Using mitigation controls monitoring with Security Posture Control

  • Release version: Xanadu
  • Updated July 31, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using Mitigation Controls Monitoring with Security Posture Control

    The Security Posture Control (SPC) application allows you to monitor mitigation controls to gain insights into threats to your assets based on the configuration of various security tools. This functionality is critical for identifying and addressing vulnerabilities within your enterprise assets.

    Show full answer Show less

    Key Features

    • Asset Inventory: Identify all enterprise assets, including unmanaged or unknown ones.
    • Security Controls Coverage and Health: Detect coverage gaps in your existing security controls.
    • Vulnerability and Threat Mitigation Visibility: Understand which threats or vulnerabilities are mitigated by applicable controls.
    • API Integrations: Utilize integrations with security tools like web-application-firewalls and endpoint protection to import configuration data for analysis.

    Roles Required

    • Admin: Installs applications from the ServiceNow Store and activates plugins (ITOM Discovery).
    • SPC Admin Group and SPC Analyst Group: Full read and write access to all records for the product and workspace.
    • SPC Analyst Read Only Group: Full read access to all records for the product.

    Key Outcomes

    • Enhanced Visibility: Cybersecurity teams gain insights into all enterprise assets and can identify critical vulnerabilities and compliance deviations.
    • Improved Risk Management: Vulnerability management teams can dynamically adjust risk scores based on mitigation insights.
    • Gaps in Mitigations: Threat defense teams can identify gaps in current mitigations or configurations against specific attack techniques.

    From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.

    Mitigation controls monitoring

    For supported applications for Security Posture Control and Mitigation Controls Monitoring, see Exploring Security Posture Control.

    The Security Posture Control application focuses on three core problem areas:
    • Asset inventory - Identifying all your enterprise assets that include unmanaged or unknown assets.
    • Security controls coverage and health - Identifying any coverage gaps with your security controls
    • Vulnerability and threat mitigation visibility - Identifying which threats or vulnerabilities to your assets are mitigated by applicable mitigation controls.

    Mitigation controls monitoring describes the features in Security Posture Control that fall under vulnerability and threat mitigation visibility.

    Roles required:
    • admin - Installs applications from the ServiceNow® Store and activates plugins (ITOM Discovery).
    • SPC Admin Group and SPC Analyst Group - Users in this group have full read and write access to all the records for the product and the workspace.
    • SPC Analyst Read Only Group - Users in this group have full read access to all the records for the product.

    Mitigation controls monitoring users and benefits

    Table 1. Users
    User Description
    Cybersecurity teams, Security analysts and managers
    • Gain visibility into all your enterprise assets that include unmanaged or unknown assets.
    • Identify coverage gaps with your security controls, toxic combinations of problems such as critical vulnerabilities and internet exposure on your assets, and deviations from your internal security standards.
    Vulnerability management teams Gain insights in mitigations available for vulnerabilities on the assets and dynamically adjust risk score for those vulnerabilities.
    Threat defense teams Gain insights into gaps in mitigations or security controls configuration against specific attack techniques.

    Security Posture Control and the mitigation controls monitoring workflow

    Security Posture Control uses API integrations with security tools such as web-application-firewalls and endpoint protection tools to import additional configuration data about your assets and analyze it to identify the applicable mitigation controls for a given asset. These API integrations are separate from the service graph connector integrations that are supported by SPC and import different data. You configure these API integrations from within the SPC Workspace.

    Service graph connector integrations or ITOM Discovery are still required for mitigation controls monitoring. For example, both the CrowdStrike Service Graph Connector and the CrowdStrike API integration supported by SPC must be activated to import additional insights about which mitigation controls are enabled by the CrowdStrike endpoint protection configuration.