---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Baseline version 2.0

# New hardening settings for baseline version 2.0 {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

New hardening settings have been released with Security Center baseline version 2.0.

* [Ensure archive table ACLs are checked \[New in Security Center 1.3 and updated in 1.5\]](1J8hJ~KKSXUElvv93A_kxw "The glide.security.enable_archive_table_acls property controls whether access control lists (ACLs) of the original table, the table the archive table was created from, are evaluated to false.")
* [Enforce application scope restrictions \[New in Security Center 1.3 and removed in 1.5\]](tcXWbnNNnpJBFkjaHzFT6g "Use the glide.record.legacy_cross_scope_access_policy_in_script property to control the permissions of scoped apps.")
* [Enable the hardened java security manager \[New in Security Center 1.3\]](V_GsCHPEFZHV50r3xsZGyA "The glide.security.manager property contains the Java classname of the current Java security manager.")
* [Verify certificate revocation \[New in Security Center 1.3\]](4dWZ9LmI9zrGmgODIsOSog "The com.glide.communications.httpclient.verify_revoked_certificate property checks certificate revocation during the Transport Layer Security (TLS) handshake to ensure that security checks are not bypassed.")
* [Require clearing pasteboard when backgrounding mobile application \[New in Security Center 1.3 and updated in 1.5\]](mK7D92EXfJ9h9PodnykUEA "The glide.sg.clear_pasteboard_when_backgrounded property controls if text copied from ServiceNow mobile app is kept in the clipboard and pasteboard after the app is in background mode. If it is not set to the recommended value of true, then sensitive information may be disclosed to the Android or iOS clipboard where it can be exposed to other applications on the device.")
* [Enable protected tables plugin \[New in Security Center 1.3\]](cHYaYzJxDVp9nBpj97cPAw "Use the com.glide.security.protected_table.enabled property to prevent higher privilege users from tampering with log tables.")
* [Enforce strict elevate privilege \[New in Security Center 1.3\]](YuzW7tJGAAC3usLaqDtnUA "Use the glide.security.strict_elevate_privilege property to control whether roles marked as privileged must be manually elevated for the user to be granted the role's capabilities.")
* [Limit integrations' active session life span \[New in Security Center 1.3\]](EGm9ezCSGjUivagnO0VVoQ "The glide.integrations.active.session.life_span property enforces max lifespan on active guest HTTP sessions irrespective of inactive timeout. The configured value is in minutes. A value of zero will disable timing out the active sessions.")
* [Proactively Invalidate Sessions After Defined Durations](https://servicenow-prod.fluidtopics.net/yjdAFqeeT1NA7yvITLA8Lg "The glide.active.session.timeout.invalidate.session property controls whether a timeout session is proactively invalidated before the Tomcat server.")
* [Enable MID audit log \[New in Security Center 1.3 and updated in 1.5\]](z2GSS6D_lLnF3P8XmXIxoA "The MID Server command audit log records details such as the command name, command hash, name of credential used, and execution status.")
* [Use of secure insert multiple operation within import set API \[New in Security Center 1.3\]](2UdwApW2FXy1Qr1NfaRTRw "Use the com.glide.import_set_api.insert_multiple_optimize property to control whether GlideRecordSecure or GlideRecord is used for the Insert Multiple operation within the Import Set API.")
* [Enforce OCSP check on network error \[New in Security Center 1.3 and updated in 2.0\]](4eqb4Q2QE8fKWUQXHUYJlw "Learn how to configure the com.glide.communications.httpclient.ocsp_allow_network_error property to prevent bad actors from bypassing Online Certificate Status Protocol (OCSP) checks.")
* [Enforce security rules to sharing dashboards \[New in Security Center 1.3\]](Ps3J4Jpe2ndY9FHGGo~6Iw "Use the glide.cms.dashboards.sharing_with_secure_search property to control whether users can share dashboards.")
* [Restrict oauth parameters to POST body \[New in Security Center 1.3\]](RsS7LyuW1dYnD0628XgaJA "Use the glide.oauth.allow.parameters.in.post.body.only property to control the inbound OAuth authentication's acceptance of access tokens. Access tokens are sensitive and should only be accepted when located within a POST request body.")
* [Limit attachment size in training and prediction flows for GraphQL endpoints \[New in Security Center 1.3 and updated in 1.5\]](ioKWsXwVslhB8c1p3viMyQ "The glide.platform_ml_di.max_attachment_size_graphql property controls the maximum allowed size limit for returning attachments in GraphQL endpoints of training or prediction flows.")
* [Disable GlideRecord Scope Fencing Legacy Behavior \[New in Security Center 1.3 and updated in 1.5 and 2.0\]](Q4AiOEk_siPtibdffTRNdA "The glide.record.legacy_cross_scope_access_policy_in_script property disables scope fencing allowing scoped apps to access global script interfaces. It was created as a patch to GlideRecord's cross scope access.")
* [Required jms connection factories \[New in Security Center 1.3 and updated in 1.5 and 2.0\]](DSQ4jCIC83waKxC~k773NQ "The mid.property.jms.command.allowed_factory_names property controls the Java Messaging Service (JMS) connection factories that the MID Server can use.")
* [Limit attachment size in training and prediction flows \[New in Security Center 1.3 and updated in 1.5\]](n5NQF_QZNtDDX2I45hS0nA "The glide.platform_ml_di.max_attachment_size property controls the maximum allowed size limit for returning attachments in training and prediction flows.")
* [Log session audit events \[New in Security Center 1.3 and updated in 1.5\]](6ETyJWuky5V~58NcomLNbQ "Set the glide.authenticate.session_access.log_audit_event property to true, so that session audit events will be created in the sys_session_access_audit table.")
* [Require write access to access service catalog add item page \[New in Security Center 1.3\]](03PZXYGzrgdetyEcMhnshA "Use the glide.sc.request.add_item_write_access property to prevent unauthorized operations from being performed on catalog items.")
* [Define active session timeout exception roles \[New in Security Center 1.3\]](MiBnhI0yvtF2GYdPngA1VQ "Use a system property to exempt roles from active session timeout limits.")
* [Certificate based authentication not enforced \[New in Security Center 1.3\]](eI9ehNuiYqNr2O9ngiKXhg "The glide.authenticate.mutual.enabled property enables certificate based authentication, a type of mutual authentication for inbound REST connections to REST and SOAP APIs in the ServiceNow AI Platform.")
* [Enforce scoped ACL access for information request playbooks \[New in Security Center 1.3 and updated in 1.5\]](lJehf4U_PvwY7Yrx~6dGjA "Use the glide.enforce_security_scope.sn_gsm_info_req property to control access to playbook data for the Information Request playbooks feature.")
* [Hide user comments on articles \[New in Security Center 1.3\]](knj4iectaPJovKZ7X0GY6w "Use the glide.knowman.show_user_feedback property to control whether feedback comments are visible.")
* [Ensure dashboards creation/deletion requires access check \[New in Security Center 1.3 and updated in 2.0\]](s11_aD28ivonSR~NlalwHw "The glide.processors.check_access_before_process system property enables access control list (ACL) enforcement for creating or deleting dashboards when a user is logged in.")
* [Enforce device encryption and passcode requirements \[New in Security Center 1.3\]](6WrBMdgYaajPI_d4EwjTHg "The glide.sg.device_encryption_enabled property enforces the Federal Information Processing Standard (FIPS 140-2) Encryption. Mobile device encryption and passcode ensure that an unauthorized user cannot access the content of a device even if the device is physically obtained.")
* [Validate file mime type in AttachmentCreator soap web service \[New in Security Center 1.3 and updated in 1.5\]](c8rB~JFw1zg~5XG_UkiVHw "The glide.attachment.enforce_security_validation property determines whether Multipurpose internet Mail Extensions (MIME) files undergo validation.")
* [Verify certificate revocation \[New in Security Center 1.3\]](4dWZ9LmI9zrGmgODIsOSog "The com.glide.communications.httpclient.verify_revoked_certificate property checks certificate revocation during the Transport Layer Security (TLS) handshake to ensure that security checks are not bypassed.")
* [Check impersonation on ACL evaluation in HR App \[New in Security Center 1.3 and updated in 1.5\]](HQnEmjc3hpJ9xM8tkEi1WA "Use the sn_hr_core.impersonateCheck property to prevent a user from impersonating another user and accessing their HR information.")
* [Require captcha for guest walk-up experience in customer service application \[New in Security Center 1.3 and updated in 1.5\]](JO5z~X1~pPeESEFgOG6bjg "The captcha for the Guest Walk-up experience prevents unauthenticated guest users to create bookings by requiring users to complete a captcha verification.")
* [Require Authentication on Event Management HTTP Processor \[New in Security Center 1.3, Updated in 1.5, and removed in 2.0\]](6aFlhMdJ9jzxo2HWuegF1g "Learn how to establish secure basic authentication for inbound Amazon Simple Notification Service (SNS) requests when the Event Management plugin (com.glideapp.itom.snac) is enabled.")
* [Limit guest's active session life span \[New in Security Center 1.3\]](DPHxp1WJGyO3WCVkhlf9kA "Use the glide.guest.active.session.life_span property to control the duration of an active guest’s HTTP sessions.")
* [Disallow target cloning \[New in Security Center 1.3\]](dC4RdD8GSawUpuo38Vy1eQ "Configure the glide.db.clone.allow_clone_target property to prevent your instance from being used as a clone target.")
* [Set safe content security policy for svg files \[New in Security Center 1.3\]](uii5Eo~ZxyFj8_6F3JDxwQ "The com.glide.csp.self_script_src_svg property adds the script-src none directive to the HTTP Content-Security-Policy header when Scalable Vector Graphics (SVGs) are accessed through the Translation Memory Index (IIX) file extension.")
* [Anti-CSRF token validation time \[New in Security Center 1.3\]](d8GRMtp~ddhHhkeTGaO7iA "The glide.security.csrf_previous.time_limit property specifies the time in seconds for a secure token to expire.")
* [Restrict knowledge bases access \[New in Security Center 1.3\]](UKHvUmudc7sTZcSi4AXVow "The glide.knowman.block_access_with_no_user_criteria property is used to control the read/write access of users on knowledge based articles.")
* [Enforce scope security for public sector digital services \[New in Security Center 1.3\]](nXX7ByWcSnuBKwq97o3g8A "Use the glide.enforce_security_scope.sn_gsm property to control how the application data from the Public Sector Digital Services application is accessed.")
* [Restrict HR case updates from personal emails \[New in Security Center 1.3 and updated in 1.5\]](H5lZ5b07XhCSHKjlWIEKGw "Use thesn_hr_core.restrict_guest_email property to control whether a user can respond back to a HR case with their personal email.")
* [Limit UI active session life span \[New in Security Center 1.3\]](7kzqZF1mnH1C05F8aCMTzA "The glide.ui.active.session.life_span property enforces max lifespan on active authenticated HTTP sessions irrespective of inactive timeout.")
* [Enforce secure referrer policy \[New in Security Center 1.3\]](ATX7WAQNzez~rO8U3jYaNg "Use the com.glide.security.referrerpolicy property to ensure that the Referrer-Policy HTTP header sends the appropriate level of data to each ServiceNow page to help prevent data leaks.")
{#new-hardening-settings__ul_qtt_q55_zyb}

