Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Set up the Hardware Vulnerability Assessment of Operational Technology devices using guided setup

Use the Industrial Workspace Admin guided setup to walk you through configuring the Hardware Vulnerability Assessment feature available on the Industrial Workspace menu.

Before you begin

Role required: admin

About this task

Use the Industrial Workspace Admin guided setup to assign required user roles, configure a system property, and schedule jobs to perform the hardware vulnerability assessment of Operational Technology devices.

Procedure

  1. Navigate to All > Industrial Workspace Admin > Guided Setup > Operational Technology Vulnerability Response.

  2. Select Get Started for the Operational Technology Vulnerability Response application.

  3. Select the Hardware Vulnerability Assessment task.

  4. Select the following task tabs, then select Configure to complete the configuration tasks.

    TaskPurpose
    User Roles assignmentAssign users or user groups with roles that enable them to use the Hardware Vulnerability Assessment feature.
    Install and Run NVD IntegrationRun the National Vulnerability Database (NVD) integration to import data from the NIST NVD database to help you determine the severity and details of CVEs found in your environment.
    Configure Vulnerability Assessment propertiesConfigure the properties required to perform hardware vulnerability assessment for OT devices.
    Schedule Vulnerability Assessment JobsExecute scheduled jobs that enable vulnerability assessment on OT devices in the inventory and mark expired assessments that must be deleted.
    Normalization opt-inSelect Firmware Discovery Model Opt-in option for ServiceNow Asset Management Content Service to collect unnormalized firmware details of OT devices and update the normalized content library. This process improves the ratio of normalized data mapping to CVEs and therefore improves assessment of vulnerabilities.
    Delete obsolete assessmentsConfigure the time duration after which the obsolete and expired assessments are deleted.
  5. Assign roles for Hardware Vulnerability Assessment
    Assign roles to users so that they can configure properties, and use hardware vulnerability assessments features, capabilities, and data.

  6. Run NVD Integrations for Hardware Vulnerability Assessment
    Install and run National Vulnerability Database (NVD) integrations to perform hardware vulnerability assessment.
  7. Configure properties for Hardware Vulnerability Assessment
    Configure the properties required to perform hardware vulnerability assessment.
  8. Run scheduled jobs to perform Hardware Vulnerability Assessment
    Execute scheduled jobs to perform hardware vulnerability assessment.
  9. Configure Normalization Opt-in for Hardware Vulnerability Assessment
    Select Firmware Discovery Model Opt-in option for ServiceNow Asset Management Content Service to collect unnormalized firmware details of Operational Technology (OT) devices and update the normalized content library. This process improves the ratio of normalized data mapping to CVEs and therefore improves assessment of vulnerabilities.
  10. Delete obsolete and expired hardware vulnerability assessments
    Set up automatic deletion of obsolete or expired assessment records.

Parent Topic:Configuring the Industrial Workspace

Related topics

Guided Setup

Operational Technology Hardware Vulnerability Assessment