Vulnerability Management Playbooks

IVM False Positive Playbook

If there is a vulnerability finding in InsightVM that is a suspected false positive result, customers are encouraged to immediately report such findings to Rapid7 for review. To assist our customers with this process, the Rapid7 Customer Advisor team has developed an easy-to-follow playbook outlining specific actions for customer teams to take so Rapid7 can be quickly informed of the suspected false positive finding and potentially release a product fix.

False Positive Playbook
This playbook applies to both Managed Vulnerability Management (MVM) and product license-only customers with defined paths for each type of customer to follow.

False Positive Playbook

Remediation Project for ServiceNow

InsightVM will initiate the connection and create ServiceNow Incident tickets (INCs) for each solution listed in a Remediation Project configured with the aforementioned ticketing connection. For multiple projects and remediation teams, it is not necessary to create multiple ticketing connections to ServiceNow as a single connection can use assignment rules to properly delegate tickets to the appropriate remediation teams (HelpDesk, Server Operations, Development, Security, etc.). Additionally, Remediation Projects that were created prior to setting up a ticketing connection can be modified to use a connection that has been created afterward.

Remediation Project
Please see the play book which outlines how to configure an external ticketing connection to ServiceNow (SNOW) for Remediation Projects.

Remediation Projects - ServiceNow