---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enforce ACL on HR Core Data \[New in Security Center 2.0\]

# Enforce ACL on HR Core Data \[New in Security Center 2.0\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Learn how to configure the
glide.enforce_security_scope.sn_hr_core property so that the Human
Resources Scoped App: Core (com.sn_hr_core) plugin does not expose sensitive data to access
control lists (ACLs) from all other scopes.
The glide.enforce_security_scope.sn_hr_core property restricts the access control lists (ACLs) of several global data tables like sys_attachment and sys_email to only consider the sn_hr_core scope. If
this property is not set to the recommended value of true, then data from the Human Resources Scoped App: Core plugin will be exposed to ACLs from all other scopes. For instance, this could result in the IT administrator
gaining access to human resources data.
Warnung:  
This is a safe harbor property, meaning the value can't be altered once it's changed. It is non-revertible.

## More information {#sc_enforce_acl_on_hr_core_data__section_p42_ydg_kcc}

{#sc_enforce_acl_on_hr_core_data__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.enforce_security_scope.sn_hr_core |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 6.5 * CVSS score: Medium * Security risk details: If this property is not set to the secure value of true, then data from the Human Resources Scoped App: Core plugin will be exposed to ACLs from all other scopes. {#sc_enforce_acl_on_hr_core_data__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
| References | [Activate Case and Knowledge Management](https://www.servicenow.com/docs/access?context=activate-case-and-knowledge-management-scoped&version=australia&pubname=australia-employee-service-management&ft:locale=en-US) |
[ ]

{#sc_enforce_acl_on_hr_core_data__table_ajc_b43_3kb}

