---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Mitigation controls policies

# Mitigation controls policies {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Posture Control and the Mitigation Controls applications are required to view the mitigation controls and mitigation controls policies in the SPC. Both applications are available from the ServiceNow Store.
Refer to the following topics for more information about downloading and installing applications from the ServiceNow® Store.

* [Download an application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.")
* [Install a Security Operations integration](https://servicenow-prod.fluidtopics.net/dIzJWROPdytPu1FmtvPx3w "All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Security Incident Response, are visible in the ServiceNow Products tab on the store. Integration add-ons are visible in the Certified Apps tab.")

{#spc-mitigation-policies__ul_zm2_mpt_pcc}

To view the mitigation controls policies, users in the SPC Admin Group and SPC Analyst Group can navigate to WorkspacesSecurity Posture ControlPolicies and findingsAll in the SPC Workspace navigation panel.  
The following mitigation controls policies are included with the application and are displayed along with the other SPC policies:

* SEH Overwrite
* Heap spray
* CrowdStrike NULL Page Allocation
* CrowdStrike Force DEP
* CrowdStrike Force ASLR
* Microsoft Defender Control Flow Guard
* Microsoft Defender force ASLR
* Microsoft Defender Mandatory ASLR and Bottom-up ASLR
* SentinelOne Application Control
* SentinelOne Data Files
* SentinelOne Executables
* SentinelOne Exploits
* SentinelOne IDR
* SentinelOne Detect Interactive Threat
* SentinelOne Detect Lateral Movement
* SentinelOne Static AI
* SentinelOne Static AI - suspicious
* SentinelOne Potentially unwanted applications
* SentinelOne Remote shell
* SentinelOne Reputation
{#spc-mitigation-policies__ul_nnt_pn5_pcc}

## Mitigation controls categories {#spc-mitigation-policies__section_r5v_grt_pcc}

The following categories of mitigation controls are currently supported with the SPC.

* [Mitigation controls and policies required for Exploit Protection (EDR) mitigation controls](https://servicenow-prod.fluidtopics.net/c7D1xTnxyjC1zt1x3Ytu4A "This category of mitigation controls covers mitigations available on your assets in the form of endpoint protection agent configuration. This applies to endpoint protection agents such as CrowdStrike and SentinelOne.").
* [Exploit Protection (WAF) mitigation controls](https://servicenow-prod.fluidtopics.net/nJOHDV7i3zFZ7enzlnpOpA "This category of mitigation controls covers mitigations available in the form of Web Application Firewall."). You must create policies for AWS WAF. See [Create a policy for the AWS WAF integration for mitigation controls monitoring](https://servicenow-prod.fluidtopics.net/K~02EQIA9USMvGnoeFKu6Q "Create a policy so you can audit your assets based on data imported from the integration.") for more information.
{#spc-mitigation-policies__ul_hts_nrt_pcc}

*[\>]: and then


