New hardening settings for baseline version 2.0
Summarize
Summary of New Hardening Settings for Baseline Version 2.0
Security Center baseline version 2.0 introduces updated and new hardening settings designed to strengthen the security posture of your ServiceNow environment. These settings help enforce stricter access controls, session management, data protection, and secure communication practices.
Show less
Key Features
- Access Control Enhancements: Archive table ACL checks, scoped ACL enforcement for playbooks, and access checks for dashboard creation/deletion ensure that data and functionalities are properly secured.
- Session and Privilege Management: Active session lifespan limits for integrations, guests, and UI sessions, along with proactive invalidation of inactive sessions and strict elevate privilege enforcement, help reduce session-related risks.
- Authentication and Authorization: Application scope restrictions, certificate revocation verification, and OAuth parameter restrictions improve authentication security. Captcha requirements for guest access and validation of impersonation in HR applications enhance authorization controls.
- Data and Content Security: Limitations on attachment sizes in GraphQL training/prediction, MIME type validation for attachments, and safe content security policies for SVG files protect against data misuse and injection attacks.
- Device and Application Security: Enforcement of device encryption and passcode requirements, clearing pasteboard on mobile backgrounding, and enabling the hardened Java security manager boost endpoint security.
- Audit and Logging Improvements: MID audit log activation and session audit event logging provide enhanced monitoring capabilities.
- Other Controls: Disallowing target cloning, secure referrer policies, anti-CSRF token validation timing, restricted knowledge base access, and restrictions on HR case updates from personal emails further tighten security boundaries.
Key Outcomes
By implementing these settings, ServiceNow customers can expect improved protection against unauthorized access, better session hygiene, enhanced data integrity, and strengthened compliance with security best practices. These updates reduce vulnerabilities related to session management, privilege escalation, data exposure, and endpoint security, supporting a robust and secure ServiceNow environment.
New hardening settings have been released with Security Center baseline version 2.0.
- Ensure archive table ACLs are checked [New in Security Center 1.3 and updated in 1.5]
- Enforce application scope restrictions [New in Security Center 1.3 and removed in 1.5]
- Enable the hardened java security manager [New in Security Center 1.3]
- Verify certificate revocation [New in Security Center 1.3]
- Require clearing pasteboard when backgrounding mobile application [New in Security Center 1.3 and updated in 1.5]
- Enable protected tables plugin [New in Security Center 1.3]
- Enforce strict elevate privilege [New in Security Center 1.3]
- Limit integrations' active session life span [New in Security Center 1.3]
- Proactively invalidate inactive sessions [New in Security Center 1.3 and updated in 1.5 and 2.0]
- Enable MID audit log [New in Security Center 1.3 and updated in 1.5]
- Use of secure insert multiple operation within import set API [New in Security Center 1.3]
- Enforce OCSP check on network error [New in Security Center 1.3 and updated in 2.0]
- Enforce security rules to sharing dashboards [New in Security Center 1.3]
- Restrict oauth parameters to POST body [New in Security Center 1.3]
- Limit attachment size in training and prediction flows for GraphQL endpoints [New in Security Center 1.3 and updated in 1.5]
- Disable GlideRecord Scope Fencing Legacy Behavior [New in Security Center 1.3 and updated in 1.5 and 2.0]
- Required jms connection factories [New in Security Center 1.3 and updated in 1.5 and 2.0]
- Limit attachment size in training and prediction flows [New in Security Center 1.3 and updated in 1.5]
- Log session audit events [New in Security Center 1.3 and updated in 1.5]
- Require write access to access service catalog add item page [New in Security Center 1.3]
- Define active session timeout exception roles [New in Security Center 1.3]
- Certificate based authentication not enforced [New in Security Center 1.3]
- Enforce scoped ACL access for information request playbooks [New in Security Center 1.3 and updated in 1.5]
- Hide user comments on articles [New in Security Center 1.3]
- Ensure dashboards creation/deletion requires access check [New in Security Center 1.3 and updated in 2.0]
- Enforce device encryption and passcode requirements [New in Security Center 1.3]
- Validate file mime type in AttachmentCreator soap web service [New in Security Center 1.3 and updated in 1.5]
- Verify certificate revocation [New in Security Center 1.3]
- Check impersonation on ACL evaluation in HR App [New in Security Center 1.3 and updated in 1.5]
- Require captcha for guest walk-up experience in customer service application [New in Security Center 1.3 and updated in 1.5]
- Require Authentication on Event Management HTTP Processor [New in Security Center 1.3, Updated in 1.5, and removed in 2.0]
- Limit guest's active session life span [New in Security Center 1.3]
- Disallow target cloning [New in Security Center 1.3]
- Set safe content security policy for svg files [New in Security Center 1.3]
- Anti-CSRF token validation time [New in Security Center 1.3]
- Restrict knowledge bases access [New in Security Center 1.3]
- Enforce scope security for public sector digital services [New in Security Center 1.3]
- Restrict HR case updates from personal emails [New in Security Center 1.3 and updated in 1.5]
- Limit UI active session life span [New in Security Center 1.3]
- Enforce secure referrer policy [New in Security Center 1.3]