Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • Now Platform administration
Table of Contents
Choose your release version
    Home New York Now Platform Administration Now Platform administration Platform security

    Platform security

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    Platform security

    Security is built into all levels of the Now Platform. Implement the security features that are appropriate for your organization, from managing failed logins and encrypted password protection, to access control rules and audit logs.

    Table 1. Platform security resources
    Resource Description
    The Security Best Practice Guide on the Customer Success Center Start here to learn about security-related configurations for your instance. You can also learn about:
    • Security responsibilities between you and ServiceNow
    • Security-related certificates and certifications that ServiceNow holds
    • Security contact details
    • Software updates
    • Mobile application security
    • Vulnerability assessment and penetration testing
    The ServiceNow® infrastructure and Now Platform® are intentionally built and operated with high levels of baseline security; however, as a customer you must make some decisions about the way in which your instance is configured to comply with your organization’s security policies.
    Instance Security Hardening Settings The Instance Security Hardening Settings content contains detailed descriptions, and compliance values, for the security-related system properties and plugins in the Now Platform.

    Instance Security Hardening Settings includes many of the same settings that appear in the security-related setup topics that follow. Where applicable, each setup topic includes links to helpful security information in Instance Security Hardening Settings.

    Table 2. Platform security features
    Feature Description Status Top Tasks
    High Security Settings

    High Security Settings refer to several security options available in your instance.

    Active
    • Request High Security Settings activation
    Certificates

    Your instance requires certificates to establish secure connections and validate signatures.

    icon Requires configuration before use

    Active
    • Upload a certificate to an instance
    Login and authentication security Configure login security options to control access to your instance. Active
    • Define login scenarios
    • Make UI pages public or private
    Web service security Enforce security using basic authentication, mutual authentication, or WS-Security. Active
    • Setting up mutual authentication
    • WS-Security
    Access control list rules

    Rules for access control lists (ACLs) restrict access to data by requiring users to pass a set of requirements before they can interact with it.

    Active
    • Create an ACL rule
    • Contextual Security Manager
    HTML sanitizer Remove unwanted code and protect against security concerns such as cross-site scripting attacks by sanitizing HTML markup in HTML fields and translated HTML fields. Active
    • Enable HTML sanitizer
    • Configure HTML sanitizer
    Auditing Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others. Active
    • Enable auditing for a table
    • History sets
    Domain separation for service providers With domain separation you can separate data, processes, and administrative tasks into logically defined domains. icon Requires a separate subscription.
    • Request domain separation
    • Domain separation setup and basic administration
    • Domain separation in Encryption Support
    • Domain separation in Edge Encryption
    Virtual Private Network (VPN) Use a virtual private network (VPN) to integrate your instance with external data sources over the Internet. icon Available by request from ServiceNow personnel.
    • Virtual Private Network (VPN)
    • Request a VPN service
    Encryption support

    Use encryption contexts to allow or deny access to sensitive data based on user role.

    icon Requires configuration before use.

    Active
    • Set up encryption contexts
    • Domain separation in Encryption Support
    • Manually encrypt and decrypt MID Server attributes
    Edge Encryption ServiceNow® Edge Encryption™ encrypts sensitive data on your company premises before sending it over the Internet to your ServiceNow instance (encrypted in flight), where it remains encrypted at rest. icon Requires a separate subscription.
    • Edge encryption installation
    • Edge Encryption configuration
    • Domain separation in Edge Encryption
    System logs View warnings and errors for instance processes, records, and non-critical events, such as memory usage on the server machine. Active
    • Transaction logs
    • Event logs
    Antivirus Scanning Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories. Active

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      Platform security

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      Platform security

      Security is built into all levels of the Now Platform. Implement the security features that are appropriate for your organization, from managing failed logins and encrypted password protection, to access control rules and audit logs.

      Table 1. Platform security resources
      Resource Description
      The Security Best Practice Guide on the Customer Success Center Start here to learn about security-related configurations for your instance. You can also learn about:
      • Security responsibilities between you and ServiceNow
      • Security-related certificates and certifications that ServiceNow holds
      • Security contact details
      • Software updates
      • Mobile application security
      • Vulnerability assessment and penetration testing
      The ServiceNow® infrastructure and Now Platform® are intentionally built and operated with high levels of baseline security; however, as a customer you must make some decisions about the way in which your instance is configured to comply with your organization’s security policies.
      Instance Security Hardening Settings The Instance Security Hardening Settings content contains detailed descriptions, and compliance values, for the security-related system properties and plugins in the Now Platform.

      Instance Security Hardening Settings includes many of the same settings that appear in the security-related setup topics that follow. Where applicable, each setup topic includes links to helpful security information in Instance Security Hardening Settings.

      Table 2. Platform security features
      Feature Description Status Top Tasks
      High Security Settings

      High Security Settings refer to several security options available in your instance.

      Active
      • Request High Security Settings activation
      Certificates

      Your instance requires certificates to establish secure connections and validate signatures.

      icon Requires configuration before use

      Active
      • Upload a certificate to an instance
      Login and authentication security Configure login security options to control access to your instance. Active
      • Define login scenarios
      • Make UI pages public or private
      Web service security Enforce security using basic authentication, mutual authentication, or WS-Security. Active
      • Setting up mutual authentication
      • WS-Security
      Access control list rules

      Rules for access control lists (ACLs) restrict access to data by requiring users to pass a set of requirements before they can interact with it.

      Active
      • Create an ACL rule
      • Contextual Security Manager
      HTML sanitizer Remove unwanted code and protect against security concerns such as cross-site scripting attacks by sanitizing HTML markup in HTML fields and translated HTML fields. Active
      • Enable HTML sanitizer
      • Configure HTML sanitizer
      Auditing Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others. Active
      • Enable auditing for a table
      • History sets
      Domain separation for service providers With domain separation you can separate data, processes, and administrative tasks into logically defined domains. icon Requires a separate subscription.
      • Request domain separation
      • Domain separation setup and basic administration
      • Domain separation in Encryption Support
      • Domain separation in Edge Encryption
      Virtual Private Network (VPN) Use a virtual private network (VPN) to integrate your instance with external data sources over the Internet. icon Available by request from ServiceNow personnel.
      • Virtual Private Network (VPN)
      • Request a VPN service
      Encryption support

      Use encryption contexts to allow or deny access to sensitive data based on user role.

      icon Requires configuration before use.

      Active
      • Set up encryption contexts
      • Domain separation in Encryption Support
      • Manually encrypt and decrypt MID Server attributes
      Edge Encryption ServiceNow® Edge Encryption™ encrypts sensitive data on your company premises before sending it over the Internet to your ServiceNow instance (encrypted in flight), where it remains encrypted at rest. icon Requires a separate subscription.
      • Edge encryption installation
      • Edge Encryption configuration
      • Domain separation in Edge Encryption
      System logs View warnings and errors for instance processes, records, and non-critical events, such as memory usage on the server machine. Active
      • Transaction logs
      • Event logs
      Antivirus Scanning Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories. Active

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login