Set up the Hardware Vulnerability Assessment of Operational Technology devices using guided setup

  • Release version: Australia
  • Updated March 12, 2026
  • 1 minute to read
  • Use the Industrial Workspace Admin guided setup to walk you through configuring the Hardware Vulnerability Assessment feature available on the Industrial Workspace menu.

    Before you begin

    Role required: admin

    About this task

    Use the Industrial Workspace Admin guided setup to assign required user roles, configure a system property, and schedule jobs to perform the hardware vulnerability assessment of Operational Technology devices.

    Procedure

    1. Navigate to All > Industrial Workspace Admin > Guided Setup > Operational Technology Vulnerability Response.
    2. Select Get Started for the Operational Technology Vulnerability Response application.
    3. Select the Hardware Vulnerability Assessment task.
    4. Select the following task tabs, then select Configure to complete the configuration tasks.
      TaskPurpose
      User Roles assignment Assign users or user groups with roles that enable them to use the Hardware Vulnerability Assessment feature.
      Install and Run NVD Integration Run the National Vulnerability Database (NVD) integration to import data from the NIST NVD database to help you determine the severity and details of CVEs found in your environment.
      Configure Vulnerability Assessment properties Configure the properties required to perform hardware vulnerability assessment for OT devices.
      Schedule Vulnerability Assessment Jobs Execute scheduled jobs that enable vulnerability assessment on OT devices in the inventory and mark expired assessments that must be deleted.
      Normalization opt-in Select Firmware Discovery Model Opt-in option for ServiceNow Asset Management Content Service to collect unnormalized firmware details of OT devices and update the normalized content library. This process improves the ratio of normalized data mapping to CVEs and therefore improves assessment of vulnerabilities.
      Delete obsolete assessments Configure the time duration after which the obsolete and expired assessments are deleted.