Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Dot-Walk Scoping Security Enhancement - How Are You Approaching Assessment, Readiness, and Prioritiz

Jeff Boltz1
Mega Guru

Dot-Walk Scoping Security Enhancement - How Are You Approaching Assessment, Readiness, and Prioritization?

Our organization recently began assessing Dot-Walk Scoping Security Enhancement and I'd be interested in hearing how other customers are approaching it.

 

What initially appeared to be a fairly straightforward communication quickly expanded into multiple KB articles, prerequisite configuration requirements, CrossScopeAccess logging analysis, CSP/RCA considerations, and broader implementation planning discussions.

 

One challenge we're working through is that the effort naturally seems to split into two parallel tracks:

 

Track 1 - Customer Assessment Activities

  • Identify CrossScopeAccess activity
  • Understand business processes generating the access
  • Assess enforcement impact
  • Evaluate CSP and RCA requirements
  • Develop governance recommendations
  • Create implementation and testing plans

Track 2 - Platform / Implementation Prerequisites

  • Logging configuration
  • Environment readiness
  • Documentation interpretation
  • Role and permission requirements
  • Vendor guidance and support engagement

At this point, we've chosen to treat the effort primarily as a readiness and risk assessment exercise rather than an implementation project.

 

Our objectives are currently:

  1. Understand where cross-scope access exists.
  2. Determine which business processes depend on that access.
  3. Assess potential impact if enforcement is enabled in the future.
  4. Establish ownership and accountability.
  5. Develop a production readiness assessment and implementation playbook.

One question that continues to come up internally is prioritization.

 

Many organizations have active project, enhancement, and development backlogs competing for the same resources. Without a clearly communicated enforcement timeline, it can be difficult to determine how aggressively this effort should be prioritized.

 

Questions for the Community

  • How are you approaching COMM2808078?
  • Are you treating this as an assessment effort, an implementation effort, or both?
  • Have you established dedicated workstreams by application area?
  • Have you encountered prerequisite, role, or permission challenges during setup?
  • Have you identified any undocumented implementation requirements?
  • Has ServiceNow provided any guidance regarding future enforcement timelines or target releases?
  • How are you balancing this work against ongoing development and enhancement activities?

I'm particularly interested in hearing from organizations that have already completed an assessment and can share lessons learned, governance approaches, or implementation strategies.

 

Thanks in advance for any insights.

0 REPLIES 0