---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Explore

# Exploring Security Posture Control {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Security Posture Control

Security Posture Control (SPC) enables cybersecurity teams to gain comprehensive visibility into their enterprise asset inventory and assess their overall security posture.
By leveraging asset data imported from ServiceNow products like Hardware Asset Management (HAM), ITOM Discovery, and various Service Graph Connectors, SPC provides insights into how well security tools cover assets.
This helps security analysts monitor compliance with internal security standards and prioritize vulnerability remediation effectively.
Show full answer Show less  

## Key Features

* **Asset Security Posture Management (ASPM):** Identifies security tool coverage gaps by comparing asset data gathered via API integrations with third-party tools and ServiceNow products. It highlights assets missing essential security tools such as endpoint protection.
* **Custom Policies and Insights:** Allows Info-Sec teams to create policies based on asset metadata, security tool coverage, and vulnerability data to monitor compliance and detect security gaps.
* **High-Risk Combinations:** Detects assets with risky combinations such as missing security tools, critical vulnerabilities, and internet exposure, requiring integration with Vulnerability Response and vulnerability scanners like Qualys or Rapid7.
* **Mitigation Controls Monitoring:** Provides visibility into how configured security tools mitigate threats to assets, accessible through the SPC Workspace.
* **Automation of Remediation Workflows:** Integrates with the Configuration Compliance application to automatically assign findings and streamline remediation efforts.

## How It Works

SPC relies on accurate CMDB data and API connections established via Service Graph Connectors to aggregate asset information across multiple categories such as endpoint management, network security, cloud providers, and vulnerability assessment. Security posture gaps are identified by comparing asset coverage reported by these tools. Activated policies evaluate assets and generate findings within the Configuration Compliance application for remediation assignment.

## Practical Benefits for ServiceNow Customers

* Gain unified visibility into security tool deployment and asset coverage across on-premises and cloud environments.
* Proactively monitor and enforce internal security compliance standards to reduce risk.
* Prioritize vulnerability remediation based on asset risk profiles informed by SPC insights.
* Automate management of security posture gaps to improve operational efficiency.
* Leverage integrations with existing ServiceNow and third-party security tools for comprehensive security posture management.  
Security Posture Control enables cybersecurity teams to get visibility into their complete enterprise asset inventory and determine their overall security posture.
Security analysts gain insights into how well security tools are deployed and covering their assets based on their asset inventories. This asset data is imported from service graph connectors and
ServiceNow products such as Hardware Asset Management (HAM) and ITOM
Discovery.

Security analysts can also create custom policies and configure insights to monitor the compliance of assets with internal security standards. Vulnerability managers can use insights from Security Posture Control (SPC) to prioritize remediation of vulnerabilities on high-risk assets.

The SPC product is based on Cloud Security Posture Management (CSPM) and Cyber Asset Hygiene Management (CAHM). Security Posture Control consists of two applications that are available by separate subscription from the ServiceNow® Store.
{#spc-overview__id_o2h_qpf_gbc__entry__2}

| Release version | Release notes |
|-|-|
| Security Posture Control Core: v7.1, v7.0 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498). |
| Asset Security Posture Management: v5.5 |   |
| Mitigation Controls Monitoring v4.2 |   |
[ ]

{#spc-overview__id_o2h_qpf_gbc}Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).

With the SPC product, Info-Sec teams can perform the following tasks:

* View security posture insights for your on-premise and cloud assets. SPC helps your Info-Sec teams identify assets that are missing endpoint protection, unmanaged assets, assets exposed to the internet, and any high-risk combinations involving vulnerabilities.
* Monitor your assets for their compliance with internal security tool configuration standards. For example, ensure that the latest version of an endpoint protection product is being used.
* Automate your remediation workflow for the security posture gaps you find with the ServiceNow Configuration Compliance application.
* Create custom policies and insights based on asset metadata, security tool coverage data, and vulnerability data.
* Gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured with [Mitigation Controls Monitoring](https://www.servicenow.com/docs/kYBYCg7wkQEbWyA_k0Xdyw "From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.").
{#spc-overview__ul_rjl_ktm_gyb}

## How Asset Security Posture Management works {#spc-overview__section_ipr_y1y_hyb}

Asset Security Posture Management (ASPM) identifies security tool coverage gaps in assets by using API integrations with various third-party tools (Service Graph Connectors) along with ServiceNow products.

ASPM relies on data populated in your CMDB about your assets. The asset data is imported by various categories of monitoring tools and compared to identify any potential security gaps.

For example, say there is asset data populated in the CMDB that is reported by tools that cover infrastructure monitoring and networking tools. However, this data for those same assets is not
populated or reported by endpoint protection tools. If you compare the asset data reported by these different tools you can see that there are assets missing an endpoint protection agent.

Asset Security Posture Management identifies security tool coverage gaps in assets by using API integrations with various tools (Service Graph Connectors) and ServiceNow products. Categories include but are not
limited to the following:

* Digital Employee Experience
* Discovery
* Endpoint Management
* IT Asset Management
* Infrastructure Monitoring 
* Networking
* Network Security
* Network Performance Monitoring
* Configuration and Patch Management  
* Endpoint Protection
* Cloud Provider
* Application Performance Monitoring
* Directory Services
* Vulnerability Assessment
{#spc-overview__ul_wwp_fcy_hyb}

## The Security Posture Control workflow {#spc-overview__section_gjj_gvb_ccc}

Identifying security tool gaps involves the following steps:

1. Set up and activate API connections with any of the tools that you are using in various categories. You can use Service Graph Connectors for products that are available from the ServiceNow Store for the API connections that are required. For more information about the supported service graph connectors, see [Service Graph Connectors](https://www.servicenow.com/docs/access?context=cmdb-sgc-available&version=zurich&pubname=zurich-servicenow-platform&ft:locale=en-US). Supported service graph connectors are available from the ServiceNow® Store with separate subscriptions.
2. Activate the policies shipped with the Security Posture Control application. The Security Posture Control product finds security tool gaps by performing the following tasks:
   1. Identifies the list of all unique assets populated by various Service Graph Connectors in the CMDB.
   2. Identifies assets that are not reported by specific categories from this asset pool, for example, Endpoint Protection. Assets are identified based on the active policy that is being evaluated.
   3. Assets identified as not reported by specific categories are reported as 'Findings' or 'Test Results' in the Configuration Compliance application.
   {#spc-overview__ol_cdf_3pn_lcc}
3. Automatically assign 'Findings' to different teams for remediation with the Configuration Compliance application.
{#spc-overview__ol_utn_l2y_hyb}

## High-risk combinations {#spc-overview__section_m1n_w5b_ccc}

With Asset Security Posture Management, you can also identify assets that have high-risk combinations. An example of a high-risk combination might show assets that are missing security tools, have critical
vulnerabilities, and are exposed to the internet.

Some of the policies shipped with the Security Posture Control application look for these high-risk combinations of critical vulnerabilities and security tool coverage gaps. However, for these combination policies to work, you must have the Vulnerability Response application and at least one vulnerability scanner integration product. Products such as Qualys, Rapid7, or the Tenable Vulnerability Integration application installed. These applications are available with separate subscriptions from the ServiceNow Store.

## Mitigation Controls Monitoring {#spc-overview__section_mdb_rdz_fdc}

From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured. See [Mitigation Controls Monitoring](https://www.servicenow.com/docs/kYBYCg7wkQEbWyA_k0Xdyw "From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.") for more information.

