---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Baseline version 5.0

# New hardening settings for baseline version 5.0 {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

New hardening settings have been released with Security Center baseline version 5.0.

* [Enforce ACL on HR Lifecycle Events Data \[New in Security Center 2.0\]](BYuisWFh649KwIDVuP4NNg "Learn how to prevent unauthorized access to data in the Human Resources Lifecycle Events application by verifying that the glide.enforce_security_scope.sn_hr_le property is set to the secured value.")
* [Sanitize All Translated HTML Fields \[New in Security Center 2.0\]](QUPkh4vh8GwpIeKSswpEoQ "Learn how to configure the glide.translated_html.sanitize_all_fields property to the secure value to ensure that all translated_html elements are sanitized with an HTML sanitizer.")
* [Configure Service Portal Widgets Allow List \[New in Security Center 2.0\]](WUOChMqJtkeA4U6IUFDoGg "Learn how to configure the glide.service_portal.widget.allow_list property securely so that the access control lists (ACLs) for the tables do not expose sensitive information.")
* [Enforce ACL on HR Core Data \[New in Security Center 2.0\]](ssRLHaCV53ahqR3mOUxPbg "Learn how to configure the glide.enforce_security_scope.sn_hr_core property so that the Human Resources Scoped App: Core (com.sn_hr_core) plugin does not expose sensitive data to access control lists (ACLs) from all other scopes.")
* [Enforce ACL on HR Virtual Agent Data \[New in Security Center 2.0\]](VkeS~GBnyOYerYDaNtlpEA "Discover how to set the glide.enforce_security_scope.sn_hr_va property to a secure value, preventing data leakage from the Virtual Agent Conversations scoped application.")
* [Configure Service Portal Widgets Table Allow List \[New in Security Center 2.0\]](ZK2~UHCkDXyPfKyu~QxjlQ "Learn how the glide.service_portal.widget.table_allow_list property enhances security by listing tables accessible to unauthenticated users through Service Portal widgets, dependent on additional checks and specific glide property settings.")
* [Enforce Security Scope for Service Application Information \[New in Security Center 2.0\]](XVA5WRABwTq9J2A9FdDD_g "Use the glide.enforce_security_scope.sn_svc_appl property to ensure that the data in master scope tables is secured.")
* [Prevent Empty ACL Creation \[New in Security Center 2.0\]](pNNXRaXbVWdkYOAqQEADCQ "Set the glide.security.empty_acl.popup_window.enabled property to the secure value of true to block attempts to create, update, or save an invalid ACL. This setting will also provide a client-side model to configure a role or security attribute for the ACL.")
* [Prevent Unauthenticated Access to Virtual Agent Embedded Web Client](https://servicenow-prod.fluidtopics.net/UZzPd9MTxKs2cAW6YfUvPA "Learn how to configure the sn_va_web_client_app_embed table to block unauthenticated users from accessing embedded web clients.")
* [Set Automatic Token Cleanup for Token Credentials \[New in Security Center 2.0\]](Pd1alsVUqdsNBh7gRYExEw "Use the com.snc.platform.security.token.auth.cleanup property to ensure that expired API keys and HMAC secrets are deleted, thereby limiting the potential for token reuse.")
* [Restrict Global App Development by Role \[New in Security Center 2.0\]](j6Bv3LGtg3uwqn4Q324V7g "Use the sn_g_app_creator.allow_global property to control which users can create applications in the global scope using the Guided Application Creator.")
* [Enable ACLs for Encoded Query in Simple List Widget \[New in Security Center 2.0\]](5SDxOHFCSgWfoXsLLqWAOQ "Learn how to set the glide.service_portal.enable_acls_for_encoded_query_in_list property to the secure value to prevent users from bypassing access control list (ACL) evaluations on a query condition in the Simple List Widget.")
* [Invalidate Session After OAuth Token Expiration \[New in Security Center 2.0\]](rudrPbJ5NIKyy6N_trrMtA "Use a system property to the secure value to prevent users from continuing to use a session via cookies after the OAuth token used to create the session expires.")
* [Set Allowed MIME Child Types \[New in Security Center 2.0\]](TSVwLo~Fg8xLIk4n9inn8A "Learn how to configure the glide.security.mime.type.allowed_child_types property to a secure setting so that file types will not pass the Multipurpose Internet Mail Extensions (MIME) type checking. This reduces the risk of remote code execution on an uploaded file.")
* [Restrict Impersonation to Admin \[New in Security Center 2.0\]](bgSkq_3gC4AulUXKsVV2kQ "The glide.sys.permissive.impersonate property can be used to prevent non-admin roles from impersonating other users.")
{#new_hardening_settings_for_baseline_version_5__ul_u2d_qk2_mcc}

