Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Report on daily security health check

Ankit Kumar6
Tera Contributor

Hi Team,

I need to understand whether ServiceNow can provide reporting and monitoring for the following security and compliance scenarios:

  1. Unauthorized or Out-of-Ordinary Access
    • Can we identify users who were granted privileged roles (e.g., admin, security_admin) without an approved request or change record?
    • Can we detect unusual login activity such as failed login spikes, after-hours access, or access from unexpected locations/IPs?
  2. Data Access and Export Anomalies
    • Can ServiceNow report on users who accessed or exported unusually large volumes of data?
    • Is there a way to track exports (CSV, Excel, XML, PDF) by user, date, application, and record count?
    • Are there any built-in anomaly detection or audit capabilities for data access patterns?
  3. Unrecognized or Unapproved Changes to the Environment
    • Can we identify configuration changes, script changes, ACL changes, business rule modifications, or update sets deployed without an approved Change Request?

Please Advice on this

 

Thanks

Ankit

0 REPLIES 0