Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create Operational vulnerability form

On the Create New Operational vulnerability form, fill in the fields.

FieldDescription
NumberNumber of the vulnerability. This field is automatically set.
NameName of the vulnerability. For example, `Environmental vulnerability`.
DescriptionDescription of the vulnerability.
StateWorkflow state of the vulnerability. This field is automatically set to New.
TypeNature or type of the vulnerability. This field is automatically set to Vulnerability Type.
SeveritySeverity of the vulnerability. The choices are as follows:- Low - Medium - High - Critical
Sub-typeSub type of vulnerability. For example, Documentation Loss.
Priority

Priority of the vulnerability. The choices are as follows:- 1 - Critical - 2- High - 3 - Moderate - 4 - Low - 5 - Planning - None

Note: The default value in this field is set to Planning.

Primary entityEntity impacted by the case. Only the entities identified in the impacted areas are available for selection as the primary entity.
Entity ownerUser who is the owner of the entity. This field is automatically set based on the entity selected in the Impacted areas related list.
Personal information
Contains personal informationField to decide if the breach contains personal information. The choices are as follows:- To be decided: Select this option if you’re not sure if the breach has personal information. - Yes: Select this option if the breach has personal information. - No: Select this option if the breach doesn’t have personal information.
Number of impacted individualsNumber of people impacted by the case.
Categories of data subjects/individuals impactedDefine who is impacted by the case. The choices are as follows:- Customers - Employees
Assignment
RequesterPerson who reported the vulnerability.
Assignment groupGroup assigned to the case. Note: The assignment group is preconfigured to the case type during configuration setup.
ApproversApprovers of the vulnerability.
Requested on behalf ofName of the person on whose behalf you’ve created the vulnerability.
AnalystAnalyst who will analyze and work on the vulnerability. The analyst is a part of the Assignment group.
Watch listPeople who must be aware of the vulnerability.
Primary origin
LocationLocation where the vulnerability occurred. For example, the location is Japan.
Impacted business unitBusiness unit that is impacted by the breach.
Sub-locationSub-location of the vulnerability occurrence. For example, the sub location is Tokyo.
SourceSource of the vulnerability creation. This field is automatically set to Manual when the operational vulnerability is manually created. If the operational vulnerability is reported from the Employee Center, the field displays the source as Employee Center. The Operational Resilience manager can update the source or add the new source to the related area.
Impacted departmentDepartment impacted by the vulnerability. The choices are as follows:- Finance - HR - IT - Marketing - Sales
Source tableSource table from where the vulnerability is created.
Source recordSource record of source object from where the vulnerability is created. For example, if the vulnerability is reported from risk events, then this field displays the name of the risk event from which the vulnerability is reported.
Schedule
Date of occurrenceDate that the vulnerability occurred on. For example, the vulnerability may have occurred on 18-02-2024.
Date of discoveryDate that the vulnerability is discovered by you. For example, the vulnerability may have occurred on 18-02-2024, but is discovered by the user only on 12-03-2024.
Due dateDate that the vulnerability is due on.
Closed dateDate that the vulnerability is closed on.
Reported dateDate that the vulnerability gets reported on.
Assessment start dateStart date for the assessment or date that the vulnerability was analyzed on.
Pending approval start dateDate that the vulnerability was resolved on.
Approved datePost case review date of the vulnerability.
Findings
TreatmentDecision made for the treatment. The choices are as follows:- Accept - Avoid - Mitigate - Transfer - None
Root cause analysis
Root causePrimary cause of the vulnerability occurrence.
Activity
Work notes \(Private\)Notes or information regarding the vulnerability.
Comments \(Customer visible\)Additional information regarding the vulnerability for the customers.
EmailOption to compose an email about the vulnerability to the stakeholders.
AttachmentsOption to attach the PDF of the vulnerability.
Action tasksAction tasks associated with the vulnerability.
Primary originPrimary origin of the vulnerability.
Impacted areasImpacted areas related to the vulnerability.
IssuesIssues related to the vulnerability.
ApproversApprovers of the vulnerability.