---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exploring vulnerability assessment

# Exploring vulnerability assessment {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Vulnerability Assessment Workspace is designed for the Vulnerability Event Manager to create a vulnerability event and to perform vulnerability assessment, especially during the zero-day vulnerability analysis.  
You can use the vulnerability assessment workspace to manage critical vulnerabilities, such as:

* Zero-day vulnerabilities of critical or high severity
* New threat intel identified for a vulnerability
* Rapid exploitation of a vulnerability of critical or high severity.
{#vr-ws-vuln-assessment__ul_evd_mr5_fzb}

## Vulnerability Assessment Workspace and Vulnerability Crisis Management {#vr-ws-vuln-assessment__section_hr3_k4r_fzb}

As a vulnerability event manager, identify and create a vulnerability event record for vulnerabilities of interest. Once you create the vulnerable event, you can perform risk assessment, manually update the risk attributes, and calculate the risk score automatically. Using the Vulnerability Assessment Workspace, you can perform the following actions to handle vulnerability crisis event from inception to resolution.

* [Create a vulnerability assessment record](https://servicenow-prod.fluidtopics.net/rDKgGA~BMRD1gf5bu7UKdw "Create assessment records for vulnerabilities of interest. After you create the assessment, you can initiate initial risk assessment, manually update the record, and calculate the risk score automatically.")
* [Modify the vulnerability assessment record](https://servicenow-prod.fluidtopics.net/Hj7EBJrFlUJdFxemqVheWQ#modify-vuln-assessment-record "Update the Vulnerability Assessment record, post it’s creation. Based on the field's values you can calculate the risk score.")
* [Perform a vulnerability assessment](https://servicenow-prod.fluidtopics.net/PACGsT8ChB8WnJnZYHyB1A "After you’ve created the vulnerability assessment record and updated the risk attribute fields, run an assessment of the event record.")
* [Review the Assessment details](https://servicenow-prod.fluidtopics.net/tiCIzdV7v_4xWNo0LEDjGQ "Review the assessment results in the assessment tab. After you perform an assessment of the vulnerability event, the record is correlated against the data from Software Bill of Materials and Software Asset Management and displayed with visualisations.")
* [Assign a priority and exposure level to the vulnerability assessment record](https://servicenow-prod.fluidtopics.net/mT7btpSRCxAFf~cAVSZKwQ "Manually assign priority and exposure level to the vulnerability assessment record.")
* [Add affected CIs to the assessment record](https://servicenow-prod.fluidtopics.net/J~lVJtxrHiH3licaSDH_Dg "Manually add the CIs in your organization that you think should be associated with the vulnerability assessment record but do not display in the affected CIs after initial assessment.")
* [Create vulnerable items for the affected CI or affected software component](https://servicenow-prod.fluidtopics.net/w1IqDjMciAY~Ld7krvuJnQ#vr-va-ws-create-vi "Create vulnerable items (VIs) or application vulnerable items (AVITs) from the Vulnerability Assessment Workspace. Vulnerability analysts analyze the list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.")
* [Link the vulnerability assessment record to major security incident in Major Security Incident Management](https://servicenow-prod.fluidtopics.net/nlSH7Qp8uZLwZCAUo88erg "You can link, propose or promote the assessment record to a Major Security Incident provided you have access to the Major Security Incident Management application.")
{#vr-ws-vuln-assessment__ul_zlf_c2c_hzb}

## Prerequisites for vulnerability assessment {#vr-ws-vuln-assessment__section_krc_xr5_fzb}

{#vr-ws-vuln-assessment__table_qqv_drb_2yb__entry__2}

| Application | Version |
|-|-|
| Vulnerability Crisis Management plugin | 1.0 |
| Vulnerability Response | 20.0 |
| Vulnerability Response with NVD Note: For more information, see [Understanding the NVD integrations](https://servicenow-prod.fluidtopics.net/eFiXOlP4oTeyfPz4Q0roQA "The NVD integrations use data imported from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) product to help you determine the impact and priority of flaws in your code. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product."). | 1.4.2 |
| Vulnerability Response Integration with CISA | 1.2 |
| Data Model for SBOM | 1.1.2 |
| Software Bill of Materials Core | 2.0.2 |
| Software Asset Management | Software Asset Management Foundation plugin or Software Asset Management Professional plugin |
| Major Security Incident Management | 2.2.5 |
[Table 1. Available versions]

{#vr-ws-vuln-assessment__table_qqv_drb_2yb}

## Scheduled jobs {#vr-ws-vuln-assessment__section_znp_1pr_2yb}

The following are the scheduled jobs.
{#vr-ws-vuln-assessment__table_nyp_1kk_cyb__entry__2}

| Scheduled job name | Description |
|-|-|
| Vulnerability Assessment | Updates the affected configuration items table and the source of the CI if vulnerable items (VITs or AVITs) are created after the assessment. Note: This scheduled job runs daily. It runs for a longer period than the other scheduled jobs. |
[ ]

{#vr-ws-vuln-assessment__table_nyp_1kk_cyb}
**Related concepts**   

* [Vulnerability Crisis Management](https://servicenow-prod.fluidtopics.net/loO1iRjkvrIHAknJ996NCA "Create and track critical vulnerability events through the Vulnerability Crisis Management (VCM) workflow. Create vulnerability assessment records, record key attributes of the vulnerability to calculate risk, perform assessment to identify exposure level, and engage stakeholders for a coordinated and swift response to vulnerabilities.")

