---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configuration

# Configuration {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

The Configuration category ensures applications have a secure build environment and
hardened third party library components. Specifically, ensuring a build and deploy pipeline is
repeatable and includes automated testing and prevents known security issues from being
deployed. This includes keeping dependencies up to date and free from known
vulnerabilities.
* **[Allow CORS Origins for OAuth Endpoints](https://servicenow-prod.fluidtopics.net/qZJ~tKS~T8wfEC~1iXVg3g)**   
  Use a system property to configure to specify which domains are allowed to make cross-origin requests.
* **[Auto set content type options \[Removed in Security Center 1.3.3\]](HRNFaLuOJjghdSP9ulIRBQ)**   
  Configure the Auto set content type options property on your instance to prevent MIME confusion attacks.
* **[Cache-Control HTTP Header Value \[Updated in Security Center 1.3 and removed in 1.5\]](RpDuKWO1pfoIsubJNuS60Q)**   
  Use the glide.http.cache_control property to set the default cache-control value in the HTTP response headers that the ServiceNow AI Platform sends when requesting static content data for a page. Examples of static content include images, CSS, and JavaScript rendered from within, for a page.
* **[Enable HTTP response headers configuration](https://servicenow-prod.fluidtopics.net/W0e08iyIaniQMv7lvpFJVg)**   
  Reduce the risk of cookie/session-related hijacking of web apps using a system property.
* **sc-disable-chat-server-debugging.html**   
* **[Disable legacy JQuery UI usage](https://servicenow-prod.fluidtopics.net/I7LiugNU48EnkKG8YuYe~Q)**   
  Avoid the introduction of unpatched vulnerabilities in the library by disabling legacy JQuery UI usage.
* **[Disable locked form elements debugging](https://servicenow-prod.fluidtopics.net/tcaYz2tbbJAgtGAPPukylQ)**   
  Here's the description for glide.security.explain.write.locks.
* **[Disable MultiSSO Debugging \[Updated in Security Center 1.3 and 1.5\]](6Lft4QwLJXO1koDsuQCHrg)**   
  The glide.authenticate.multisso.debug property controls debug logging for Multi-SSO.
* **[Disallow target cloning \[New in Security Center 1.3\]](dC4RdD8GSawUpuo38Vy1eQ)**   
  Configure the glide.db.clone.allow_clone_target property to prevent your instance from being used as a clone target.
* **[Disable soap fault stack trace display](https://servicenow-prod.fluidtopics.net/~kh5DOysUYgTfMmKhUW71w)**   
  Manage how stack traces are displayed in your instance.
* **[Restrict performance monitoring access \[Updated in Security Center 1.3\]](sjzjGdo~L9tCxLbheNiv2Q)**   
  Use the glide.security.diag_txns_acl property to control stats.do, threads.do, thread_pool_stats, and replication.do access from an unauthenticated connection.
* **[Enable updated version of MultiSSO plugin \[Updated in Security Center 1.3 and 1.5\]](MY4Ae4WgKgHQgQBGDHx_9A)**   
  Verify that you're using v2 of the MultiSSO plugin and that it's set to true to reduce security vulnerabilities.
* **[Enforce secure referrer policy \[New in Security Center 1.3\]](ATX7WAQNzez~rO8U3jYaNg)**   
  Use the com.glide.security.referrerpolicy property to ensure that the Referrer-Policy HTTP header sends the appropriate level of data to each ServiceNow® page to help prevent data leaks.
* **[Ensure minimum private key size](https://servicenow-prod.fluidtopics.net/SvbSc3R1bLNqMQQsTe16TA)**   
  Use a system property to determine the minimum size of the private key used for Certificate Signing Request (CSR) generation with the Certificate Inventory Management application.
* **[Implement the x-frame-options: SAMEORIGIN security header \[Updated in Security Center 1.3\]](7tqYV9SdmuAAJrLLrJQ8MQ)**   
  Use the glide.set_x_frame_options property to set the X-Frame-Options response header to SAMEORIGIN for all UI pages.
* **[Require write access to access service catalog add item page \[New in Security Center 1.3\]](03PZXYGzrgdetyEcMhnshA)**   
  Use the glide.sc.request.add_item_write_access property to prevent unauthorized operations from being performed on catalog items.
* **[Set Xframe options to prevent embedding third-party websites \[Updated in Security Center 1.3\]](wR1Nz4iF_93qCCjm8HjX_Q)**   
  Configure this property to prevent the content of a web-application from being embedded in a third-party site.

