---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Evaluate vulnerability exposure data using generative AI with Security Exposure 360

# Evaluate vulnerability exposure data with Security Exposure 360 {#ariaid-title1}

* Release version: Australia
* 
* Updated August 3, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the Security Exposure 360 agentic workflow to review vulnerability data about your environment. Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about
host, container, and test results vulnerabilities.

## Before you begin

Note:  
Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see [ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

Roles required: sn_vul.vulnerability_analyst or sn_vul.vulnerability_admin

## Procedure

1. Navigate to WorkspacesSecurity Exposure Management.
2. Select the ServiceNow Otto® icon () on the header page from anywhere in your instance.  
   The ServiceNow Otto® panel is displayed. If you don't see the ServiceNow Otto® icon in the header on the page, you must activate the ServiceNow Otto® panel. For more information, see [Activate the ServiceNow Otto panel standard chat](https://www.servicenow.com/docs/access?context=activate-now-assist-panel&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).
3. Select Exposure 360 from the available options.
4. At the prompt, enter your question in natural language.  
   For example: <kbd class="ph userinput">How many active vulnerable items have a 'Critical' risk rating?</kbd>  
   Note:  
   The responses generated by the Security Exposure 360 agentic workflow are based on the data available in your environment. Review answers for accuracy before acting on them.

   Counts and findings in the Security Exposure 360 output are now directly clickable, linking you to the underlying vulnerable item (VITs) and records in your instance.

   Suggested follow-up questions are provided that help you drill down.  
   The agentic workflow supports results for all types of findings in Unified Security Exposure Management (USEM) that include host vulnerable items (VITs), container vulnerable items (CVITs), and container test results (CTRs) in your environment.  
   Note:  
   To view CVITs and CTRs, you must have the Container Vulnerability Response and Configuration Compliance applications installed.
5. **Optional:** If the response indicates no records, you might refine your question so it is more specific.  
   If you choose to enter them, it is helpful to be sure field labels and field values on records match the information on vulnerability records exactly. For example, a 'Critical' risk rating might correspond exactly to
   the value `1 - Critical` in the Risk rating fields on vulnerability records. Rephrasing your question to include information such as specific field labels or field values can help you improve the
   accuracy of your returned results.

*[\>]: and then


