---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Update the state of the operational vulnerability

# Update the state of the operational vulnerability {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Update the state of the Operational vulnerability record to the Assessment or Treatment state. At this stage, the vulnerability is being evaluated to determine the best course of action and
create an action task accordingly.

## Before you begin

Role required: sn_oper_res.manager

## Procedure

1. Navigate to WorkspacesOperational Resilience WorkspaceAll Operational Vulnerabilities.
2. Open the vulnerability record from the list.  
   The Operational vulnerability record is in the New state.
3. Select Update state UI action.  
   The New state can be transitioned to the following states as shown in the example:
   * Assessment
   * Treatment
   * Pending approval
   * Approved
   * Closed
   * Canceled
   {#update-state-of-vul__ul_nx3_ypn_wcc}

   For more information on the state transition model, see [Set up the State model and Action task model](https://www.servicenow.com/docs/cegEI_FfQlt1efqjtL6cZQ "Set up the Vulnerability state model and Action task model to manage the workflow of the Operational vulnerability record. These models define the workflow states and transition conditions for a record type and an action task, respectively. Both the Operational vulnerability record type and the action task adhere to the workflow states configured in their corresponding models.").
4. Update the state of the vulnerability record.

   | Step | Description |
   | Select Update state UI action, select Assessment, add comments in Additional comments, and select Submit. | This action updates the state of the vulnerability record to the Assessment state. |
   | Select Update state UI action, select Treatment, add comments in Additional comments, and select Submit. | This action updates the state of the vulnerability record to the Treatment state. |
   |-|-|

   {#update-state-of-vul__choicetable_yf4_vjd_xcc}  
   The Update state window is shown in the example.  
   When the state is updated to Assessment, the state of the Operational vulnerability record is updated to the Assessment in progress state as shown in the example.

## What to do next

When the vulnerability record is in the Assessment state, the task owner creates an assessment-type action task. For more information, see [Manage an assessment-type action task](https://www.servicenow.com/docs/2ZwFiNSDi5aSc0L4_khXuw "Create and manage an action task for the Operational vulnerability, where the type of the task is assessment. You can then assign it to an appropriate task owner.").

When the vulnerability record is in the Treatment state, the task owner creates an investigation-type action task. For more information, see [Manage an investigation-type action task](https://www.servicenow.com/docs/cHca98eOYz5R5rgtijUL7g "Manage an investigation-type action task for the Operational vulnerability. An investigation-type action task is initiated when additional investigation is needed to resolve the vulnerability. If the approver rejects the Operational vulnerability and requests more investigation, the task owner can create an investigation-type of action task, assign it to an appropriate user, review their completed work, and then request an approval again.").

*[\>]: and then


