---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Explore

# Exploring Security Posture Control {#ariaid-title1}

* Release version: Australia
* 
* Updated July 31, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Security Posture Control

Security Posture Control (SPC) provides cybersecurity teams with comprehensive visibility into their enterprise asset inventory and overall security posture.
It integrates asset data imported from ServiceNow products like Hardware Asset Management (HAM) and ITOM Discovery, as well as from third-party tools via Service Graph Connectors.
SPC enables security analysts to assess security tool deployment coverage across assets, monitor compliance with internal security standards, and prioritize vulnerability remediation on high-risk assets.
Show full answer Show less  
SPC is composed of two applications available through separate subscriptions in the ServiceNow Store, leveraging Cloud Security Posture Management (CSPM) and Cyber Asset Hygiene Management (CAHM) frameworks.

## Key Features

* **Security Posture Insights:** View comprehensive insights for both on-premises and cloud assets, identifying gaps such as missing endpoint protection, unmanaged assets, internet exposure, and high-risk vulnerability combinations.
* **Custom Policies and Compliance Monitoring:** Create and configure policies to monitor asset compliance with internal security tool configurations, ensuring standards like up-to-date endpoint protection are met.
* **Automated Remediation Workflow:** Integrate with the ServiceNow Configuration Compliance application to automate assignment and remediation of identified security posture gaps.
* **Mitigation Controls Monitoring:** From the SPC Workspace, gain visibility into which threats are mitigated based on the configuration of various security tools.
* **Asset Security Posture Management (ASPM):** Uses API integrations with multiple categories of monitoring and security tools (e.g., endpoint management, network security, vulnerability assessment) to identify coverage gaps by comparing asset data in the CMDB reported by different tools.
* **High-Risk Combination Detection:** Identifies assets with critical vulnerabilities combined with security tool gaps and internet exposure. Requires Vulnerability Response application and vulnerability scanner integrations (e.g., Qualys, Rapid7, Tenable) available via separate subscriptions.

## How It Works

* Activate API connections with third-party and ServiceNow tools through Service Graph Connectors.
* Enable and configure Security Posture Control policies to evaluate asset security coverage.
* SPC identifies assets missing specific security tool coverage and reports these as findings in the Configuration Compliance application.
* Findings are automatically assigned to responsible remediation teams to streamline response efforts.

## Practical Benefits for ServiceNow Customers

* Achieve unified visibility of security tool coverage and asset compliance across your enterprise, both on-premises and cloud.
* Proactively detect security posture gaps to reduce risk exposure and prioritize remediation efficiently.
* Leverage automation to reduce manual tracking and accelerate vulnerability management workflows.
* Enhance threat mitigation understanding through monitoring of configured security controls.
* Extend your asset security management by integrating multiple data sources and vulnerability scanners in a centralized platform.  
Security Posture Control enables cybersecurity teams to get visibility into their complete enterprise asset inventory and determine their overall security posture.
Security analysts gain insights into how well security tools are deployed and covering their assets based on their asset inventories. This asset data is imported from service graph connectors and
ServiceNow products such as Hardware Asset Management (HAM) and ITOM
Discovery.

Security analysts can also create custom policies and configure insights to monitor the compliance of assets with internal security standards. Vulnerability managers can use insights from Security Posture Control (SPC) to prioritize remediation of vulnerabilities on high-risk assets.

The SPC product is based on Cloud Security Posture Management (CSPM) and Cyber Asset Hygiene Management (CAHM). Security Posture Control consists of two applications that are available by separate subscription from the ServiceNow® Store.
{#spc-overview__id_o2h_qpf_gbc__entry__2}

| Release version | Release notes |
|-|-|
| Security Posture Control Core: v7.1, v7.0 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498). |
| Asset Security Posture Management: v5.5 |   |
| Mitigation Controls Monitoring v4.2 |   |
[ ]

{#spc-overview__id_o2h_qpf_gbc}Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).

With the SPC product, Info-Sec teams can perform the following tasks:

* View security posture insights for your on-premise and cloud assets. SPC helps your Info-Sec teams identify assets that are missing endpoint protection, unmanaged assets, assets exposed to the internet, and any high-risk combinations involving vulnerabilities.
* Monitor your assets for their compliance with internal security tool configuration standards. For example, ensure that the latest version of an endpoint protection product is being used.
* Automate your remediation workflow for the security posture gaps you find with the ServiceNow Configuration Compliance application.
* Create custom policies and insights based on asset metadata, security tool coverage data, and vulnerability data.
* Gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured with [Mitigation Controls Monitoring](https://servicenow-prod.fluidtopics.net/qJ0t1xSq~1LC6CAMMFTpRA "From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.").
{#spc-overview__ul_rjl_ktm_gyb}

## How Asset Security Posture Management works {#spc-overview__section_ipr_y1y_hyb}

Asset Security Posture Management (ASPM) identifies security tool coverage gaps in assets by using API integrations with various third-party tools (Service Graph Connectors) along with ServiceNow products.

ASPM relies on data populated in your CMDB about your assets. The asset data is imported by various categories of monitoring tools and compared to identify any potential security gaps.

For example, say there is asset data populated in the CMDB that is reported by tools that cover infrastructure monitoring and networking tools. However, this data for those same assets is not
populated or reported by endpoint protection tools. If you compare the asset data reported by these different tools you can see that there are assets missing an endpoint protection agent.

Asset Security Posture Management identifies security tool coverage gaps in assets by using API integrations with various tools (Service Graph Connectors) and ServiceNow products. Categories include but are not
limited to the following:

* Digital Employee Experience
* Discovery
* Endpoint Management
* IT Asset Management
* Infrastructure Monitoring 
* Networking
* Network Security
* Network Performance Monitoring
* Configuration and Patch Management  
* Endpoint Protection
* Cloud Provider
* Application Performance Monitoring
* Directory Services
* Vulnerability Assessment
{#spc-overview__ul_wwp_fcy_hyb}

## The Security Posture Control workflow {#spc-overview__section_gjj_gvb_ccc}

Identifying security tool gaps involves the following steps:

1. Set up and activate API connections with any of the tools that you are using in various categories. You can use Service Graph Connectors for products that are available from the ServiceNow Store for the API connections that are required. For more information about the supported service graph connectors, see [Service Graph Connectors](https://www.servicenow.com/docs/access?context=cmdb-sgc-available&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US). Supported service graph connectors are available from the ServiceNow® Store with separate subscriptions.
2. Activate the policies shipped with the Security Posture Control application. The Security Posture Control product finds security tool gaps by performing the following tasks:
   1. Identifies the list of all unique assets populated by various Service Graph Connectors in the CMDB.
   2. Identifies assets that are not reported by specific categories from this asset pool, for example, Endpoint Protection. Assets are identified based on the active policy that is being evaluated.
   3. Assets identified as not reported by specific categories are reported as 'Findings' or 'Test Results' in the Configuration Compliance application.
   {#spc-overview__ol_cdf_3pn_lcc}
3. Automatically assign 'Findings' to different teams for remediation with the Configuration Compliance application.
{#spc-overview__ol_utn_l2y_hyb}

## High-risk combinations {#spc-overview__section_m1n_w5b_ccc}

With Asset Security Posture Management, you can also identify assets that have high-risk combinations. An example of a high-risk combination might show assets that are missing security tools, have critical
vulnerabilities, and are exposed to the internet.

Some of the policies shipped with the Security Posture Control application look for these high-risk combinations of critical vulnerabilities and security tool coverage gaps. However, for these combination policies to work, you must have the Vulnerability Response application and at least one vulnerability scanner integration product. Products such as Qualys, Rapid7, or the Tenable Vulnerability Integration application installed. These applications are available with separate subscriptions from the ServiceNow Store.

## Mitigation Controls Monitoring {#spc-overview__section_mdb_rdz_fdc}

From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured. See [Mitigation Controls Monitoring](https://servicenow-prod.fluidtopics.net/qJ0t1xSq~1LC6CAMMFTpRA "From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.") for more information.

