Combined Operational Technology Vulnerability Response release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Operational Technology Vulnerability Response release notes for upgrades from Yokohama to Zurich
This consolidated release notes document provides ServiceNow customers with essential information for upgrading the Operational Technology Vulnerability Response (OTVR) product from the Yokohama release to the Zurich release. It outlines new features, changes, deprecations, and upgrade considerations to help you prepare and understand the key improvements and modifications in Zurich.
Show less
Key Features
- Unified Security Exposure Management (USEM) Workspace Integration: From version 30.0.x onwards, OTVR configuration tasks are performed via the USEM Workspace, with the Vulnerability Response plugin consolidated under USEM to streamline management.
- Operational Technology Risk Calculator: The Risk Calculator plugin can now be accessed and used directly without the need to load demo data during installation, simplifying setup and evaluation.
- Enhanced Hardware Vulnerability Assessment: New capabilities include:
- Assessments without normalization, enabling evaluation of discovery models lacking normalization content.
- Introduction of confidence scores to improve assessment accuracy.
- Support for version range information from the National Vulnerability Database (NVD) to create assessments without explicit Common Platform Enumeration (CPE) entries.
- Partial assessments for discovery models missing firmware version data based on publisher and model matching.
- Automated expiration and regeneration of assessments when firmware versions on configuration items (CIs) are updated.
- Industrial Workspace Enhancements:
- A dedicated Hardware Vulnerability Assessment menu enables automatic and periodic firmware vulnerability assessments of OT device inventories.
- Vulnerability risk scores for OT devices can be viewed at multiple equipment model levels via the OT Risk Management dashboard.
- The enhanced OTVR (PA) dashboard aggregates OT vulnerability data and visualizations in one centralized location accessible from the Dashboard Library.
Changes
- Data previously available on the OT Vulnerabilities tab of the OT Manager dashboard (such as total OT vulnerable items and risk ratings) has been moved to the enhanced OTVR (PA) dashboard to consolidate vulnerability information.
Deprecations
- The OT Vulnerabilities tab is no longer available on the OT Manager dashboard in the Industrial Workspace starting with Yokohama.
- Vulnerability Response integration with Microsoft Defender for IoT (On-premises Management Console) is being prepared for future deprecation; it is hidden and not activated on new instances but remains supported.
Upgrade Considerations
- Review and complete all pre- and post-upgrade tasks before upgrading to Zurich to ensure a smooth transition.
- Activation of OTVR continues via requests through the ServiceNow Store as in previous releases.
- There are no additional browser or localization requirements introduced in Zurich.
- Coral is now the default theme for new portals and experiences, providing a refreshed, brand-neutral look with dark mode options for web and mobile.
Practical Outcomes for ServiceNow Customers
- Improved configuration management through USEM Workspace integration.
- More efficient and accurate vulnerability assessments of OT devices, even for models lacking full normalization data.
- Centralized dashboards enhance visibility and management of OT vulnerabilities and remediation efforts.
- Simplified plugin installation and risk calculation without dependency on demo data.
- Awareness of deprecated features helps plan for future changes in integrations and dashboard availability.
Consolidated page of all release notes for Operational Technology Vulnerability Response from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Operational Technology Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Operational Technology Vulnerability Response to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Operational Technology Vulnerability Response.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Operational Technology Vulnerability Response features.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
No updates for this release. |
Removed
Between your current release family and Zurich, some Operational Technology Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Operational Technology Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Operational Technology Vulnerability Response.
| Release | Release notes |
|---|---|
Yokohama |
Install Operational Technology Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Operational Technology Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Operational Technology Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Operational Technology Vulnerability Response for more information. |
Zurich |
|