---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exposure assessment by software

# Exposure assessment by software {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Exposure assessment for zero-day vulnerabilities, when Common Vulnerabilities and Exposures (CVEs) for the asset or configuration item is not available. It uses the software information to assess exposure, using the software
discovery model.  
For information on assessing exposure by software, see:

* [Add software for exposure assessment](https://servicenow-prod.fluidtopics.net/R6ub4PaPEL1K9Uy192RM5g "Add a new software to the Exposure Assessment module to assess the impact of a new vulnerability or zero-day vulnerability.")
* [Create VIs for software for exposure assessment](https://servicenow-prod.fluidtopics.net/C1qpZIY6AQiluHggj6bLxQ "Create vulnerable items (VIs) from the Exposure Assessment page. Vulnerability event managers then analyze this list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.")
* [Activate or deactivate software for exposure assessment](https://servicenow-prod.fluidtopics.net/nB7Yz9TLNM3qJi91jieUgA "To stop further delta processing of software, you can choose to deactivate it, thus removing it from the active list of software.")
* [Export impacted CIs for software in the Vulnerability Assessment workspace](https://servicenow-prod.fluidtopics.net/MXiMfqZ8NzIRIH~3XPfBCQ "You can track the impacted assets list for new software by exporting the configuration items (CIs) related to an exposure assessment record to an excel sheet. This sheet can be used to share the assets details and owners to create incidents with the known impacted assets for the zero-day vulnerabilities.")
{#vr-ws-exposure-assessment-software__ul_zd4_wwn_dyb}

