---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Reporting Operational vulnerability

# Reporting Operational vulnerability {#ariaid-title1}

* Release version: Australia
* 
* Updated June 1, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Any Operational Resilience application user can report an operational vulnerability that needs the attention of the Operational Resilience team.  
Users of the Operational Resilience feature can report an operational vulnerability using one the following options:

* To create an operational vulnerability from the Employee Center, see [Report operational vulnerability from the Employee Center](https://servicenow-prod.fluidtopics.net/j07ONK6_g08WsxpVyplNuA "Report an operational vulnerability from the Employee Center. Any employee or user can report the operational vulnerabilities and complaints directly to the supporting teams for a quick response. The user in the assignment group can assign an analyst for the operational vulnerability. Reporting the issues helps to reduce and avert losses in a timely manner."). The user must have the Operational Resilience business user \[sn_oper_res.operational_resilience_business_user\] role.
* To create an operational vulnerability from the Operational vulnerability menu in the Operational Resilience Workspace, see [Report an operational vulnerability from the module](https://servicenow-prod.fluidtopics.net/sKzPtLQ8CGzq8iGPui818g "Report an operational vulnerability from the Operational vulnerability module in the Operational Resilience Workspace."). The user must have the Operational Resilience manager \[sn_oper_res.operational_resilience_manager\] role.
* To create an operational vulnerability from the records in the Operational Resilience Workspace, see the following topics:
  * [Report Operational vulnerability from Importance assessment](https://servicenow-prod.fluidtopics.net/bvsxeqYFLX_0HIxolUbKlw "Report an operational vulnerability from the Importance and impact assessment in the Operational Resilience Workspace.")
  * [Report an operational vulnerability from Scenario analysis](https://servicenow-prod.fluidtopics.net/BLSkwNxwpBSNwRn223IHgA "Report an operational vulnerability from the Scenario analysis in the Operational Resilience Workspace.")
  * [Report an operational vulnerability from Self-attestation](https://servicenow-prod.fluidtopics.net/IaSXYq_SaiHghb~xXhPwhQ "Report an Operational vulnerability from the Self-attestation module in the Operational Resilience Workspace.")
  * [Report an operational vulnerability from the Service record](https://servicenow-prod.fluidtopics.net/KX_hCp_KXgfw76c7cvgP6w "Report an operational vulnerability from the Service record available in the Self-attestations list.")
  {#reporting-operational-vul__ul_fwg_psd_xcc}
{#reporting-operational-vul__ul_wjq_mvc_zvb}

## States of the vulnerability {#reporting-operational-vul__section_ecq_s2v_wcc}

An operational vulnerability record moves through the following workflow states.{#reporting-operational-vul__table_b5y_dfv_wcc__entry__2}

| States | Description |
|-|-|
| New | The vulnerability has been opened and it is in the initial stage of review. |
| Assessment | The vulnerability is being evaluated to determine the appropriate course of action. |
| Treatment | The vulnerability is being actively investigated to gather information and evidence. The course of action and treatment is being decided. |
| Pending approval | The vulnerability is being worked on to find a resolution. |
| Approved | A review of the vulnerability is being done after it is resolved. |
| Closed | The vulnerability is closed and is no longer active. |
| Canceled | The vulnerability is canceled and it is no longer being pursued. |
[Table 1. States of a vulnerability record]

{#reporting-operational-vul__table_b5y_dfv_wcc}

## Email notifications for the vulnerabilities {#reporting-operational-vul__section_uxf_yn1_xcc}

When the vulnerability is assigned to the users, they receive email notifications informing them about the vulnerability details, upcoming actions, and due dates. Email notifications are sent to the following users:

1. When the vulnerability is assigned to an analyst or a user, they receive the email notifications.
2. When the vulnerability is approved or rejected, the analyst receives the email notification.
3. When the vulnerability is canceled, the approver, requester, analyst, and people on the watchlist receive the email notifications.
{#reporting-operational-vul__ol_bdz_k41_xcc}

