---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install supported applications

# Install the supported applications for Security Posture Control {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

The applications required for this integration are available on the ServiceNow Store. Some applications have dependencies that you must download and install separately.

## Before you begin

Role required: admin for download, installation, and activation of all applications.

## Procedure

1. Download the required applications from the ServiceNow Store into your ServiceNow instance.  
   The Security Posture Control (SPC Core) application provides the core framework and is required for Asset Security Posture Management (ASPM). The Configuration Compliance application and its dependencies permit you to create remediation tasks for the security control gaps you find using Asset Security Posture Management.  
   {#spc-install__table_vzt_cjq_ktb__entry__2}

   | Application | App ID |
   |-|-|
   | Asset Security Posture Management | (Plugin id: sn_sec_caasm) |
   | ITOM Discovery License | (Plugin id: com.snc.itom.discovery.license) |
   | Security Posture Control Core | (Plugin id: sn_sec_spc_core) |
   | Mitigation Controls Monitoring | (Plugin id: sn_sec_mit_ctr) |
   | Configuration Compliance (includes child app secops_shared_components)  | (Plugin id: sn_vulc) |
   | Vulnerability Response Licensing and Usage | (Plugin id: sn_vul_licensing) |
   [Table 1. Asset Security Posture Management applications]

   {#spc-install__table_vzt_cjq_ktb} {#spc-install__table_oxx_3cb_vcc__entry__2}

   | Application | App ID |
   |-|-|
   | Discovery Plugin | (Plugin id: com.snc.discovery) |
   | Cloud Configuration Governance | (Plugin id: sn_itom_ccg) |
   | CCG Content Pack | (Plugin id: sn_itom_ccg_cp) |
   | CMDB CI Class Models | (Plugin id: sn_cmdb_ci_class) |
   | Cloud Action Library | (Plugin id: com.sn.itom.cal) |
   [Table 2. Cloud Security Posture Management applications]

   {#spc-install__table_oxx_3cb_vcc}  
   {#spc-install__entry__28}

   | Application | Application ID and version |
   |-|-|
   | Security Posture Control API Connectors | sn_spc_cxf |
   | Security Posture Control | sn_sec_spc_core |
   | Asset Security Posture Management | sn_sec_caasm |
   | Mitigation Controls Monitoring | sn_sec_mit_ctrl |
   [Table 3. Required applications for the SPC Connector Framework]

   {#spc-install__entry__38}

   | Plugin | Plugin ID |
   |-|-|
   | ServiceNow IntergationHub Action Template - Data Stream | com.glide.hub.action_type.datastream |
   [Table 4. Plugin dependencies]

   See [Creating your own API connectors in Security Posture Control](https://servicenow-prod.fluidtopics.net/HZVE2nuXoLj8UufWJr_MqQ "Create your own Security Posture Control (SPC) API connectors using the connector framework that is included with the application.") for more information.  
   For more information about downloading and activating applications, see the following topics:
   * [Download an application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
   * [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.").
   {#spc-install__ul_oh3_5qd_5tb}
2. After you have downloaded the applications, navigate to AllSystem ApplicationsAll Available ApplicationsAll.
3. Locate the applications that you downloaded and select Install to activate them along with their dependencies.  
   Any dependency applications that are also installed automatically along with an application are displayed in the Application installation dialog. However, if you are prompted to install dependency plugins during the installation, follow the prompts provided. Verify you have all the applications and dependencies listed in the previous table installed and activated.

   A dialog is displayed after an application is successfully
   activated.  
   For more information about downloading and installing applications from the ServiceNow Store:
   * To Opt in to ServiceNow products, follow the steps in [Opt in to the ServiceNow Store products](https://www.servicenow.com/docs/access?context=optin-optout-prod&version=australia&pubname=australia-platform-administration&ft:locale=en-US).
   * To install an application that you have purchased from the ServiceNow Store, follow the steps in [Install a ServiceNow Store application](https://www.servicenow.com/docs/access?context=t_InstallApplications&version=australia&pubname=australia-platform-administration&ft:locale=en-US).
   * Alternatively, if you want to manage your entitlement for the applications on other ServiceNow AI Platform instances, follow the steps in [Manage entitlements from your ServiceNow instance](https://www.servicenow.com/docs/access?context=entite-app&version=australia&pubname=australia-platform-administration&ft:locale=en-US).
   {#spc-install__ul_edx_rcd_h2c}
4. After you have installed and activated the applications, assign users to the following Security Posture Control groups:  
   These groups inherit all the roles necessary to read and edit SPC records.

   SPC Admin Group
   :   Users in this group have full read and write access to all the records for the product, including licensing information. Granular roles for this group include: \[sn_sec_caasm.analyst,
       sn_sec_caasm.caasm_security_admin, and sn_sec_spc_core.configure\].

   SPC Analyst Group
   :   Users in this group have full read and write access to all the records for the product but cannot view licensing information. Granular roles for this group include \[pa_power_user and
       sn_sec_spc_core.analyst\].

   SPC Analyst Read Only Group
   :   Users in this group have full read access to all the records for the product but cannot view licensing information. Granular roles for this group include \[pa_power_user, sn_sec_spc_core.analyst_read,
       sn_sec_caasm.read, and cmdb_ms_user\].

   Supporting application roles
   :   The following roles are required by the applications listed in the preceding table that support SPC and Asset Security Posture Management.
       * Configuration Compliance Admin \[sn_vulc.admin\] - Configures the Configuration Compliance application, has visibility to all records, and can modify properties. Assigns roles in the Configuration Compliance application.
       * Vulnerability Response Admin \[sn_vulc.admin\] - Configures the Vulnerability Response application and the vulnerability risk calculators.
       * MID Server \[mid_server\] - Configures a MID Server.
       {#spc-install__ul_rsd_1nn_lcc}
5. Set the glide.identification_engine.multisource_enabled system property to true.  
   Security Posture Control relies on data from service graph connectors that is populated in the CMDB 360 Data \[cmdb_multisource_data\] table. This data is populated only when the glide.identification_engine.multisource_enabled system property is set to true. You must have the cmdb_ms_admin role to modify property values. To set the property, navigate to AllConfigurationCMDB 360 Properties.
6. **Optional:** Set the ignoreCIClass \[sn_sec_cmn.ignoreCIClass\] system property to ignore some configuration item (CI) classes when running CI Lookup Rules.  
   As an SPC Admin and SPC Analyst, you might need to ignore certain hardware or virtual classes. By ignoring these items, you do not ingest information about assets you do not want to control. See [Create a Vulnerability Response CI lookup rule](https://servicenow-prod.fluidtopics.net/DQQBP6USedqPaEVrEOS8cg "The CI Lookup Rules module contains rules that are used to find the matching record for host information received during third-party vulnerability integration imports. The host information is matched with the discovered items, unmatched configuration item classes, and the Configuration Management Database (CMDB).") and [Ignore CI classes](https://servicenow-prod.fluidtopics.net/_ePaKee3N7E9o7oYAwvelg "To ignore some configuration item (CI) classes, for example Load Balancer [cmdb_ci_lb], when running CI Lookup Rules, set the ignoreCIClass [sn_sec_cmn.ignoreCIClass] system property.") for more information.
7. Modify reconcilation and recompute CMDB data sources to set the source of truth for attribute values.  
   The CMDB 360 dashboard provides aggregations and analysis of CMDB 360 data. CMDB 360 collects data about all the discovery sources reporting attribute values for CIs. Use the CMDB 360 view in Configuration Management
   Database (CMDB) Workspace to track activities and identify potential issues of discovery sources. See [CMDB 360 view in CMDB Workspace](https://www.servicenow.com/docs/access?context=cmdb-workspace-cmdb360-view&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US) for more information.

*[\>]: and then


