Enabling the High Security Plugin ... what to watch out for

Michael Domke
Tera Guru

My company is considering implementing the High Security Plugin. We've used ServiceNow for quite some time (one of the first 100 I believe) and have, as you would expect, created various groups, roles and ACLs to accommodate a wide variety of processes.

We're experiencing tremendous growth and as such many more departments beyond just IT and HR are starting to (or wanting to) rely on ServiceNow. So, security is becoming more of an issue.

My question to this community is to ask what are some of the things we should look out for? I'm sure several pre-High Security Plugin companies have since implemented the plugin and I would be very interested in listening to any comments regarding their experiences after enabling the plugin.

Any specific pain points? What you might have done differently before/after enabling the plugin?

Any feedback would be greatly appreciated.

Thanks,
Michael

14 REPLIES 14

Hello,



I have been looking for some information regarding turning on high security after your instance has been in Production for many years.   Looks like our situation is very similar to yours.  



Just curious have you implemented the high security in your instance yet and if so can you give me some lesson's learned information.  



We are considering turning it on in our DEV instance here in the next month or so.



Thanks,


Denise


We have not made the move to the High Security Plugin yet. But if/when you do, please come back and note any lessons learned.



Michael


any reason's why you haven't turned on?   Any information will help us decide whether to move forward or not.


No other reason other than just time and effort to test.


mdomke pagdenl



I am currently testing the ISTANBUL release after upgrading from FUJI and have found that some OOB ACLs have been updated with the expectation that the High Security Plugin has been enabled.



Our instance does not have the High Security Plugin enabled so we are seeing issues relating to the updated ISTANBUL ACLs.



At this point it feels we just need to bite the bullet,   enable the High Security Plugin and combine it with testing of ISTANBUL.   We do have the Contextual Security plugin enabled so hopefully that will make things a little easier according to valor.