GRC: NIST CSF Use Case Accelerator release notes
Summarize
Summary of GRC: NIST CSF Use Case Accelerator release notes
The GRC: NIST CSF Use Case Accelerator is an application available on the ServiceNow Store designed to support governance, risk, and compliance initiatives aligned with the NIST Cybersecurity Framework (CSF). It provides structured content, controls, and workflows to help organizations manage cybersecurity risk effectively within the ServiceNow platform. The release notes detail version updates, enhancements, fixes, and ongoing compatibility with ServiceNow platform families.
Show less
Key Enhancements and Updates
- Query Range ACLs (Version 22.3.1, June 2026): Standardized query range security ACLs were introduced across all tables to ensure consistent access control. Upgrades are automated, requiring no manual administrator actions, and any custom ACLs should be reviewed post-upgrade to maintain intended security policies.
- Control Objective Workflow Restrictions (Version 22.0.1, March 2026): Business workflows are now limited to current version control objective records only. Draft control objectives cannot be associated with NIST CSF activity objects in Gap tables, ensuring data integrity and version control.
- Activation of GRC Choices (Version 21.1.0, December 2025): GRC choices used within the accelerator can be toggled active or inactive via a new Active field, improving configuration flexibility.
- Role Fixes and Licensing (Versions 20.1.1 and 16.0.2): Control provider role restrictions and license tracking were improved, preventing unauthorized updates and enhancing role-based report access.
- NIST CSF 2.0 Content (Version 19.0.1, August 2024): The accelerator was updated with NIST CSF 2.0 content, including authority documents, citations, policies, and control objectives to keep compliance frameworks current.
- Dashboard Migration (Version 18.1.0, June 2024): Dashboards were migrated to the Analytics workspace, providing enhanced data visualization and reporting capabilities within ServiceNow.
Compatibility and Maintenance
The application maintains compatibility with multiple ServiceNow platform releases, starting from Madrid through to the Australia release family. Automated upgrade scripts and fixes have been implemented to ensure smooth transitions between versions, maintain security, and optimize application size and performance.
Practical Impact for ServiceNow Customers
- Enables consistent and secure querying of NIST CSF-related records with enhanced ACL management.
- Supports accurate version control of control objectives to maintain compliance integrity.
- Allows administrators to manage GRC choice lists dynamically, improving configuration agility.
- Keeps NIST CSF content current with the latest framework versions to support regulatory requirements.
- Improves analytics and reporting through dashboard migrations to the Analytics workspace.
- Ensures seamless upgrades with minimal administrative overhead and clear post-upgrade review steps.
Version history for the GRC: NIST CSF Use Case Accelerator Use Case Accelerator on the ServiceNow Store.
Version history
- Version 22.3.1 - June 2026 (Australia)
-
- New:
- Query range ACLs include the following enhancements:
- Consistent access control — All tables include standardized query range security ACLs. These ACLs ensure that authenticated users with appropriate read permissions can query records consistently across the platform.
- Seamless upgrade experience — New query ACL rules are installed automatically during upgrade, with no administrator action required. Automated upgrade scripts handle the transition, including detecting and processing previously customized ACLs to ensure existing processes continue without interruption.
- Query range ACLs include the following enhancements:
- Post-upgrade review for customized ACLs: If the instance includes administrator-modified query range ACLs, review those records after upgrade to confirm they align with the intended access policy.
- New:
- Version 22.0.1 - March 2026
- Changed:
- Allow business workflow on control objective current version records only
- Prevent association of control objectives which are working drafts to NIST CSF activity objects in the Gap table
- Updated control objective content records with record nature field as Current version and state as published
- Changed:
- Version 21.1.0 - December 2025 (Zurich)
- New: GRC choices used for the NIST CSF Use Case Accelerator can be activated or deactivated with the new Active field.
- Version 20.1.1 - May 2025
- Fixed: Control provider role was able to create and update Orient targets.
- Version 20.0.0 - February 2025
- Fixed:
- Localization issues
- More than one Target without entity
- Fixed:
- Version 19.0.1 - August 2024
- New: Added NIST CSF 2.0 content - authority document, citations, policies, and control objectives.
- Version 18.1.0 - June 2024
- New: Migrated dashboards to Analytics workspace.
- Version 18.0.1 - February 2024
- Fixed: On the risk statements, source is showing incorrect value.
- Version 17.0.0 - August 2023
- Fixed: Cleaned up auto generated business rules as the functionality is already handled.
- Version 16.0.2 - February 2023
- Fixed:
- Enabled license tracking for Risk executive, Security officer, User, and Control provider roles.
- Access controls for viewing reports.
- Reduction in installation size of the application.
- Fixed:
- Version 14.1.3 - March 2022
- Changed: Support for multiple controls
- Version 11.0.0 - October 2020
- Changed: Enabled report_view_acl by default
- Version 10.1.0 - June 2020
- Changed: The internal plugin name has been changed
- Version 9.0.1 - November 2019
- This application was released for the Madrid family release and is still compatible with New York.
- Version 7.0.1 - May 2019
- Initial release to the ServiceNow Store.