<h2>Report an operational vulnerability from the Self-attestation module</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="task" /><meta name="DC.title" content="Report an operational vulnerability from the Self-attestation module" /><meta name="abstract" content="Report an Operational vulnerability from the Self-attestation module in the Operational Resilience Workspace." /><meta name="description" content="Report an Operational vulnerability from the Self-attestation module in the Operational Resilience Workspace." /><meta name="DC.relation" scheme="URI" content="../../../product/grc-operational-res/concept/reporting-operational-vul.html" /><meta name="DC.relation" scheme="URI" content="../../../product/grc-common/reference/r_WhatIsGRC.html" /><meta name="DC.relation" scheme="URI" content="../../../product/grc-operational-res/reference/grc-opres-landing-page.html" /><meta name="DC.relation" scheme="URI" content="../../../product/grc-operational-res-ws/concept/working-in-opres-ws.html" /><meta name="DC.relation" scheme="URI" content="../../../product/grc-operational-res/concept/operational-vulnerability.html" /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2024-09-30T10:28:32-07:00" /><meta name="DC.date.modified" content="2025-01-30" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="report-op-vul-from-attestation" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Report an operational vulnerability from the Self-attestation module</title></head><body id="report-op-vul-from-attestation"> <div class="breadcrumb"><a class="link" href="../../../product/grc-common/reference/r_WhatIsGRC.html" title="Respond to business risks in real time. Connect security and IT with an integrated risk program offering continuous monitoring, prioritization, and automation.">Governance, Risk, and Compliance</a> > <a class="link" href="../../../product/grc-operational-res/reference/grc-opres-landing-page.html" title="Operational Resilience is the ability of an organization to respond to the adverse operational events by anticipating, preventing, recovering from, and adapting to such events.">Operational Resilience</a> > <a class="link" href="../../../product/grc-operational-res-ws/concept/working-in-opres-ws.html" title="Starting with GRC version 16.x.x, a new workspace has been introduced for the GRC: Operational Resilience application. You can use Operational Resilience Workspace for managing your resilience tasks and monitoring the resilience metrics from a single dashboard.">Managing Operational Resilience</a> > <a class="link" href="../../../product/grc-operational-res/concept/operational-vulnerability.html" title="Operational vulnerabilities are weaknesses in systems, processes, or procedures that can be exploited by attackers to compromise the security and integrity of an organization's operations. These vulnerabilities can arise from a variety of factors, including IT and non-IT operations.">Managing Operational vulnerability</a> > </div> <h1 class="title topictitle1" id="ariaid-title1">Report an operational vulnerability from the Self-attestation module</h1> <div class="body taskbody"><p class="shortdesc">Report an <span class="ph">Operational vulnerability</span> from the Self-attestation module in the <span class="ph">Operational Resilience Workspace</span>.</p> <div class="section prereq p"> <p class="p">Role required: sn_oper_res.manager</p> </div> <ol class="ol steps" id="report-op-vul-from-attestation__steps_mqj_mls_tcc"><li class="li step stepexpand"> <span class="ph cmd">Navigate to <span class="ph menucascade"><span class="ph uicontrol">Workspaces</span> > <span class="ph uicontrol">Operational Resilience Workspace</span> > <span class="ph uicontrol">Self-attestations</span></span>.</span> <div class="itemgroup info">A list of the available Self-attestations is displayed.</div> </li><li class="li step stepexpand"> <span class="ph cmd">Select a Self-attestation record from the list.</span> <div class="itemgroup info">If you create a Self-attestation record and save it, the Operational vulnerabilities related list is displayed.</div> <div class="itemgroup stepresult">The Self-attestation record with the Operational vulnerabilities related list is displayed.</div> </li><li class="li step stepexpand"> <span class="ph cmd">Check the state of the Self-attestation record.</span> <div class="itemgroup info"> <p class="p">If the self-attestation is in the <span class="ph uicontrol">Attestation received</span> state, you cannot add or remove a vulnerability at this stage.</p> </div> </li><li class="li step stepexpand"> <span class="ph cmd">Add a service to the self-attestation record.</span> </li><li class="li step stepexpand"> <span class="ph cmd">Open the Service record, select <span class="ph uicontrol">More</span> and add the <span class="ph uicontrol">Operational vulnerabilities</span> related list.</span> </li><li class="li step stepexpand"> <span class="ph cmd">Select <span class="ph uicontrol">New</span> in the Operational vulnerabilities related list and add an operational vulnerability.</span> </li><li class="li step stepexpand"> <span class="ph cmd">On the Vulnerability New record form, fill in the fields.</span> <div class="itemgroup info"> <p class="p">The source of the vulnerability is the Self-attestation. Therefore, the <span class="ph uicontrol">Source</span> field on the form shows the source as Self attestation and the <span class="ph uicontrol">Source table</span> field on the form shows the table as Self attestation. The <span class="ph uicontrol">Source table</span> field is auto-filled.</p> <p class="p">To view more information on the fields, see the <a class="xref" href="../reference/create-new-op-vul-form.html" title="On the Create New Operational vulnerability form, fill in the fields.">Create New Operational vulnerability form</a>.</p> </div> </li><li class="li step stepexpand"> <span class="ph cmd">Select <span class="ph uicontrol">Save</span>.</span> <div class="itemgroup info"><p class="p">The following example shows how the Self-attestation record is displayed in the Operational vulnerabilities related list and the <span class="ph">Operational vulnerability</span> is associated with the Self-attestation for critical services.</p> <img class="image" id="report-op-vul-from-attestation__image_uzd_gn1_xcc" src="../image/op-vul-added-for-service-attest-record.png" alt="Attestation record." /></div> </li><li class="li step stepexpand"> <span class="ph cmd">Select <span class="ph uicontrol">Save</span>.</span> <div class="itemgroup stepresult"> <p class="p">The Self-attestation record is saved.</p> </div> </li></ol> </div> <div class="related-links"> <div class="familylinks"> <div class="parentlink"><strong>Parent Topic:</strong> <a class="link" href="../../../product/grc-operational-res/concept/reporting-operational-vul.html" title="Any Operational Resilience application user can report an operational vulnerability that needs the attention of the Operational Resilience team.">Reporting Operational vulnerability</a></div> </div> </div></body></html></div>