Security Posture Control release notes

  • Release version: Zurich
  • Updated January 28, 2026
  • 4 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Security Posture Control release notes

    The ServiceNow® Security Posture Control application offers cybersecurity teams enhanced visibility into security tool coverage gaps and configuration deviations across enterprise assets. The Zurich release introduces significant updates to help organizations better monitor and manage their overall security posture through improved integrations, policies, and user experience enhancements.

    Show full answer Show less

    Key Features

    • Custom API Connectors with Generative AI: Developers can now create and publish custom API service graph connectors using the Connector builder module within the Security Posture Control workspace. Generative AI, available via the Now Assist skill included in the ServiceNow Otto for Unified Security Exposure Management application, automates key steps such as selecting API templates and mapping response fields, accelerating integration with diverse security tools.
    • Enhanced Policies and Asset Profiles: New out-of-the-box policies and asset profiles help identify security tool coverage gaps and configuration compliance issues for tools such as CrowdStrike, Microsoft Intune, Defender, SCCM, HCL Big Fix, SentinelOne, Qualys, and Rapid7. Customers can activate these in the workspace to monitor vulnerabilities, critical risk combinations, and possible internet exposure.
    • Improved Data Integration: Security Posture Control depends on service graph connector data stored in the CMDB 360 Data table, requiring the system property glide.identificationengine.multisourceenabled to be enabled. This ensures comprehensive asset data for accurate security posture analysis.
    • User Interface Enhancements: Labels in mitigation control details have been clarified (e.g., "EDR" expanded to "Endpoint Protection") for better usability. The new default Coral theme, including a dark mode option, offers a modern, brand-neutral visual experience for portals and mobile apps.

    Important Upgrade and Activation Information

    • Security Posture Control is available via the ServiceNow Store and requires requesting installation of necessary applications.
    • Starting with Zurich Patch 12, Now Assist for Vulnerability Response is deprecated and replaced under the ServiceNow Otto branding for Unified Security Exposure Management.
    • To leverage generative AI capabilities in the Connector builder, customers must install Zurich Patch 4 of the ServiceNow Otto application.

    What Customers Can Expect

    By upgrading to the Zurich release, ServiceNow customers will gain automated, AI-assisted capabilities to build custom integrations, enhanced visibility into security coverage and configuration gaps, and a more intuitive UI experience. These improvements empower cybersecurity teams to proactively monitor enterprise assets, reduce security risks, and streamline security operations using the ServiceNow platform.

    The ServiceNow® Security Posture Control application provides cybersecurity teams with visibility into security tool coverage gaps and deviations from security tool configuration for their enterprise assets. Security Posture Control was enhanced and updated in the Zurich release.

    Security Posture Control highlights for the Zurich release

    • Create and publish your own API connectors with a step-by-step process in the Connector builder module in the Security Posture Control workspace. You can use generative AI to automate some steps. See the ServiceNow Otto for Security Incident Response (SIR) (SIR) release notes for more information about the Now Assist skill.
    • Get insights into your overall security posture and configuration gaps in your security tools using new policies and asset profiles that are included with the Security Posture Control application.
    • Use the policies included with the application or custom policies that you create to monitor your assets for overall security tool coverage, compliance with internal configuration standards, critical combinations of security gaps and vulnerabilities, and possible internet exposure.

    See Security Posture Control for more information.

    Important:
    Security Posture Control is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

    Important information for upgrading Security Posture Control to Zurich

    For a complete list of the applications that are required to implement Security Posture Control, see Install Security Posture Control. Starting with Zurich Patch 12, Now Assist for Vulnerability Response is being prepared for future deprecation. It will be hidden and no longer installed on new instances but will continue to be supported. For details, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base. The change is reflected in the name of ServiceNow® products, including Now Assist for Vulnerability Response which is called ServiceNow Otto for Unified Security Exposure Management. See Now Assist in Unified Security Exposure Management for more information.

    New in the Zurich release

    Create a custom API service graph connector in the Security Posture Control workspace
    Use generative AI to help your developers create SPC API connectors quickly with the Connector builder framework module in the Security Posture Control workspace. With a Now Assist skill that is included with the ServiceNow Otto for Unified Security Exposure Management application, your developers have the option to automate steps in the Connector builder framework.
    • You have the option to automate the steps for selecting API templates, populating request and header parameters, and response field mapping with generative AI.
      Note:
      You must install Zurich Patch 4 of the ServiceNow Otto for Unified Security Exposure Management application to have access to the generative AI skill for the Connector builder framework. See the ServiceNow Otto for Security Incident Response (SIR) (SIR) release notes and Supporting information for Unified Security Exposure Management AI skills and agents for more information.
    • Use your custom API connector to integrate with security tools and import asset data that is based on the unique requirements of your environment.
    • Help your cybersecurity teams monitor your overall security posture and identify assets that are missing key security tools with the API connectors that you build.
    Enhancements to policies and asset profiles included with the Security Posture Control application
    Get insights into your overall security posture and configuration gaps in your security tools using new policies and asset profiles that are included with the Security Posture Control application. Activate these asset profiles and policies in the Security Posture Control workspace so that you can identify gaps in configuration or coverage for the following tools:
    • CrowdStrike
    • Microsoft Intune, Defender, and SCCM
    • HCL Big Fix
    • SentinelOne
    • Qualys
    • Rapid7

    Changed in this release

    • Security Posture Control relies on data from service graph connectors that is populated in the CMDB 360 Data [cmdb_multisource_data] table. This data is populated only when the glide.identification_engine.multisource_enabled system property is set to true. You must have the cmdb_ms_admin role to modify property values. To set the property, navigate to All > Configuration > CMDB 360 Properties.
    • The labels on the form view for the mitigation control details record associated with vulnerable item records (VITs) have been enhanced for more clarity. These updates make the interface more user-friendly by expanding abbreviations on the form view, such as changing "EDR" to "Endpoint Protection."

    UI changes

    Coral theme
    Coral is now the default theme for new portal, web, and mobile experiences with Next Experience or Core UI enabled. This theme provides a fresh look and feel, featuring brand-neutral illustrations to enhance your user experience. A dark theme option is available for web and mobile experiences.

    Activation information

    Install Security Posture Control by requesting the required applications from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Accessibility information

    Dark theme
    The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.