New hardening settings for baseline version 2.0
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of New Hardening Settings for Baseline Version 2.0
Security Center baseline version 2.0 introduces enhanced hardening settings to improve the security posture of your ServiceNow instance. These updates build upon previous versions (1.3 and 1.5) and are designed to enforce stricter access controls, session management, data protection, and application security measures in accordance with the Zurich release.
Show less
Key Features
- Access Control Enhancements: Includes checking archive table ACLs, enforcing scoped ACL access for information request playbooks, requiring write access for service catalog item pages, and ensuring dashboard creation/deletion requires access checks.
- Session and Integration Security: Limits active session lifespans for integrations, UI, and guest users, proactively invalidates inactive sessions, and defines exception roles for active session timeouts.
- Application and API Security: Enables hardened Java Security Manager, restricts OAuth parameters to POST body, disables legacy GlideRecord Scope Fencing, requires secure insert multiple operations in import set APIs, and validates file mime types in SOAP web services.
- Certificate and Authentication Controls: Verifies certificate revocation with enforced OCSP checks, controls certificate-based authentication, and requires captcha for guest walk-up experiences.
- Data Protection and Privacy: Enforces device encryption and passcode requirements, clears pasteboard when mobile apps background, limits attachment sizes in training/prediction flows, hides user comments on articles, and restricts HR case updates from personal emails.
- Audit and Logging: Enables MID audit logs and logs session audit events to improve traceability and compliance.
- Security Policies and Protocols: Sets safe content security policies for SVG files, enforces strict elevate privilege, anti-CSRF token validation time, secure referrer policy enforcement, and scope security for public sector digital services.
- Additional Controls: Disallows target cloning, requires JMS connection factories, and restricts knowledge base access to enhance data integrity and limit unauthorized access.
Key Outcomes
By implementing these baseline 2.0 hardening settings, ServiceNow customers can expect:
- Stronger protection against unauthorized access and data breaches through improved ACL enforcement and session management.
- Enhanced security for integrations, APIs, and mobile applications reducing attack surfaces.
- Improved compliance with security policies and regulations by enforcing encryption, certificate validation, and audit logging.
- Greater control over user activities and content sharing to safeguard sensitive information.
- A more secure environment aligned with modern security best practices tailored for ServiceNow Zurich release.
New hardening settings have been released with Security Center baseline version 2.0.
- Ensure archive table ACLs are checked [New in Security Center 1.3 and updated in 1.5]
- Enforce application scope restrictions [New in Security Center 1.3 and removed in 1.5]
- Enable the hardened java security manager [New in Security Center 1.3]
- Verify certificate revocation [New in Security Center 1.3]
- Require clearing pasteboard when backgrounding mobile application [New in Security Center 1.3 and updated in 1.5]
- Enable protected tables plugin [New in Security Center 1.3]
- Enforce strict elevate privilege [New in Security Center 1.3]
- Limit integrations' active session life span [New in Security Center 1.3]
- Proactively invalidate inactive sessions [New in Security Center 1.3 and updated in 1.5 and 2.0]
- Enable MID audit log [New in Security Center 1.3 and updated in 1.5]
- Use of secure insert multiple operation within import set API [New in Security Center 1.3]
- Enforce OCSP check on network error [New in Security Center 1.3 and updated in 2.0]
- Enforce security rules to sharing dashboards [New in Security Center 1.3]
- Restrict oauth parameters to POST body [New in Security Center 1.3]
- Limit attachment size in training and prediction flows for GraphQL endpoints [New in Security Center 1.3 and updated in 1.5]
- Disable GlideRecord Scope Fencing Legacy Behavior [New in Security Center 1.3 and updated in 1.5 and 2.0]
- Required jms connection factories [New in Security Center 1.3 and updated in 1.5 and 2.0]
- Limit attachment size in training and prediction flows [New in Security Center 1.3 and updated in 1.5]
- Log session audit events [New in Security Center 1.3 and updated in 1.5]
- Require write access to access service catalog add item page [New in Security Center 1.3]
- Define active session timeout exception roles [New in Security Center 1.3]
- Certificate based authentication not enforced [New in Security Center 1.3]
- Enforce scoped ACL access for information request playbooks [New in Security Center 1.3 and updated in 1.5]
- Hide user comments on articles [New in Security Center 1.3]
- Ensure dashboards creation/deletion requires access check [New in Security Center 1.3 and updated in 2.0]
- Enforce device encryption and passcode requirements [New in Security Center 1.3]
- Validate file mime type in AttachmentCreator soap web service [New in Security Center 1.3 and updated in 1.5]
- Verify certificate revocation [New in Security Center 1.3]
- Check impersonation on ACL evaluation in HR App [New in Security Center 1.3 and updated in 1.5]
- Require captcha for guest walk-up experience in customer service application [New in Security Center 1.3 and updated in 1.5]
- Require Authentication on Event Management HTTP Processor [New in Security Center 1.3, Updated in 1.5, and removed in 2.0]
- Limit guest's active session life span [New in Security Center 1.3]
- Disallow target cloning [New in Security Center 1.3]
- Set safe content security policy for svg files [New in Security Center 1.3]
- Anti-CSRF token validation time [New in Security Center 1.3]
- Restrict knowledge bases access [New in Security Center 1.3]
- Enforce scope security for public sector digital services [New in Security Center 1.3]
- Restrict HR case updates from personal emails [New in Security Center 1.3 and updated in 1.5]
- Limit UI active session life span [New in Security Center 1.3]
- Enforce secure referrer policy [New in Security Center 1.3]