Secure your instance
Summarize
Summary of Secure your instance
The ServiceNow AI Platform® Security provides robust features to secure your instance, encrypt data, verify identities, and manage compliance with application security standards. Security is integrated at all levels of the platform, allowing organizations to implement tailored security measures based on their needs.
Show less
Key Features
- Platform Security: Protects instances from intrusions and secures data.
- Platform Privacy: Classifies sensitive data and anonymizes personally identifiable information (PII).
- Identity Management: Manages identities across the instance.
- Access Management: Authenticates users and authorizes access based on roles.
- ServiceNow Vault: Offers tools for data security including encryption and secrets management.
- Encryption Options: Includes Column Level Encryption and Edge Encryption for data protection.
- Instance Security Center: Monitors compliance and manages security settings.
Key Outcomes
Implementing these security features enables organizations to:
- Reduce risks to sensitive data through encryption and data privacy measures.
- Enhance visibility and response capabilities to security incidents with real-time dashboards and guided remediation.
- Ensure compliance with data protection regulations by anonymizing PII and managing access effectively.
The ServiceNow AI Platform® Security enables you to secure your instance, encrypt your data, verify identity, authenticate users, and view your current compliance levels based on application security standards.
Security is built into all levels of the ServiceNow AI Platform. Implement the security features that are appropriate for your organization, from managing failed logins and encrypted password protection, to access control rules and audit logs.
Choose one of these tiles to get started.
General Platform Security settings Know more about the General Platform Security settings. |
Secure your instance
Security is built into all levels of the ServiceNow AI Platform. Implement the security features that are appropriate for your organization, from managing failed logins and encrypted password protection, to access control rules and audit logs.
|
|
|
|
|
|
|
|
|
|
|
Reduce risks to sensitive data using Column Level Encryption
Column Level Encryption Enterprise utilizes the Key Management Framework and enables best practice key lifecycle management to customize and manage granular specifications to encrypt and decrypt on your instance. You must purchase a subscription to Column Level Encryption Enterprise, but the Key Management Framework is available by default for all instances.
Encrypt data in flight using Edge Encryption
Edge Encryption encrypts sensitive data on your company premises before sending it over the internet to your instance (encrypted in transit), where it remains encrypted at rest. Also referred to as client-side encryption, Edge requires all bi-directional user traffic to pass through proxies that are maintained on your infrastructure. You have full control over your key management, as the keys are stored within your proxy on your infrastructure.
Secure access to your instance
Choose the type of authentication that meets your company needs. You can authenticate users, enable single-sign on, authorize web clients to access your instance, and more.
Anonymize Personally Identifiable Information (PII)
Use data privacy to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Ensure that your user data is no longer considered regulated private information.
Respond to risks fast
Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.
Products
- Access control list rules
- Antivirus Scanning
- Auditing
- Authentication
- Certificates
- Connections and Credentials
- Data classification
- Data filtration
- Data privacy
- Domain separation for service providers
- Encryption and Key Management
- Explicit Roles
- Identity
- Instance Security Center
- Instance Security Hardening Settings
- Vault
- Virtual Private Network (VPN)