Reporting Operational vulnerability

  • Release version: Australia
  • Updated June 1, 2026
  • 1 minute to read
  • Any Operational Resilience application user can report an operational vulnerability that needs the attention of the Operational Resilience team.

    Users of the Operational Resilience feature can report an operational vulnerability using one the following options:

    States of the vulnerability

    An operational vulnerability record moves through the following workflow states.
    Table 1. States of a vulnerability record
    States Description
    New The vulnerability has been opened and it is in the initial stage of review.
    Assessment The vulnerability is being evaluated to determine the appropriate course of action.
    Treatment The vulnerability is being actively investigated to gather information and evidence. The course of action and treatment is being decided.
    Pending approval The vulnerability is being worked on to find a resolution.
    Approved A review of the vulnerability is being done after it is resolved.
    Closed The vulnerability is closed and is no longer active.
    Canceled The vulnerability is canceled and it is no longer being pursued.

    Email notifications for the vulnerabilities

    When the vulnerability is assigned to the users, they receive email notifications informing them about the vulnerability details, upcoming actions, and due dates. Email notifications are sent to the following users:
    1. When the vulnerability is assigned to an analyst or a user, they receive the email notifications.
    2. When the vulnerability is approved or rejected, the analyst receives the email notification.
    3. When the vulnerability is canceled, the approver, requester, analyst, and people on the watchlist receive the email notifications.