New hardening settings for baseline version 2.0

  • Release version: Yokohama
  • Updated January 30, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of New Hardening Settings for Baseline Version 2.0

    Security Center baseline version 2.0 introduces updated and new hardening settings designed to strengthen the security posture of your ServiceNow environment. These settings help enforce stricter access controls, session management, data protection, and secure communication practices.

    Show full answer Show less

    Key Features

    • Access Control Enhancements: Archive table ACL checks, scoped ACL enforcement for playbooks, and access checks for dashboard creation/deletion ensure that data and functionalities are properly secured.
    • Session and Privilege Management: Active session lifespan limits for integrations, guests, and UI sessions, along with proactive invalidation of inactive sessions and strict elevate privilege enforcement, help reduce session-related risks.
    • Authentication and Authorization: Application scope restrictions, certificate revocation verification, and OAuth parameter restrictions improve authentication security. Captcha requirements for guest access and validation of impersonation in HR applications enhance authorization controls.
    • Data and Content Security: Limitations on attachment sizes in GraphQL training/prediction, MIME type validation for attachments, and safe content security policies for SVG files protect against data misuse and injection attacks.
    • Device and Application Security: Enforcement of device encryption and passcode requirements, clearing pasteboard on mobile backgrounding, and enabling the hardened Java security manager boost endpoint security.
    • Audit and Logging Improvements: MID audit log activation and session audit event logging provide enhanced monitoring capabilities.
    • Other Controls: Disallowing target cloning, secure referrer policies, anti-CSRF token validation timing, restricted knowledge base access, and restrictions on HR case updates from personal emails further tighten security boundaries.

    Key Outcomes

    By implementing these settings, ServiceNow customers can expect improved protection against unauthorized access, better session hygiene, enhanced data integrity, and strengthened compliance with security best practices. These updates reduce vulnerabilities related to session management, privilege escalation, data exposure, and endpoint security, supporting a robust and secure ServiceNow environment.

    New hardening settings have been released with Security Center baseline version 2.0.