---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use mitigation controls

# Using mitigation controls monitoring with Security Posture Control {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using mitigation controls monitoring with Security Posture Control

Security Posture Control (SPC) enables ServiceNow customers to gain comprehensive visibility into how their enterprise assets are protected by mitigation controls.
By integrating with various security tools, SPC identifies which threats and vulnerabilities are mitigated based on the configuration of these controls.
This capability helps organizations understand security coverage gaps and improve their overall security posture.
Show full answer Show less  

## Key Features

* **Asset Inventory:** Identifies all enterprise assets, including unmanaged or unknown ones, to ensure complete visibility.
* **Security Controls Coverage and Health:** Detects any gaps in security control coverage across assets.
* **Vulnerability and Threat Mitigation Visibility:** Shows which threats or vulnerabilities are mitigated by existing controls, enhancing risk management.
* **API Integrations:** Connects with security tools like web application firewalls and endpoint protection via APIs to gather configuration data that informs mitigation control status.
* **Service Graph Connector and ITOM Discovery:** Required to complement API integrations by providing foundational asset and configuration data.

## Roles and Access

* **Admin:** Responsible for installing applications and activating necessary plugins such as ITOM Discovery.
* **SPC Admin and Analyst Groups:** Have full read/write access to SPC records and workspace.
* **SPC Analyst Read Only Group:** Have full read access to SPC records.

## Benefits for Users

* **Cybersecurity Teams and Security Analysts:** Obtain visibility into all enterprise assets and identify critical security gaps and toxic problem combinations.
* **Vulnerability Management Teams:** Understand mitigation options for vulnerabilities and dynamically adjust risk scores accordingly.
* **Threat Defense Teams:** Identify gaps in mitigation controls related to specific attack techniques to strengthen defense strategies.

## Practical Application

Within the SPC Workspace, users configure API integrations with supported security tools to import mitigation control data. For example, activating both the CrowdStrike Service Graph Connector and the CrowdStrike API integration provides enriched insights into endpoint protection controls. This layered integration approach allows organizations to accurately assess and improve their mitigation controls based on real-time configuration data from multiple sources.  
From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.

## Mitigation controls monitoring {#spc-mitigation-exploring__cf-exploring-parent-overview}

For supported applications for Security Posture Control and Mitigation Controls Monitoring, see [Exploring Security Posture Control](https://www.servicenow.com/docs/IlqPPNk5B3oZInfnN6utsA "Security Posture Control enables cybersecurity teams to get visibility into their complete enterprise asset inventory and determine their overall security posture.").  
The Security Posture Control application focuses on three core problem areas:

* Asset inventory - Identifying all your enterprise assets that include unmanaged or unknown assets.
* Security controls coverage and health - Identifying any coverage gaps with your security controls
* Vulnerability and threat mitigation visibility - Identifying which threats or vulnerabilities to your assets are mitigated by applicable mitigation controls.
{#spc-mitigation-exploring__ul_l3n_h3t_pcc}

Mitigation controls monitoring describes the features in Security Posture Control that fall under vulnerability and threat mitigation visibility.  
Roles required:

* admin - Installs applications from the ServiceNow® Store and activates plugins (ITOM Discovery).
* SPC Admin Group and SPC Analyst Group - Users in this group have full read and write access to all the records for the product and the workspace.
* SPC Analyst Read Only Group - Users in this group have full read access to all the records for the product.
{#spc-mitigation-exploring__ul_k12_sp1_qcc}

## Mitigation controls monitoring users and benefits {#spc-mitigation-exploring__cf-exploring-parent-users}

{#spc-mitigation-exploring__table_pss_ygt_pcc__entry__2}

| User | Description |
|-|-|
| Cybersecurity teams, Security analysts and managers | * Gain visibility into all your enterprise assets that include unmanaged or unknown assets. * Identify coverage gaps with your security controls, toxic combinations of problems such as critical vulnerabilities and internet exposure on your assets, and deviations from your internal security standards. {#spc-mitigation-exploring__ul_pw3_2mt_pcc} |
| Vulnerability management teams | Gain insights in mitigations available for vulnerabilities on the assets and dynamically adjust risk score for those vulnerabilities. |
| Threat defense teams | Gain insights into gaps in mitigations or security controls configuration against specific attack techniques. |
[Table 1. Users]

{#spc-mitigation-exploring__table_pss_ygt_pcc}

## Security Posture Control and the mitigation controls monitoring workflow {#spc-mitigation-exploring__cf-exploring-parent-workflow}

Security Posture Control uses API integrations with security tools such as web-application-firewalls and endpoint protection tools to import additional configuration data about your assets and analyze it to identify
the applicable mitigation controls for a given asset. These API integrations are separate from the service graph connector integrations that are supported by SPC and import different data. You configure these API integrations from within the SPC Workspace.

Service graph connector integrations or ITOM Discovery are still required for mitigation controls monitoring. For example, both the CrowdStrike Service Graph Connector and the CrowdStrike API integration supported by SPC must be activated to import additional insights about which mitigation controls are enabled by the CrowdStrike endpoint protection configuration.

