Skip to content
Release: Australia · Updated: 2026-06-01 · Official documentation · View source

Reporting Operational vulnerability

Any Operational Resilience application user can report an operational vulnerability that needs the attention of the Operational Resilience team.

Users of the Operational Resilience feature can report an operational vulnerability using one the following options:

States of the vulnerability

An operational vulnerability record moves through the following workflow states.

StatesDescription
NewThe vulnerability has been opened and it is in the initial stage of review.
AssessmentThe vulnerability is being evaluated to determine the appropriate course of action.
TreatmentThe vulnerability is being actively investigated to gather information and evidence. The course of action and treatment is being decided.
Pending approvalThe vulnerability is being worked on to find a resolution.
ApprovedA review of the vulnerability is being done after it is resolved.
ClosedThe vulnerability is closed and is no longer active.
CanceledThe vulnerability is canceled and it is no longer being pursued.

Email notifications for the vulnerabilities

When the vulnerability is assigned to the users, they receive email notifications informing them about the vulnerability details, upcoming actions, and due dates. Email notifications are sent to the following users:

  1. When the vulnerability is assigned to an analyst or a user, they receive the email notifications.
  2. When the vulnerability is approved or rejected, the analyst receives the email notification.
  3. When the vulnerability is canceled, the approver, requester, analyst, and people on the watchlist receive the email notifications.