---
sourceDocument: Xanadu Operational Technology Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/operational-technology

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Operational Technology Management

ft:clusterId :

    - optm

bundleId :

    - optm

workflow :

    - Technology


---

# Hardware Vulnerability Assessment

# Hardware Vulnerability Assessment {#ariaid-title1}

* Release version: Xanadu
* 
* Updated December 18, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The Hardware Vulnerability Assessment (HVA) is available in the Industrial Workspace menu for users who are using the Operational Technology Vulnerability Response Pro.

## Hardware Vulnerability Assessment overview {#understanding-hwd-vuln-assessment__section_ocl_g2x_ydc}

You can use Hardware Vulnerability Assessment to assess the firmware vulnerabilities of the OT devices in inventory and create vulnerable items (VIT) against the impacted OT devices.

HVA uses normalized content for firmware discovery model and Common Platform Enumeration (CPE) format provided by the National Vulnerability Database (NVD) to perform assessments.
The normalized content contains OT device data, such as manufacturer, firmware version, and product model. It's based on the normalization process available in the Enterprise Asset Management. The normalized content for OT devices is mapped with the Common Vulnerabilities and Exposures (CVEs) available in NVD. The Hardware Vulnerability Assessment menu
displays the OT devices that are at risk, when the CVE data matches the OT device data available in the normalized content.  
You must perform the following scheduled jobs to perform hardware vulnerability assessment automatically and periodically:

* Hardware Vulnerability Assessment - Full
* Hardware Vulnerability Assessment - Delta
{#understanding-hwd-vuln-assessment__ul_wyk_qjb_zdc}

## Required Operational Technology and Hardware Vulnerability Assessment roles {#understanding-hwd-vuln-assessment__section_tz2_bt2_xdc}

You need the following roles to use the Hardware Vulnerability Assessment (HVA) menu:

* sn_vul.manage_exposure_assessment: Assign roles to admin users or user groups as needed, which enables them to view or edit properties for Hardware Vulnerability Assessment.
* sn_otvr.vul_event_manager (OT Vulnerability Event Manager): Assign roles to Hardware Vulnerability Analyst users  or user groups as needed, which enables them to view assessment records and act accordingly.
{#understanding-hwd-vuln-assessment__ul_lmy_y1f_ydc}

## Use Case {#understanding-hwd-vuln-assessment__section_ctp_qgf_ydc}

OT hardware vulnerability analysts can use HVA to:

* Identify cybersecurity risks in OT devices.
* Focus on high-risk vulnerabilities via fully match assessments on OT device data.
* Set up automatic creation of vulnerable items for fully matched assessments.
* Investigate and address partially matched assessments to identify potential risks and act accordingly.
* Monitor unprocessed OT devices from Awaiting Normalization tab, which are pending full discovery or pending content updates.
{#understanding-hwd-vuln-assessment__ul_h3y_3z5_zdc}

## HVA tabs {#understanding-hwd-vuln-assessment__section_cl2_knm_ydc}

The HVA menu displays hardware vulnerability assessment records created for the OT devices. These assessment records are created based on many criteria. For example, CVE
vulnerability, OT device at risk, Common Vulnerability Scoring System (CVSS) score, and Device Criticality.

* The Fully matched assessments tab displays the assessment records, where the CVEs fully match with the manufacturer, product model, and firmware version of the OT devices. A fully matched assessment means that an OT device matches all vulnerability factors specified in a CVE.
* The Partially matched assessments tab displays the assessment records, where the CVEs partially match the manufacturer and model on the OT device but the firmware version match is undetermined.
* The Vulnerable Items tab displays the VITs that are created automatically or you create manually based on the assessments.
* The Ignored assessments tab displays the assessments of the devices that you choose to ignore.
* The Awaiting Normalization tab displays the OT device data that doesn't have the normalized data and hasn't been used for assessment.

{#understanding-hwd-vuln-assessment__ul_skw_qhb_zdc}  
Important:  
* If the property to create automatic VIT is enabled, the Fully matched assessments tab doesn't display any data. You can view this information in the Vulnerable Items tab.
* Enable Opt-in feature in Enterprise Asset Management to allow OT devices be available for normalization. For more information, see [Opt-in to Enterprise Asset Management Content Service](https://www.servicenow.com/docs/access?context=optin-cs-eam&version=xanadu&pubname=xanadu-it-asset-management&ft:locale=en-US).
{#understanding-hwd-vuln-assessment__ul_u4z_m5g_c2c}

## Delete obsolete assessments {#understanding-hwd-vuln-assessment__section_yx3_hrr_12c}

You can also set up automatic deletion of obsolete assessment records.  
1. Navigate to AllSystem Data ManagementData Management Policies.
2. Search and select the sn_vul_analyst_firmware_vulnerability_assessment policy.
3. Select the Active check box.
4. Select Update.
{#understanding-hwd-vuln-assessment__ol_awq_qyd_b2c}
**Related concepts**   

* [Industrial Workspace](https://servicenow-prod.fluidtopics.net/cN~7y88unVVslAEipeqc9Q "The Industrial Workspace is a user interface that provides Operational Technology (OT) users with the tools they need to manage their OT data.")  
**Related tasks**   

* [Setting up Hardware Vulnerability Assessment of OT devices using guided setup](https://servicenow-prod.fluidtopics.net/rheAu2UZ_TBExHs6rHpbwQ "Use Industrial Workspace Admin Guided setup to walk you through configuring the Hardware Vulnerability Assessment feature available on the Industrial Workspace menu.")
* [Using the Hardware Vulnerability Assessment menu in the Industrial Workspace](https://servicenow-prod.fluidtopics.net/a8EI8odFNeSoQedT1hGjAA "The Hardware Vulnerability Assessment menu provides information of all vulnerabilities in the OT inventory that match fully or partially to the vulnerabilities enlisted in NVD.")  
**Related topics**   

* [Enterprise Asset Management normalization](https://www.servicenow.com/docs/access?context=normalization-eam&version=xanadu&pubname=xanadu-it-asset-management&ft:locale=en-US)

*[\>]: and then


