ITSM & Ticketing
Cloudaware integrates with ITSM platforms such as ServiceNow and Jira to create, update, and close tickets based on vulnerability data. This allows teams to work in their existing tools while Cloudaware provides context, ownership, and reporting.
Use tia guide to learn how Cloudaware integrates with ITSM platforms, including common ticketing patterns, field and ownership mapping, and status synchronization between systems.
Integration Patterns
Common patterns include:
- One task → one ticket
- A Remediation Task in Cloudaware corresponds to a single ITSM ticket.
- Linked vulnerabilities are referenced in the ticket description or attachments.
- One initiative → many tickets
- Large Initiatives (e.g., OS upgrade campaigns) generate multiple tickets across teams.
- Exception workflows
- Exceptions may trigger change requests or risk acceptance records in ITSM.
See Workflows & Tickets and Vulnerability Management Processes for the conceptual model.
Field and Ownership Mapping
When creating tickets, Cloudaware typically maps:
- Owner/Assignment group ← OU, application team, or platform team.
- Short description/Summary ← High‑level remediation task name.
- Description ← Details of affected assets, CVEs, and risk.
- Priority ← Risk band or severity.
- Due date ← SLA‑driven due date from Cloudaware.
Best practices:
- Define routing rules so tickets land in the correct queues.
- Agree on how priority is derived from risk bands.
- Include deep links back to Cloudaware dashboards and CIs.
Stateful Updates
After tickets are created:
- Status updates in ITSM can be synchronized back to Cloudaware (e.g., In Progress, Resolved).
- When Cloudaware detects that a vulnerability is no longer present, it can:
- Mark the remediation task as Closed.
- Optionally update or resolve the related ticket.
This ensures that dashboards and reports accurately reflect real‑world remediation progress.