We are excited to announce that Orca now integrates with ServiceNow®’s Configuration Management Database (CMDB) to automatically populate and continuously maintain your cloud asset inventory with high-fidelity data from Orca. For teams already using Orca’s ServiceNow integration for alert-driven ticketing and remediation, this expands what that partnership can do, turning Orca into the authoritative source of cloud asset truth for your entire ServiceNow environment.
A CMDB is only as useful as the data inside it. Cloud infrastructure changes constantly: instances spin up and down, containers are replaced, serverless functions are deployed and retired, and keeping pace with that churn manually is practically impossible. The result is a CMDB that IT and security teams quietly stop trusting. Stale records, duplicate configuration items, and missing assets erode the foundation that risk management and service workflows depend on. Without current asset data and the security risk context to go with it, an unmaintained CMDB often misleads and slows teams down.
How Orca Populates and Maintains Your ServiceNow CMDB
Orca continuously syncs your cloud asset inventory into ServiceNow using the same Service Graph Connector standard that ServiceNow’s most trusted data sources follow.
Orca CMDB integration modules in ServiceNow, with scheduled imports organized by asset type
Every asset Orca discovers across AWS, Azure, GCP, and OCI gets mapped to the appropriate CMDB class automatically, covering virtual machines, containers, Kubernetes clusters and workloads, databases, load balancers, storage buckets, serverless functions, networking, and identity. Alongside asset metadata, Orca syncs its risk score for each CI as an authoritative security field, so every configuration item in ServiceNow carries not just what the asset is, but Orca’s assessment of the risk it represents. The integration handles deduplication natively, so new assets are created cleanly and existing CIs are updated in place rather than duplicated.
Virtual Machine instances synced to ServiceNow CMDB by Orca, showing Attestation Scores and most recent discovery timestamps
When an asset is decommissioned or disappears from your environment, the integration updates its status in the CMDB automatically. Your inventory stays current without manual cleanup, and historical records are preserved for audit purposes.
Connecting Cloud Security Risk to Business Services
A cloud asset CI in ServiceNow CMDB with infrastructure relationships, CI health tracking, and Orca as the discovery source
Accurate asset data in the CMDB opens up something more valuable than inventory hygiene. It makes service-aware security workflows possible. When every cloud asset is correctly mapped to a CI, ServiceNow can connect Orca’s security findings directly to the business services those assets support. A critical vulnerability on an EC2 instance tied to your payments service carries different operational weight than the same finding on a dev sandbox, and your CMDB is what makes that distinction visible to the teams that need to act on it.
For security operations teams, this means risk can be prioritized in business terms that IT operations already understands. For IT operations teams, it means change and incident workflows can automatically pull in the security context that Orca surfaces, without anyone needing to manually correlate findings across systems. With Orca and ServiceNow, CMDB becomes a system that actively works for you.
Next Steps: Make Orca the Source of Truth for Your ServiceNow CMDB
Interested in discovering the benefits of the Orca Platform and how it can be integrated with ServiceNow? Schedule a personalized 1:1 demo, and we’ll show how you can use Orca to identify, prioritize, and remediate risks in your cloud environment. If you already use both Orca and ServiceNow, follow the steps in the documentation to set up the integration.
Security For The Companies That Build
The Orca Cloud Security Platform is for the companies that build. Risk lives everywhere your teams operate, from AWS, Azure, Google Cloud, Oracle Cloud, Alibaba Cloud, and Tencent Cloud to every PaaS service, runtime, and AI agent they ship next. Orca delivers the context your cloud and AI depend on: deep, accurate, and actionable, so your team knows what matters and can act on it fast.
