---
sourceDocument: Yokohama Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/platform-security

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Hardening settings

# Hardening settings {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Hardening settings

The ServiceNow Security Center (SSC) provides hardening settings that detail security-related system properties and plugins within the ServiceNow AI Platform.
These settings can be managed through the Security Center's hardening settings app, which calculates a daily compliance score indicating how closely your instance's security settings align with recommended compliance values.
Show full answer Show less  
Each hardening setting includes attributes such as configuration name, type, data type, recommended and default values, security risk severity (using CVSS scoring), dependencies, functional impact, and reference documentation. Some configurations require assistance from ServiceNow Customer Service and Support.

## Key Features

* **Compliance Scoring:** Daily percentage score reflecting your instance's security compliance based on recommended hardening settings.
* **Comprehensive Configuration Details:** Each setting includes important metadata to help you understand its purpose, impact, and security risk rating.
* **Security Risk Assessment:** Uses CVSS scoring (0.0-10.0) to classify vulnerabilities from None to Critical, helping prioritize remediation efforts.
* **Category-Based Controls:** Hardening settings are organized into categories such as Access Control, API and Web Service, Authentication, Communications, Data Protection, and more, covering a broad range of security domains.
* **Integration with Security Center:** Manage and adjust security configurations directly within the Security Center interface.

## Security Categories Explained

* **Access Control:** Protect resources by managing permissions and credentials effectively.
* **API and Web Service:** Ensure APIs have robust authentication, authorization, and input validation.
* **Architecture, Design, and Threat Modeling:** Incorporate secure design principles including confidentiality, integrity, and privacy.
* **Authentication:** Implement modern authentication methods resistant to impersonation and interception.
* **Business Logic:** Maintain secure application logic flow to prevent bypass and attacks.
* **Communications:** Use strong encryption standards, TLS versions, and secure certificates for all connections.
* **Configuration:** Maintain secure build environments and hardened third-party libraries.
* **Data Protection:** Ensure confidentiality, integrity, and availability of data.
* **Error Handling and Logging:** Manage logged information to avoid exposing sensitive data.
* **File and Resources:** Securely handle files and data from untrusted sources.
* **Malicious Code:** Ensure code is free from vulnerabilities and unwanted functionality.
* **Session Management:** Secure user sessions with unique, unguessable tokens and proper invalidation.
* **Stored Cryptography:** Use established algorithms for encrypting stored data and manage keys securely.
* **Validation, Sanitization, and Encoding:** Protect against injection attacks like XSS and SQL injection by validating inputs properly.

## Practical Benefits for ServiceNow Customers

By leveraging the Security Center's hardening settings, ServiceNow customers can:

* Continuously monitor and improve instance security compliance with actionable scores.
* Understand the security impact and risks associated with each configuration setting.
* Manage security settings in a centralized interface with guidance aligned to industry best practices.
* Prioritize security improvements based on severity and potential impact to your environment.
* Access detailed documentation and recommendations to support secure configuration and operation of your ServiceNow instance.  
The ServiceNow Security Center (SSC) hardening settings content contains detailed descriptions and compliance values for the security-related system properties and plugins in the ServiceNow AI Platform. You can set these properties using the hardening settings app in the Security Center.

## Overview and purpose {#security-hardening-settings__section_e2w_hbx_nkb}

The Security Center calculates a daily compliance score, expressed as a percentage that is based on how compliant your current instance security settings are with the compliance values in Security Center hardening settings.

You can manage the specific security configuration settings that may affect the score for your instance directly from the Security Center.

The hardening settings configurations are explained with several attributes described in the table.
{#security-hardening-settings__table_mtb_wsf_swb__entry__2}

| Configuration attribute | Description |
|-|-|
| Overview | Provides a high level overview of the recommendation. |
| Configuration name | The property or plugin name. |
| Configuration type | Describes where the property can be configured outside of the Security Center, such as in system properties (sys_properties_list.do). |
| Data type | Describes the type of value required for the configuration. Examples are true/false boolean, installation, plugin, string, etc. |
| Recommended value | The value that is recommended by the Security Center to enhance security compliance in your instance. |
| Default value | The value that the configuration is set to in the base system. |
| Category | The name and link to the category for the hardening setting. |
| Security risk | Severity score: The score indicates the potential security risk to your instance as per the likelihood of the vulnerability to be exploited. The security vulnerability is considered and scored individually using the CVSS (Common Vulnerability Scoring System) score on a scale ranging from 0.0 to 10.0. See <https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator> for additional information. |
| Security risk | Severity rating per CVSS score: * Critical: 9.0-10.0 * High: 7.0-8.9 * Medium: 4.0-6.9 * Low: .01-3.9 * None: 0.0 {#security-hardening-settings__ul_osy_nnt_swb} |
| Security risk | Security risk details: Describes the importance of the setting configuration and the risk of not utilizing the recommended configuration. |
| Dependencies and prerequisites | Related settings or configurations that are required before or in conjunction with the hardening configuration. |
| Functional impact | The impact this hardening setting has on the operation of your instance. |
| References | Links to configuration documentation or other helpful information. |
[Table 1. Hardening settings configuration details]

{#security-hardening-settings__table_mtb_wsf_swb}  
Note:  
Some of the configurations can only be completed by Customer Service and Support and will be indicated as such.

To learn more about ensuring your instances meet hardening requirements, see [Security hardening](https://www.servicenow.com/docs/iplnDIlaHiliDY7lYmO9JA "View your hardening compliance score, compare it with previous scores, and change settings to improve your compliance score and security posture in the security hardening page.").

## Other resources {#security-hardening-settings__section_uzn_rbx_nkb}

For user reference, the ServiceNow AI Platform maintains extensive configuration capabilities information in the product documentation. You access most of the security content using the links found in [Secure your instance](https://www.servicenow.com/docs/HW~IuNZAG10IXH9MLYNRRA "Platform security provides capabilities to secure the instance."). Also, see the following:

* [Available system properties](https://www.servicenow.com/docs/access?context=r_AvailableSystemProperties&version=yokohama&pubname=yokohama-platform-administration&ft:locale=en-US)
* General security settings properties
* [High Security Settings](https://www.servicenow.com/docs/9Gp6ESfDBEzGvMQm~zQ41A "High Security Settings refer to several security options available in your instance.")
{#security-hardening-settings__ul_m13_pgc_qkb}
* **[Hardening settings baseline versions](https://www.servicenow.com/docs/rEJ0ZR7AOPq1jv7bsZKRYw)**   
  Explore how baseline versions for hardening settings align with family and store releases.
* **[Access control](https://www.servicenow.com/docs/sLoIn7PGfxwuO~UZl0Tmhw)**   
  The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.
* **[API and web service](https://www.servicenow.com/docs/PUBhR1qmpp353CaefULnRQ)**   
  The API and Web Service category ensures that applications have appropriate authentication, authorization and session management, validate all input that traverses a trust boundary and include security controls for all API types.
* **[Architecture, design, and threat modeling](https://www.servicenow.com/docs/WtfcOxTmzTCkcEJ5R4hScQ)**   
  This broad control addresses high level design considerations and key elements to implement a secure application. This covers the tenants of availability, confidentiality processing integrity, non-repudiation and privacy. Additionally, elements of a secure software development lifecycle are included.
* **[Authentication](https://www.servicenow.com/docs/CpjM6EJi4VZ84cvyemT8Hw)**   
  The authentication category covers the main elements of modern authentication to confirm an entity and its claims are authentic and correct, resistant to impersonation and prevent interception of passwords.
* **[Business Logic](https://www.servicenow.com/docs/onp3Qf5lutXspZlMDC2SPw)**   
  This category looks at the logic and flow unique to each application with general secure principles. Specifically ensure that the intended sequence of business logic flow cannot by bypassed, that limits exist to detect and prevent automated attacks, and that protections against spoofing, tampering, information disclosure and elevation of privilege attacks exist.
* **[Communications](https://www.servicenow.com/docs/qyXwy7NH49JEBlTbVOq8jA)**   
  This control ensures proper encryption using strong algorithms and ciphers. This includes ensuring the recommended version of TLS is used for client connectivity, use of strong cipher suites, use of trusted and signed certificates, ensuring connections are encrypted between components and logging of connection failures.
* **[Configuration](https://www.servicenow.com/docs/WFJwn~TetH3UCR288RF5Yw)**   
  The Configuration category ensures applications have a secure build environment and hardened third party library components. Specifically, ensuring a build and deploy pipeline is repeatable and includes automated testing and prevents known security issues from being deployed. This includes keeping dependencies up to date and free from known vulnerabilities.
* **[Data protection](https://www.servicenow.com/docs/N04EnHLtBrvBJxpzGU2QHQ)**   
  The data protection category addresses the elements of confidentiality, integrity and availability (CIA) of data.
* **[Error handling and logging](https://www.servicenow.com/docs/UmA2txiMuwkPXhfMQxIQQg)**   
  The error handling and logging category addresses the quality and verbosity of logged information exposed to stakeholders.
* **[File and resources](https://www.servicenow.com/docs/LaMYJNHmpMPU24b455f3eg)**   
  The file and resources category ensures applications handle untrusted file data securely and store untrusted data from untrusted sources with limited permissions in an appropriate location.
* **[Malicious code](https://www.servicenow.com/docs/jCJX7MnSZkH6RG8fuRG4fA)**   
  The Malicious Code category ensures that best efforts are made to confirm that your code is free of vulnerabilities and unwanted functionality.
* **[Session management](https://www.servicenow.com/docs/4wvXcp8l0BcUUdlL~tEurw)**   
  This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.
* **[Stored cryptography](https://www.servicenow.com/docs/SEnBBoZVGKFMuPf0rN3tIA)**   
  This category focuses on the encryption of stored data. It encompasses several key aspects, such as employing established algorithms and cryptographic modules, ensuring the proper generation of pseudo-random values, implementing encryption based on data classification, and securely storing and isolating key material.
* **[Validation, sanitization, and encoding](https://www.servicenow.com/docs/5ux6kSi26zIdvY6Bp8tAfw)**   
  Validation, sanitization, and encoding addresses input validation to prevent against vulnerabilities like Cross-Site Scripting (XSS), SQL injection and other attacks.

