---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Adjust instance security settings to increase compliance

# Adjust instance security settings to increase compliance {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 Minuten Lesedauer

Using the Hardening Compliance Configuration page, harden and optimize non-compliant
security properties that affect the daily compliance score of your instance. Its use ensures
that your instance complies with the published security hardening standards, while
fulfilling your company's security requirements.

## Vorbereitungen

Role required: security_dashboard_user or admin.
Refer to the [Hardening settings](https://servicenow-prod.fluidtopics.net/RXuZVYITUAWpGv29FS1iKg "The ServiceNow Security Center (SSC) hardening settings content contains detailed descriptions and compliance values for the security-related system properties and plugins in the ServiceNow AI Platform. You can set these properties using the hardening settings app in the Security Center.") content for detailed descriptions, and compliance values, for the security-related system properties and plugins in the ServiceNow AI Platform.

* Consult the Instance Security Hardening Settings whenever you set or update security-related properties, even if some of the compliance values may not be suitable for your instance.
* When you are updating these properties, ensure that the instance continues to behave as expected. Consult with the appropriate internal personnel who have the expertise to determine the security impacts.

{#update-security-hardening-params__ul_dxz_wf3_nlb}  
Hinweis:  
If you have an admin role, you can view and edit security controls. If you have a security_dashboard_user role, you can view security controls, but you cannot edit them.

## Prozedur

1. Navigate to AllSystem SecurityInstance Security Center.
2. Click the Daily Compliance Score tile or the Hardening link to access the Hardening Compliance Configuration page.  
3. In the Hardening Compliance chart, view the statistics for compliant and non-compliant security configuration properties.

   | Option | Bezeichnung |
   | Compliant | Number of security configuration properties that comply with the compliance values in the Instance Security Hardening Settings. Hinweis: You cannot change the settings for compliant security properties in the Hardening Compliance Configuration. If you want to do so, you must update them in System Properties. To learn more, see [Add a system property](https://www.servicenow.com/docs/access?context=t_AddAPropertyUsingSysPropsList&version=australia&pubname=australia-platform-administration&ft:locale=en-US). |
   | Non-Compliant | Number of security configuration properties that do not comply with the compliance values in the Instance Security Hardening Settings. You can update settings for non-compliant properties. |
   |-|-|

   {#update-security-hardening-params__choicetable_lvw_mhf_kfb}  
   Hinweis:  
   To view the number of compliant or non-compliant security scores over a range of dates, move the blue dot on the slider below the Daily Compliance Score.
4. In the Show list below the chart, specify whether you want to access all security configuration properties, or only recommended ones.

   | Option | Bezeichnung |
   | All | (Default) All compliant and non-compliant security configuration properties in each selected category. |
   | Recommended | Only recommended security configuration properties appear in each selected category. These security configuration properties are a selected subset of the most critical ones used to secure the ServiceNow AI Platform. Consider these security configuration properties to be the bare minimum number of settings you must set to secure the ServiceNow AI Platform. Hinweis: To fully secure your instance, use the All option. It includes all recommended security configuration properties too. |
   |-|-|

   {#update-security-hardening-params__choicetable_kwb_2q5_mlb}  
5. In Categories, select the category that contains the security configuration properties you would like to access:  

   | Option | Bezeichnung |
   | Access Control | Access controls determine whether to grant or deny user access to a particular resource based on who is permitted to use those resources. To learn more, see [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") in the Instance Security Hardening Settings. |
   | Attachments | Attachment security controls enable validation of incoming attachments to protect your instance against malicious files sent by attackers. To learn more, see [Validate file mime type in AttachmentCreator soap web service \[New in Security Center 1.3 and updated in 1.5\]](c8rB~JFw1zg~5XG_UkiVHw "The glide.attachment.enforce_security_validation property determines whether Multipurpose internet Mail Extensions (MIME) files undergo validation.") in the Instance Security Hardening Settings. |
   | Email Security | Email security encompasses security configuration properties an administrator can configure to ensure that proper security policies are in place for all inbound emails. To learn more, see [Enable email spam scoring and filtering \[Updated in Security Center 1.3\]](6iyDJBaiNtknZsx~T3bWsA "Install the Email Filter (com.glide.email_filter) plugin to install email filtering within the instance. This filtering identifies existing headers, which enables you to decide what to do with the email based on the associated header. Alternatively, set com.glide.email_filter to false.") in the Instance Security Hardening Settings. |
   | Input Validation | Input validation includes security-related properties that an administrator can configure to minimize entry of malformed data, regardless of source. To learn more, see [Validation, sanitization, and encoding](https://servicenow-prod.fluidtopics.net/F1nREUr0FIKK6cga6jbKwg "Validation, sanitization, and encoding addresses input validation to prevent against vulnerabilities like Cross-Site Scripting (XSS), SQL injection and other attacks.") in the Instance Security Hardening Settings. |
   | Secure communications | Secure communications properties are those that an administrator can configure to secure the transportation of HTTP traffic. To learn more, see [Communications](https://servicenow-prod.fluidtopics.net/KYWXOfqNUW0uNGo3zippJA "This control ensures proper encryption using strong algorithms and ciphers. This includes ensuring the recommended version of TLS is used for client connectivity, use of strong cipher suites, use of trusted and signed certificates, ensuring connections are encrypted between components and logging of connection failures.") in the Instance Security Hardening Settings. |
   | Security Best Practices | Security best practices encompass Security Tasks that an administrator should perform periodically, within a certain interval of time, and include related configuration properties. To learn more, see [Security Best Practices](https://servicenow-prod.fluidtopics.net/l_pkb7BNrSWMERFK4CI~Gw "Use Security Best Practices to implement privacy and security configuration tasks on your ServiceNow instance.") in the Instance Security Hardening Settings. |
   | Security Inclusion Listing | Security inclusion listing includes security-related properties that an administrator can configure to restrict behavior to known inclusion listings. |
   | Session Management | Session management includes security-related properties that an administrator can configure to ensure secure session management in the ServiceNow AI Platform. To learn more, see [Session management](https://servicenow-prod.fluidtopics.net/VAFB7gAR3D02VvnVYJ_a3g "This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.") in the Instance Security Hardening Settings |
   |-|-|

   {#update-security-hardening-params__choicetable_lbl_dnx_lgb}
6. Configure the non-compliant security properties in the selected category.  
   * Unless otherwise specified, sliding the switch on sets a security property to its recommended setting. For example, you set most controls to true or false, but some require entry of a value, or values, such as a comma-separated value list.
   * To access the dedicated Instance Security Hardening Settings topic for the security control, and learn more about it, click More Info.
   {#update-security-hardening-params__ul_vkp_31v_mlb}

## Ergebnisse

The Daily Compliance score increases or decreases depending on the changes that you
make to the non-compliant security control settings.
**Zugehörige Konzepte**   

* [Instance Security Center](https://servicenow-prod.fluidtopics.net/xpUTpZb5ScUKqSrIXf3_Yg "Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.")

