Combined Continuous Authorization and Monitoring release notes for upgrades from Xanadu to Yokohama
Summarize
Summary of Combined Continuous Authorization and Monitoring release notes for upgrades from Xanadu to Yokohama
This consolidated update details the Continuous Authorization and Monitoring (CAM) enhancements, changes, and important upgrade considerations for ServiceNow customers moving from the Xanadu release to Yokohama. The document assists customers in preparing for their upgrade by summarizing new features, role changes, export/import capabilities, and reporting enhancements across these releases.
Show less
Key Features
- CAM Workspace Enhancements (Xanadu): Provides an end-to-end user experience with a Home page, dashboards, unified tasks, and overview pages for authorization boundaries and packages. Features include adding related control objectives, viewing controls by family (such as NIST 800-53), attaching files to assessment procedures, and a consolidated Plan of Actions and Milestones (POA&M) view.
- OSCAL Format Support: CAM supports the National Institute of Standards and Technology (NIST) recommended OSCAL format for exporting control-related information including System Security Plan (SSP) files, Catalog, Profile, and Catalog overlay models for easier sharing and integration with other systems.
- ATO Artifact Generation: Generate Authorization to Operate (ATO) artifacts in Microsoft Word format, including SSP, Security Assessment Report (SAR), Security Assessment Plan (SAP), ATO Letter, and Executive Summary reports. This ensures consistent formatting for sharing and review.
- Role Enhancements: Introduction of new lite roles such as Information Owner and Audit Reader with scoped permissions for viewing and updating information types, viewing audit engagements, and managing issues to streamline business operations securely.
- OSCAL Import and Export (Yokohama): New OSCAL Import landing page for catalog and SSP model files and an OSCAL Export button to export selected control objectives in OSCAL format from the control objectives list view.
- Document Designer Plugin: Enables creation of customizable Microsoft Word and HTML report templates to support varied reporting requirements within CAM.
Key Changes
- Role Modifications: Some roles like Authorization Official and Information System Security Officer have had audit and compliance roles removed to better define read and approval capabilities separately from audit functions.
- Control Objective Mapping: In exports, child control objectives map to the Control field and related controls to the Links field, improving clarity and structure in exported catalog models.
- CAM Workspace Usability Enhancements: Added new pop-ups for hybrid control creation, inclusion of all authorization package issues in POA&Ms, additional fields such as Family and Family ID on control objectives, Notes and Attachments on assessment procedures, and a 360° View button across CAM Workspace pages.
Upgrading and Activation
To install or upgrade CAM, customers should request the application from the ServiceNow Store. This ensures access to the latest release versions and cumulative release notes. There are no additional browser or localization requirements introduced between Xanadu and Yokohama releases.
Practical Benefits for ServiceNow Customers
- Streamlined end-to-end authorization and monitoring workflows through CAM Workspace enhancements, improving operational efficiency.
- Improved interoperability and automation via OSCAL format support for exporting and importing security documentation and control objectives.
- Flexible and consistent reporting with the ability to generate ATO artifacts and assessment reports in Microsoft Word and HTML formats, tailored to organizational standards.
- More granular and secure user role definitions that enhance governance while simplifying access management.
- Enhanced visibility and control over authorization packages and assessment procedures with new fields and views.
Consolidated page of all release notes for Continuous Authorization and Monitoring from Xanadu to Yokohama.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Continuous Authorization and Monitoring release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Yokohama.
Important information for upgrading Continuous Authorization and Monitoring to Yokohama
Before you upgrade to Yokohama, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
New features
Between your current release family and Yokohama, new features were introduced for Continuous Authorization and Monitoring.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Changes
Between your current release family and Yokohama, some changes were made to existing Continuous Authorization and Monitoring features.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Removed
Between your current release family and Yokohama, some Continuous Authorization and Monitoring features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
No updates for this release. |
Deprecations
Between your current release family and Yokohama, some Continuous Authorization and Monitoring features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Activation information
Review information on how to activate Continuous Authorization and Monitoring.
| Release | Release notes |
|---|---|
Xanadu |
Install Continuous Authorization and Monitoring by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Yokohama |
Install CAM by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Continuous Authorization and Monitoring we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Continuous Authorization and Monitoring we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Accessibility information
Review details on accessibility information for Continuous Authorization and Monitoring, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Localization information
If there are specific localization considerations for Continuous Authorization and Monitoring we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Continuous Authorization and Monitoring we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Continuous Authorization and Monitoring for more information. |
Yokohama |
See Continuous Authorization and Monitoring for more information. |