---
sourceDocument: Xanadu Operational Technology Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/operational-technology

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Operational Technology Management

ft:clusterId :

    - optm

bundleId :

    - optm

workflow :

    - Technology


---

# Configure

# Configuring Operational Technology Vulnerability Response {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure Operational Technology (OT) assignment rules, remediation targets, risk calculators, and risk rollup calculation then configure integrations to create vulnerable item records.  
Note:  
If you have the sn_vul.vulnerability_admin role, you can use the Industrial Guided Setup to lead you through the setup of the Operational Technology Vulnerability Response application.

To access the Guided Setup, navigate to Industrial Workspace AdminGuided Setup.
{#configuring-oper-tech-vulnerability-response__table_dt5_rxj_4nb__entry__2}

| Task | Purpose |
|-|-|
| 1. Install Operational Technology Vulnerability Response from the ServiceNow Store. | Install the Operational Technology Vulnerability Response application. |
| 2. Assign roles to admin users  or user groups, if needed. | Assigns roles to control the actions that are available for each user. |
| 3. Assign roles for the OT Vulnerability Remediation Owner. | Assigns roles to control the actions that are available for the OT Vulnerability Remediation Owner. |
| 4. Create assignment groups and assign users to sites and groups. 1. Create an Operational Technology Vulnerability Response site assignment group for each site that you have in the Equipment Model Manager. 2. Assign users who already have either the cmdb_ot_isa_viewer or cmdb_ot_isa_editor role to sites. 3. Add users to the assignment group for their site. {#configuring-oper-tech-vulnerability-response__ol_rfp_jjq_3rb} | * Allows OT Remediation Owner users to see only vulnerable Items for their site. * Allows users to see the Vulnerability Items for the sites they're assigned to. {#configuring-oper-tech-vulnerability-response__ol_otn_qjq_3rb} |
| 5. Configure OT remediation target rules. | * Assigns OT vulnerable items to site-level groups, or groups based on classification. * Defines the expected timeframe for remediating vulnerable items. {#configuring-oper-tech-vulnerability-response__ul_dsl_czq_3rb} |
| 6. Load the demo data records for the Operational Technology Vulnerability Response application. | Calculates the remediation target for OT vulnerable items. |
| 7. Configure OT risk calculators. | Determines which OT risk factors to use when calculating the risk of a vulnerable item on an OT device. |
| 8. Configure OT risk roll up calculator. | Calculates the risk score of the OT devices at each level for the equipment model entity. |
| 9. Install Operational Technology Certified integrations for the Operational Technology Vulnerability Response application that are applicable to your environment. | Integrates certified third-party applications that enhance functionality of OT vulnerability management. |
[ ]

{#configuring-oper-tech-vulnerability-response__table_dt5_rxj_4nb}
* **[Install Operational Technology Vulnerability Response](https://servicenow-prod.fluidtopics.net/3~dn6x4DKDrZMGFia8ix9Q)**   
  Install the Operational Technology Vulnerability Response application if you have the admin role. This application includes demo data and installs the related store applications and plugins if they are not already installed.
* **[Assign Operational Technology Vulnerability Response roles](https://servicenow-prod.fluidtopics.net/XTNzfREsX3Itl8sx3smAJA)**   
  Assign roles to your users so that you can control their access to the features, capabilities, and data in the Operational Technology Vulnerability Response application.
* **[Create a site assignment group](https://servicenow-prod.fluidtopics.net/AO5Sa6nN2~Ei2NojcVB4dw)**   
  Create one Operational Technology Vulnerability Response assignment group per site that you have in the Equipment Model Manager. This allows OT Remediation Owner users to only see vulnerable items for their site.
* **[Assign users to sites](https://servicenow-prod.fluidtopics.net/t1njSX91QqMeKShCgc1Mjg)**   
  If you have not already done so during configuration of the Industrial Process Manager, assign users who already have either the cmdb_ot_isa_viewer or cmdb_ot_isa_editor role to sites.
* **[Assign users to assignment groups](https://servicenow-prod.fluidtopics.net/KGYR5cOExhe54YIc_ag5xA)**   
  Add users to assignment groups so they can see the vulnerability items for their assigned site.
* **[Assign vulnerable items to groups](https://servicenow-prod.fluidtopics.net/ONLn8EFRJI2YkdMHpmDYaQ)**   
  Configure OT Vulnerability assignment rules.
* **[Configure OT remediation task rules](https://servicenow-prod.fluidtopics.net/rBoCss99Fo1lLE72rlpq_w)**   
  For remediation tasks that are created in the Industrial Workspace, update existing remediation task rules to prevent imported vulnerable items from automatically adding OT devices.
* **[Configure OT remediation target rules](https://servicenow-prod.fluidtopics.net/PvhAJJZes5YiXpT_Qt5KTw)**   
  Configure remediation target rules for OT vulnerable items.
* **[Configure risk calculators](https://servicenow-prod.fluidtopics.net/gk3MHO4g1rw0bBZ91NAhBA)**   
  Determine which OT risk factors to use when calculating the risk of a vulnerable item on an OT device.
* **[Configure OT vulnerability risk rollup calculator](https://servicenow-prod.fluidtopics.net/oR2SID7MT95p1SL8HyjiSg)**   
  Use the OT vulnerability risk rollup calculator to calculate the risk score of the OT devices at each level of the equipment model. The overall risk score is rolled up to the parent equipment model entity.
* **[Install certified Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/MpecLsd1q4HG~ACWgoNSpg)**   
  Integrate certified third-party applications that enhance functionality of OT vulnerability management.

*[\>]: and then


