---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Managing Operational vulnerability

# Managing Operational vulnerability {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Operational vulnerabilities are weaknesses in systems, processes, or procedures that can be exploited by attackers to compromise the security and integrity of an organization's operations. These vulnerabilities can arise from a
variety of factors, including IT and non-IT operations.

## Vulnerability in operational processes {#operational-vulnerability__section_txq_b2y_b5b}

In today's ever-changing business environment, organizations may face various operational vulnerabilities at unforeseen times. These vulnerabilities can originate from IT-related issues or non-IT areas like third party problems or
facility issues that might affect organizational functioning. Through Operational vulnerability, you can identify these weaknesses or vulnerabilities in IT systems and other operational processes within your organization.

Upon identifying vulnerabilities, analysts and owners undertake action tasks and determine the optimal response strategy. To address the vulnerability, stakeholders carry out risk assessments, pinpoint affected areas, and create
corresponding assessment and treatment tasks. A treatment plan is then developed to either accept, avoid, mitigate, or transfer the vulnerability. Once the associated tasks are completed, approval for the vulnerability is requested.
Following approval, the vulnerability is closed.

By addressing these vulnerabilities and implementing effective controls, organizations can significantly reduce the risk to their operations and ensure the timely delivery of the business services.

Starting with Release 19.0.x, the Operational vulnerability feature is integrated into the Operational Resilience application by default.

## Get started {#operational-vulnerability__section_fnd_d3y_b5b}

|-|-|
| [Explore Learn about Operational vulnerability](https://servicenow-prod.fluidtopics.net/23RpEF~zYV7oP4FW9DQgKQ "The Operational vulnerability capability in Operational Resilience empowers users to flag operational vulnerabilities or critical functionality gaps, engage with key stakeholders, analyze underlying causes, and identify remedies.") | [Configure Configure Operational vulnerability](https://servicenow-prod.fluidtopics.net/~2kVT9Pwaq3x2F6EqE1akA "Configure the Operational vulnerability feature in the Operational Resilience Workspace to help identify and address operational vulnerabilities within your organization.") |
| [ManageManage Operational vulnerability](https://servicenow-prod.fluidtopics.net/XXy5HYKWZeiBuv2YPQwILw "Any Operational Resilience application user can report an operational vulnerability that needs the attention of the Operational Resilience team.") | [Reference Components installed with Operational vulnerability](https://servicenow-prod.fluidtopics.net/B0yEXI3o0Yo4NHQVjrbhYQ "Reference topics provide additional information about the Operational vulnerability, including the associated tables and roles.") |
[ ]

{#operational-vulnerability__table_iwv_lpv_klb} To identify and address operational process vulnerabilities, follow these steps:

1. Report an operational vulnerability from the Employee Center or the Operational Resilience Workspace.
2. Identify and link the impacted and related areas to the operational vulnerability.
3. Generate action tasks and request approval for them.
4. Decide a treatment plan to address the operational vulnerability and conduct a root cause analysis.
5. Add or create issues related to the operational vulnerability.
6. Request approval for and close the operational vulnerability.
{#operational-vulnerability__ol_ih4_lhv_xcc}

## Additional resources {#operational-vulnerability__section_unp_p3q_tnb}

* [Ask or answer questions in the GRC community](https://community.servicenow.com/community/business-management/grc)
* [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477)
* [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case)
* [Developer training](https://developer.servicenow.com/app.do#!/training/landing)
* [Developer documentation](https://developer.servicenow.com/app.do#!/documentation)
{#operational-vulnerability__ul_dsv_s3q_tnb}

