Skip to main content

Workflows & Tickets

Cloudaware Vulnerability Management uses Initiatives, Remediation Tasks, and ITSM integrations to coordinate fixes across teams while preserving full CMDB context.

Use this guide to learn how vulnerability findings become remediation tasks, gain ownership and risk context, and move through ticketing and collaboration workflows to closure.

From Findings to Tasks

Typical flow:

  1. Group findings. Use grouping rules (e.g., CVE + asset/app) to define logical units of work.
  2. Create Remediation Tasks. Tasks can be created:
    • Automatically based on risk, age, or scheduled cycles (e.g., monthly CrowdStrike tasks).
    • Manually by SecOps or owners from a list view or dashboard.
  3. Attach context. Each task includes:
    • Linked vulnerability records.
    • Affected assets and applications.
    • Risk band, OU, environment, and due date (from SLAs).

See Vulnerability Management Processes for the conceptual task model.

ITSM and Collaboration Tools

Cloudaware can synchronize tasks with external systems, for example:

  • Jira (issues in security or application projects).
  • ServiceNow (incidents, problems, or change requests).
  • Collaboration tools like Slack or Microsoft Teams for alerts and status updates.

Key characteristics:

  • Stateful synchronization – when Cloudaware detects that a vulnerability is remediated, it can update or resolve the related ticket.
  • Routing by ownership – tickets are created in queues or projects aligned with OU/application owners.
  • Back‑links to CMDB – tickets include links to affected CIs and dashboards for additional context.

See also: ITSM Integrations and Collaboration.

While exact states depend on your ITSM tool, a common pattern is:

  • New – task created and awaiting triage.
  • Assigned/In Progress – owner actively working on remediation.
  • Waiting on Change/Maintenance Window – implementation scheduled via Patch or Change Management.
  • Resolved/Implemented – fix applied; awaiting verification scan.
  • Verified/Closed – vulnerabilities no longer detected; evidence captured.

Cloudaware dashboards and escalation reports can surface tasks that are stuck in intermediate states or breaching SLAs.