Combined Continuous Authorization and Monitoring release notes for upgrades from Yokohama to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 8 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Continuous Authorization and Monitoring Release Notes for Upgrades from Yokohama to Zurich

    This consolidated release note provides ServiceNow customers with key information about upgrading Continuous Authorization and Monitoring (CAM) from the Yokohama release to Zurich. It summarizes new features, changes, and important upgrade tasks to help ensure a smooth transition and to leverage enhanced capabilities in governance, risk, and compliance (GRC) workflows.

    Show full answer Show less

    Key Features

    • OSCAL Import and Export Enhancements: Import catalog and System Security Plan (SSP) models via a new OSCAL Import landing page with import status tracking. Export control objectives and authorization packages in OSCAL format, including SSP and Plan of Action and Milestones (POA&M) files directly from the authorization package.
    • Microsoft Word ATO Artifacts: Generate consistent and shareable Authorization to Operate (ATO) artifacts, such as Security Assessment Plans, ATO letters, and executive summaries, using Microsoft Word templates within CAM Workspace.
    • CAM Workflow Configuration (Zurich): Administrators can now create, manage, and version multiple custom workflows within packages, define custom GRC state models, configure approvals, perform risk assessments, and migrate the NIST Risk Management Framework (RMF) flow for improved standardization.
    • Boundary Management Enhancements: Introduces a Child Boundaries list to create one-to-many boundary hierarchies, visualized in sidebar and diagram views. Dynamic boundary filters can be enabled to automatically update system elements based on filter conditions.
    • Boundary Operational Status Automation: Boundary status now automatically synchronizes with the package life cycle, transitioning to Operational or Reauthorize states as the package progresses or authorization dates approach.
    • OSCAL Import Playbook Improvements: Supports importing individual POA&M JSON files, automatic user and group mapping by exact name matches to ServiceNow records, and automatic population of roles and responsibilities in packages for streamlined data integration.
    • Overlay Policy Enhancements: Apply policies as overlays on authorization packages to add, subtract, or customize control objectives, allowing tailored impact on baseline controls.
    • New User Interface Elements: CAM Workspace features card-based containers, vertical authorization boundaries, and a new Authorization Documents tab to access ATO reports more conveniently. The Ageing of Packages widget helps track package progress through lifecycle steps.
    • System Administration Improvements: A new CAM System Properties page allows administrators to configure system-wide properties, and automated audit generation can be scheduled by setting the Next Engagement Date.

    Important Upgrade Considerations

    • Review and complete required pre- and post-upgrade tasks to ensure configuration alignment and system coherence.
    • All new features and enhancements are designed to improve process standardization, reporting consistency, and operational efficiency within CAM.
    • No features were removed or deprecated between Yokohama and Zurich releases.
    • Installation continues to be managed through the ServiceNow Store.
    • There are no changes to browser requirements, localization, or accessibility noted for this upgrade.

    What to Expect After Upgrading

    • Improved OSCAL model handling with enhanced import/export workflows and detailed preview capabilities.
    • Greater flexibility in governance workflows through customizable and versioned CAM workflows.
    • Enhanced boundary management with hierarchical relationships and automated status synchronization aligned to package lifecycle.
    • Simplified and consistent generation of compliance documentation in Microsoft Word format for easier sharing and review.
    • Streamlined administrative controls and audit scheduling features for efficient system management.
    • A more modern and organized user interface for better navigation and monitoring of authorization packages.

    Consolidated page of all release notes for Continuous Authorization and Monitoring from Yokohama to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Continuous Authorization and Monitoring release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Continuous Authorization and Monitoring to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    New features

    Between your current release family and Zurich, new features were introduced for Continuous Authorization and Monitoring.

    Release Release notes

    Yokohama

    OSCAL Import landing page
    Import files for catalog and SSP models on the new OSCAL Import landing page. Once the import process is initiated, you can check the status under the Import status section.
    OSCAL Export button
    Export selected control objectives in the OSCAL format with the new OSCAL Export button while in the control objectives list view.
    ATO artifacts in Microsoft Word
    Generate ATO artifacts from an authorization package in the Microsoft Word format. In CAM Workspace, you can use the Generate SSP drop-down list in a selected authorization package to generate the following reports:
    • Security Assessment Plan (SAP)
    • Authorization to Operate (ATO) Letter
    • Executive Summary

    This enhancement verifies that all ATO artifacts are formatted consistently and can be shared and reviewed.

    Zurich

    [Placeholder link text to key cam-workflow-configurator]
    Streamline governance, risk, and compliance processes with the CAM Workflow Configuration. This feature allows administrators to:
    • Create and manage multiple workflows within a package.
    • Define GRC State Models for custom workflows.
    • Configure and version workflows.
    • Evaluate workflow version impacts to retrieve baseline controls.
    • Set up workflow-specific approval configurations.
    • Perform risk assessments across CAM objects.
    • Migrate the NIST RMF flow to workflow configuration for improved standardization.
    [Placeholder link text to key add-child-boundary]
    Introducing a new Child Boundaries list that enables a one-to-many boundary hierarchy, allowing you to create relationships between boundaries. This hierarchy is visualized in both the sidebar and diagram view, showing one parent boundary with multiple child boundaries. OSCAL export and import now include the parent boundary relationship if present.
    Dynamic Boundary Filters Dynamic boundary filters
    Select the Dynamic Filter option in boundary filters to update system elements according to filter conditions. When disabled, the system elements remain unchanged. This update enhances the flexibility of boundary filter management.
    Boundary operational status automation
    Linking boundary operational status to the package life cycle ensures seamless integration. Key changes include:
    • Automatic update of boundary status to Operational when a package moves to the Monitor state.
    • Transition of Boundary status to Reauthorize as the Package Authorization date approaches. This update maintains synchronization between package and boundary states, enhancing overall system coherence.
    [Placeholder link text to key export-oscal-files-from-authorization-package]
    Generating and downloading OSCAL SSP and POA&M files is supported directly from within a authorization package. The supported file types include:
    • Catalog
    • Overlay Catalog
    • Profile
    • SSP
    • POA&M
    OSCAL import enhancements
    Enhancing the OSCAL import experience, the OSCAL import playbook now allows you to:
    • Import individual POA&M JSON files.
    • User Mapping: Automatically map users to existing ServiceNow users based on exact name matches, with the option to manually adjust mappings.
    • Group Mapping: Automatically map groups to existing ServiceNow groups based on exact name matches, with the option to manually adjust mappings.
    • Roles and Responsibilities: Populate relevant package fields with roles and responsibilities.
    Overlay enhancement
    Apply policies as an overlay in an authorization package to determine how the control objectives in the policy impact the baseline. This can be done in the following ways:
    • Addition: Create control objectives to address specific requirements not covered in the baseline.
    • Subtraction: Move existing control objectives to Not Applicable.
    • Customization: Create, move existing control objectives to not applicable, or skip control objectives.
    OSCAL enhancements
    Use the OSCAL import playbook to follow a user-friendly, step-by-step approach for importing OSCAL models. Using the playbook, you can:
    • Add multiple Catalog overlay files.
    • Preview OSCAL data before importing them to confirm accuracy. You can preview the following:
      • Authorization boundary
      • Authorization package
      • System elements
      • Information types
      • Baseline controls
      • Inherited controls
      • Hybrid controls
      • Not applicable controls
      • Policies
      • Control objectives
      • Control objectives requirements
    • Skipped objects in the preview, such as control objectives, policies, authorization boundaries and packages can be individually overridden.

    Changes

    Between your current release family and Zurich, some changes were made to existing Continuous Authorization and Monitoring features.

    Release Release notes

    Yokohama

    Generate the OSCAL SSP model of an authorization package
    Export the SSP model of an authorization package in the OSCAL format. The exported report contains only the control objectives linked to the authorization package and their additional information, such as inherited controls and the hierarchy of the control objectives.
    Generate ATO artifacts in Microsoft Word and HTML templates
    Use the Document designer plugin (com.sn_grc_doc_design) to create report templates in Microsoft Word. A new property module has been introduced to select the template type as a Microsoft Word template in addition to an HTML template.

    Zurich

    New Authorization Documents tab for ATO reports
    Access all Authority to Operate (ATO) artifacts reports from the new Authorization Documents tab available in the Authorization Package.
    New CAM System Properties page for administrators
    Access the new CAM System Properties page to enable administrators to configure various system properties.
    Track package progress with the Ageing of Packages widget
    View the duration that a package stayed in each step, like Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor, using the Ageing of Packages widget.
    Set Next Engagement Date for Automated Audit Generation
    Enter the Next engagement date to automatically generate the audit engagement on the specified date.

    Removed

    Between your current release family and Zurich, some Continuous Authorization and Monitoring features or functionality were removed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Continuous Authorization and Monitoring features or functionality were deprecated.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Continuous Authorization and Monitoring.

    Release Release notes

    Yokohama

    Install CAM by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install CAM by requesting it from the ServiceNow Store.

    Additional requirements

    If any additional requirements were introduced or changed for Continuous Authorization and Monitoring we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Continuous Authorization and Monitoring we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Continuous Authorization and Monitoring, such as specific requirements or compliance levels.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Localization information

    If there are specific localization considerations for Continuous Authorization and Monitoring we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Continuous Authorization and Monitoring we have noted them here.

    Release Release notes

    Yokohama

    • Import catalog and System Security Plan (SSP) models with the new CAM Open Security Controls Assessment Language (OSCAL) import landing page.
    • Export and import SSP models and catalog models in the OSCAL format.
    • Export control objectives as a catalog in the OSCAL format.
    • Generate additional reports in Microsoft Word format, such as a Security Assessment Plan (SAP), Authorization to Operate (ATO) Letter, and Executive Summary.
    • Generate reports based on a Microsoft Word template.

    See Continuous Authorization and Monitoring for more information.

    Zurich

    • Simplify Governance, Risk, and Compliance processes by enabling admins to create, version, and manage custom workflows, define state models, configure approvals, assess risks, and standardize with NIST RMF migration.
    • The CAM workspace homepage now features card-based containers with headers, sidebars, and overviews for a more organized and modern experience.
    • Authorization boundaries and package layout are now vertical. New Boundary Type and Classification records are included in OSCAL export file.
    • Add a Child Boundaries to create one-to-many relationships between boundaries. You can view the parent-child boundary mapping of a authorization boundary in the Highlighted details panel under the Boundary hierarchy section.
    • Select the Dynamic Filter option to make boundary filters update system elements automatically based on conditions, enhancing filter flexibility.
    • Boundary operational status now automatically syncs with the package life cycle.
    • Generate and download Open Security Controls Assessment Language (OSCAL) System Security Plans (SSP) and Plan of Action and Milestones (POA&M) files directly from within a package.
    • The OSCAL import playbook now supports importing single POA&M JSON files, automatically maps users and groups by exact names to ServiceNow, and populates package roles and responsibilities for a streamlined import experience.
    • CAM overlays new capability has been introduced to perform various operations like addition, subtraction, custom while applying a policy overlay to an authorization package.
    • Import OSCAL models using a user-friendly playbook that guides you through preview and customization steps.

    See Continuous Authorization and Monitoring for more information.