Combined Operational Technology Vulnerability Response release notes for upgrades from Xanadu to Zurich
Summarize
Summary of Combined Operational Technology Vulnerability Response release notes for upgrades from Xanadu to Zurich
This consolidated release notes page provides ServiceNow customers with a comprehensive view of updates, new features, changes, and important guidance for upgrading Operational Technology Vulnerability Response (OTVR) from the Xanadu release through to Zurich. It covers enhancements introduced across the major releases, pre- and post-upgrade tasks, feature deprecations, and activation instructions, enabling customers to effectively manage their OT vulnerability lifecycle and risk exposure.
Show less
New Features
- Hardware Vulnerability Assessment (HVA) Menu: Available in the Industrial Workspace, this menu enables periodic and automatic assessment of OT device firmware vulnerabilities, generating vulnerable item records against impacted Configuration Items (CIs).
- Risk Scoring Dashboards: The OT Vulnerability Risk Rollup and OT Risk Management dashboards present vulnerability risk scores at various equipment model levels, providing clear visibility into device risk posture.
- Enhanced OTVR (PA) Dashboard: A centralized dashboard experience consolidates all OT vulnerability data and visualizations for easier management, accessible via the Dashboard Library page.
- OT Vulnerability Remediation Owner Role: A dedicated role (snotvr.remediationowner) assigns remediation task ownership with capabilities to create change tasks and manage vulnerabilities efficiently.
- Automatic Remediation Task Scheduling: Remediation tasks can be automatically started based on the ISA maintenance schedule, facilitating timely vulnerability mitigation aligned with operational windows.
- Common Security Advisory Framework (CSAF) Support: Enables importing vulnerability solutions from multiple vendors using a standardized advisory format, enhancing integration with aggregators and trusted providers.
- Guided Setup for OTVR (PA) Dashboard: Simplifies configuration of data collection and indicator sources within the Industrial Workspace.
- Bulk Edit for OT VR Assignment Group: Allows updating assignment groups across multiple site records simultaneously, streamlining administrative tasks.
- Compensating Controls: Supports use of compensating controls to mitigate risks from vulnerabilities that cannot be immediately patched.
- Configuration via Unified Security Exposure Management (USEM) Workspace: From version 30.0.x onward, some configuration tasks are performed in the USEM Workspace, consolidating Vulnerability Response plugins under USEM.
- Risk Calculator Plugin: Now accessible without requiring demo data installation, enabling quicker risk calculations for OT vulnerabilities.
- Advanced HVA Enhancements: Include assessments without normalization, confidence scoring, version range support from the National Vulnerability Database (NVD), partial assessments for discovery models missing full firmware data, and automatic expiration of outdated assessments when firmware updates occur.
Changes
- Data previously available on the OT Vulnerabilities tab within the OT Manager dashboard has been migrated to the enhanced OTVR (PA) dashboard for Xanadu and Yokohama releases, improving data accessibility and consistency.
Deprecations
- The OT Vulnerabilities tab is no longer available on the OT Manager dashboard starting with Xanadu and Yokohama.
- Integration with Microsoft Defender for IoT (On-premises Management Console) is deprecated and hidden from new instances but remains supported for existing deployments.
Activation and Installation
Operational Technology Vulnerability Response must be installed by requesting it from the ServiceNow Store. Customers can view available apps and submit requests through the store. For cumulative release notes of all app versions, refer to the ServiceNow Store version history.
Accessibility and User Experience
The Zurich release introduces the Coral theme as the default for new portals, web, and mobile experiences with Next Experience or Core UI enabled. This theme offers a fresh, brand-neutral design with optional dark mode for web and mobile, enhancing user interaction with the platform.
Practical Takeaways for ServiceNow Customers
- Prepare for upgrade by reviewing pre- and post-upgrade tasks to ensure smooth transition to Zurich.
- Leverage the enhanced dashboards and roles to gain comprehensive visibility and efficient management of OT vulnerabilities and remediation workflows.
- Use the Hardware Vulnerability Assessment capabilities to continuously monitor firmware vulnerabilities and act proactively.
- Adopt the CSAF standard to streamline importing and managing vulnerability data from diverse vendors.
- Plan for the deprecation of legacy dashboard tabs and integrations to avoid disruptions post-upgrade.
- Utilize the Unified Security Exposure Management workspace for consolidated configuration and management.
- Take advantage of improved UI themes and accessibility features for better end-user experience.
Consolidated page of all release notes for Operational Technology Vulnerability Response from Xanadu to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Operational Technology Vulnerability Response release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.
Important information for upgrading Operational Technology Vulnerability Response to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Operational Technology Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Operational Technology Vulnerability Response features.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
No updates for this release. |
Removed
Between your current release family and Zurich, some Operational Technology Vulnerability Response features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Operational Technology Vulnerability Response features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Operational Technology Vulnerability Response.
| Release | Release notes |
|---|---|
Xanadu |
Install Operational Technology Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Yokohama |
Install Operational Technology Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Operational Technology Vulnerability Response by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Operational Technology Vulnerability Response, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Operational Technology Vulnerability Response we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Operational Technology Vulnerability Response for more information. |
Yokohama |
See Operational Technology Vulnerability Response for more information. |
Zurich |
|