestamp.
Synchronization Failure Logged when the background sync job or on-demand sync fails to retrieve ticket data from ServiceNow.
Ticket Reopened Logged when a previously closed ticket is reopened in ServiceNow.
Note: Audit logs are retained in the database for historical reference. Closed ticket records—including Ticket ID, asset, finding, final status, closed timestamp, and validation outcome—are preserved for compliance and audit purposes.

Error Handling

If ticket creation or synchronization fails, QTH provides visual indicators and audit log entries to help you identify and resolve the issue.

Table 10. Table 10. Error Handling Scenarios
Scenario Behavior Resolution
Ticket creation fails An error icon is displayed in the Action column next to the Create Ticket button. Hovering over the icon displays the failure message. An audit log entry is generated. Verify the ServiceNow integration credentials and connectivity. Correct the issue and retry ticket creation.
Invalid credentials Ticket creation fails with an authentication error. The error is displayed in the Action column and logged in the audit trail. Update the credentials in the ServiceNow integration configuration in the Integration Hub.
Synchronization failure The background sync job logs the failure. The Ticket ID column retains the last known value; the status may be stale until the next successful sync. Check the ServiceNow integration connectivity. Use View Ticket for on-demand status refresh.
Bulk selection exceeds limit An error message is displayed if more than 100 records are selected for bulk ticket creation. Reduce the selection to 100 or fewer records and retry.