---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Policies

# Policies for Security Posture Control {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Policies audit your assets based on data imported from your service graph connectors to help you find potential violations.

## Policies {#spc-policies-overview__section_rgn_k5z_hyb}

Security Posture Control policies are built on an asset-relationships-properties data model. There are policies that are included with the application, and you can create your own policies to look for specific
criteria.

The criteria for policies can be specified either in the form of conditions on that asset's properties or on a related entity's properties. From the policy builder in the Policy and findings module in the workspace, you can define
policies to look for an asset type (Hardware, Software) and a Connection (Reported by, Not reported by), or an Entity (Asset source, service graph connector product, or CMDB Metadata), or you can match other types of specific
criteria.  
To help you with modifying or creating policies:

* Set your conditions in the Asset search module and search for assets by specific service graph connector products or for assets that have specific data reported by a connector. You can save your searches as policies.
* Clone the policies that are included with the application to create more expansive policies. You copy and then refine an existing policy's conditions without having to re-enter them.
* Create new policies (child policies) using base policies you select as a starting point for new policies.
{#spc-policies-overview__ul_jyw_v3l_dcc}

## Asset types and policies {#spc-policies-overview__section_g1p_ljl_dcc}

You use these primary, or top-level asset types as a starting point for defining policies.  

Hardware Asset
:   Hardware Asset is an abstraction that represents any device that includes personal computing devices, servers, network devices, cloud virtual machines, and other hardware. Policies audit your assets for potential violations
    based on the imported data from service graph connector products and ServiceNow® products such as Software Asset Management (SAM) and ITOM Discovery.

Software Asset
:   Software Asset permits you to look for any discrepancies that exist between the installed software reported by imported data from service graph connectors, your vulnerability scanner products, and the software reported by
    scanners that is already accounted for in Software Asset Management (SAM) and other ServiceNow products.
{#spc-policies-overview__table_sx3_p5n_lcc__entry__4}

| Entity | Relationship | Target entity | Description |
|-|-|-|-|
| Hardware Asset | Reported by | Asset Source | Represents a source that reported this asset into CMDB. |
| Hardware Asset | Reported only by | Asset Source | Represents the only source reporting this asset into CMDB. |
| Hardware Asset | Not reported by | Asset Source | Represents a source that did not report this asset into CMDB. |
| Hardware Asset | With IRM Exception | IRM Exception | Represents an exception record in Integrated Risk Management. |
| Hardware Asset | With vulnerability | Vulnerability | Represents a vulnerability found on this asset. |
| Hardware Asset | Has configuration finding | Configuration | Represents a configuration and a compliance issue found on this asset. |
| Hardware Asset | With CMDB metadata | CMDB Metadata | Represents the collection of CMDB CI properties on this asset. |
| Hardware Asset | With connector data | Service Graph Connector | Represents collection of properties reported by selected service graph connector for this asset. |
| Hardware Asset | With aggregated data | Aggregated data | Collection of properties with aggregated values reported by different sources for a given asset. An example is OS. |
| Hardware Asset | From CI Class | CMDB CI Class | Used for defining conditions on specific CI class properties. |
| Hardware Asset | Has cloud metadata | Cloud Metadata | Represents cloud metadata (applicable for cloud VMs). |
| Hardware Asset | Has port exposed to internet | OpenPort | Represents a port open to the internet (applicable for cloud VMs). |
| Software | Reported by | Asset Source | Represents a source that reported this software. |
| Software | Reported only by | Asset Source | Represents the only source reporting this software. |
| Software | Not reported by | Asset Source | Represents a source that did not report this software. |
| Software | With software details | Software | Represents the collection of software properties such as publisher and version, for example. |
[Table 1. Entities and their relationships to secondary entities]

{#spc-policies-overview__table_sx3_p5n_lcc}

## Example policy audit and data population: CI classes in the CMDB {#spc-policies-overview__section_of3_5qm_dcc}

If a policy tries to retrieve an asset class that is reported or not-reported by a specific Service Graph Connector, Security Posture Control maps all the relevant configuration item (CI) classes that are related to that asset class
in the CMDB that are populated or not-populated by that Service Graph Connector or connector Category.

For example, say a policy looks for all the hardware assets that are reported by the Service Graph Connector Jamf Pro. The following logic applies.

1. Security Posture Control identifies which CI classes in the CMDB are mapped to the class 'Hardware Asset' for Jamf Pro.  
   Note:  
   Different Service Graph Connectors populate different CI classes in the CMDB, and the mapping to CI classes from 'Hardware Asset' varies from one Service Graph Connector to another.
2. Security Posture Control determines that the CI classes, Computer, Server, and Printer in the CMDB are mapped to the 'Hardware Asset' asset class for the Service Graph Connector Jamf Pro.
3. Security Posture Control then queries for any asset records populated in any of these three CI classes: Server, Computer, and Printer by the Jamf Pro Service Graph Connector in the CMDB and returns those assets.

   The 'CI classes supported by SPC' column in the following table indicates which classes of CI records are considered during a query by the Security Posture Control product as part of a policy evaluation. This table is
   not a comprehensive list, but you can use it to see how ingested data from various categories and sources is generally mapped and queried.
{#spc-policies-overview__ol_pf3_5qm_dcc}

## Policies included with the application {#spc-policies-overview__section_xls_hkk_1gc}

Activate the asset proﬁles and policies in the Security Posture Control workspace that are [Included with the application](https://servicenow-prod.fluidtopics.net/gebkZuSAkDMuPJ32A4Hcrw "There are a few policies that are included with the Security Posture Control application that are tied to important use cases and are ultimately shown as key insights on the dashboard on the landing page (Home module) in the SPC Workspace.") so that you can identify gaps in configuration or coverage for security tools.

## Creating your own policies {#spc-policies-overview__section_p11_4nz_dcc}

See [Creating your own policies in the Security Posture Control application](https://servicenow-prod.fluidtopics.net/FwgODHWAP6I~VR7rpDXbMg "You can create your own custom policies to monitor data that is specific to the assets in your environment. You base these policies on data you will import from the various Service Graph Connectors you have installed and activated.") for more information about how to create your own policies.

For example policies, see [Examples of base, child, and cloned policies for Security Posture Control](https://servicenow-prod.fluidtopics.net/3jRePf1q0A3v5nhKueUYRQ "You can create your own base policies that have broad sets of conditions that you can use as starting points for more complex policies.").

See [Create and activate custom policies for Security Posture Control](https://servicenow-prod.fluidtopics.net/DHTaHFvZydVudRl7PnhfKQ "Create your own custom policies to monitor assets for tool coverage and other high-risk combinations.") for more information about the steps required to create a policy.

## Supported SGCs {#spc-policies-overview__section_qf3_5qm_dcc}

For a list of some of the supported service graph connectors, see [Supported hardware service graph connectors for Security Posture Control](https://servicenow-prod.fluidtopics.net/jrrwRJgGaAdg42dCDEzhNg "Supported Hardware service graph connectors with CI class, source (product), and tool categories. This list is not complete and is subject to change with the addition of more products.") and [Supported software service graph connectors for Security Posture Control](https://servicenow-prod.fluidtopics.net/hsG2giJ3LAnPCNw56vziCw "Supported Software service graph connectors with CI class, source (product), and tool categories. This list is not complete and is subject to change with the addition of more products.").

## Mitigation Controls policies {#spc-policies-overview__section_g1l_hcz_fdc}

From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured. See [Mitigation controls policies](https://servicenow-prod.fluidtopics.net/NPOmlmzMFo6ejx3b2OzLsA "The Security Posture Control and the Mitigation Controls applications are required to view the mitigation controls and mitigation controls policies in the SPC. Both applications are available from the ServiceNow Store.") for more information.

