---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enable High Security Plugin \[Updated in Security Center 1.3\]

# Enable High Security Plugin \[Updated in Security Center 1.3\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

When you activate the High Security plugin, it creates or updates hundreds of different
configurations to control the level of security on your instance. These configurations mitigate
many of the top OWASP attacks by enabling strict access control, input validation, and output
encoding.
These configurations include:

* Access Control
* Business rules
* System properties
* UI policy action
* script actions
* script includes
{#sc-high-security-plugin__ul_i1m_msx_nkb}

## Example {#sc-high-security-plugin__section_example}

Refer to the examples for the following properties:
{#sc-high-security-plugin__table_dyv_wqx_nkb__entry__2}

| Property | Topic |
|-|-|
| glide.ui.escape_all_script | [Escape jelly script \[Updated in Security Center 1.3 and 1.5\]](1Sr0HpOv_ulGo9FNu4VPYw "Use the glide.ui.escape_all_script property to force escape of all scripts injected into Jelly.") |
| glide.security.strict.actions | [Check UI action conditions before execution](https://servicenow-prod.fluidtopics.net/QeEd21E6qrFitL0oWR7qCg "Use the glide.security.strict.actions property to enable checking of UI actions conditions in forms and lists before they execute. When you set this property to true, it adds an extra layer of validation on the table UI actions before they are executed.") |
| glide.security.csrf_previous.allow | [Enable Anti-CSRF token \[New in Security Center 1.3, updated in 1.5, and removed in 2.0\]](5HnExiYsP8dMZYFTOTUV6w "Use the glide.security.use_csrf_token property to ensure the use of a secure token to identify and validates incoming requests, which in turn are used to prevent these attacks.") |
| glide.security.csrf.strict.validation.mode | [Prevent Users From Accepting Warning To Bypass CSRF Validation \[Updated in Security Center 1.3 and 1.5\]](Z5GsDZSNPcMjr5Wprc_oCw "Use the glide.security.csrf.strict.validation.mode property to enable CSRF token strict validation. If the CSRF token doesn't match, it prevents resubmission of the request.") |
[ ]

{#sc-high-security-plugin__table_dyv_wqx_nkb}

## More information {#sc-high-security-plugin__section_more_information}

{#sc-high-security-plugin__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Plugin Name | com.glide.high_security |
| Configuration type | System Definition \> Plugins - Development |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Purpose | It is mandatory to activate this plugin. It increases the security level of an instance, which reduces the attack surface by mitigating owasp top 10 attacks, including CSRF, XSS, Securing Session Cookies, and File uploads. |
| Recommended value | Active |
| Security risk rating | 9.8 |
| Functional impact | This plugin enables several system security configurations, which may impact UI and functionality as well. |
| Security risk | (High) Many security configurations are unintentionally left open, which may open the door for some of the critical vulnerabilities. |
| References | [Activating High Security Settings](https://servicenow-prod.fluidtopics.net/x4_sab01YzabJ6GB7Vn~3g "The High Security Settings plugin is active by default on all new instances. If it is not active on your instance, you can request the plugin.") [High Security Settings](https://servicenow-prod.fluidtopics.net/f8gVxeeTKuTUbGIE_Ua8hw "High Security Settings refer to several security options available in your instance.") |
[ ]

{#sc-high-security-plugin__table_ajc_b43_3kb} To learn more about activating a plugin, see [Activate a plugin](https://www.servicenow.com/docs/access?context=t_ActivateAPlugin&version=australia&pubname=australia-platform-administration&ft:locale=en-US)

