---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use the workspace

# Using the Security Posture Control workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using the Security Posture Control workspace

The Security Posture Control workspace allows users to configure, monitor, and manage data related to their assets.
It is essential for assessing and improving your organization's security posture through various modules and policies.
The workspace's functionality is tailored for different user roles, ensuring appropriate access to sensitive information based on responsibilities.
Show full answer Show less  

## Key Features

* **Modules:**
  * **Home:** View visualizations and insights on asset security status.
  * **Configured Insights:** Monitor customized data visualizations on your assets.
  * **Asset Search:** Quickly locate assets based on defined conditions.
  * **Asset Profiles:** Create profiles to monitor specific asset categories.
  * **Policies and Findings:** Create and manage policies to audit assets for compliance.
  * **Connectors and Use Cases Setup:** Activate service graph connectors and set up use cases to monitor assets.
  * **Custom Insight Builder:** Design personalized visual reports based on policy results.
* **User Roles:** Different roles provide varying levels of access, from full administrative rights to read-only capabilities, ensuring secure management of asset data.
* **API Connections:** Utilize Service Graph Connectors for integrating with various tools to enhance asset visibility.

## Key Outcomes

By effectively using the Security Posture Control workspace, customers can:

* Identify security tool gaps through comprehensive asset tracking and policy evaluations.
* Automate remediation workflows via the Configuration Compliance application, ensuring timely action on identified findings.
* Enhance visibility into asset security by creating custom policies and insights tailored to specific organizational needs.

Utilizing this workspace empowers organizations to strengthen their security posture and effectively manage compliance requirements across their asset landscape.  
The Security Posture Control workspace contains the modules you use for configuring, using, and monitoring the imported data about your assets.

## Roles {#spc-workspace__section_omb_dpt_ncc}

SPC Admin Group
:   Users in this group have full read and write access to all the records for the product, including licensing information. Granular roles for this group include: \[sn_sec_caasm.analyst, sn_sec_caasm.caasm_security_admin, and
    sn_sec_spc_core.configure\].

SPC Analyst Group
:   Users in this group have full read and write access to all the records for the product but cannot view licensing information. Granular roles for this group include \[pa_power_user and sn_sec_spc_core.analyst\].

SPC Analyst Read Only Group
:   Users in this group have full read access to all the records for the product but cannot view licensing information. Granular roles for this group include \[pa_power_user, sn_sec_spc_core.analyst_read, sn_sec_caasm.read, and
    cmdb_ms_user\].

Supporting application roles
:   The following roles are required by the applications that support SPC and Asset Security Posture Management.

    * Configuration Compliance Admin \[sn_vulc.admin\] - Configures the Configuration Compliance application, has visibility to all records, and can modify properties. Assigns roles in the Configuration Compliance application.
    * Vulnerability Response Admin \[sn_vulc.admin\] - Configures the Vulnerability Response application and the vulnerability risk calculators.
    * MID Server \[mid_server\] - Configures a MID Server.
    {#spc-workspace__ul_rsd_1nn_lcc}

## The modules of the workspace {#spc-workspace__section_crv_4dd_mzb}

To access the workspace, navigate to WorkspacesSecurity Posture Control The Home (landing page) is displayed. The Security Posture Control workspace contains the following modules.
{#spc-workspace__table_m5z_sdd_mzb__entry__2}

| Module | Description |
|-|-|
| Home | View data visualizations and other information in the Overview, Key insights, and Key use case coverage sections to help you monitor your assets. The information provided on this page permits you to report on the status of your overall security posture to IT, IT and security managers, and other key stakeholders. See [Key insights and configured insights for Security Posture Control](https://servicenow-prod.fluidtopics.net/2_4UJXYsmQ5Swivbgz3F0w "Key and configured (custom) insights provide you with visual reports that are created and updated by the assessment criteria that match your assets. Insights help you monitor security controls metrics on a dashboard.") and [Policies for Security Posture Control](https://servicenow-prod.fluidtopics.net/7BrLaYpUwbNdt6zWL4uEOg "Policies audit your assets based on data imported from your service graph connectors to help you find potential violations."). |
| Configured insights | View the data visualizations about your assets that you create, configure, and activate. See [Key insights and configured insights for Security Posture Control](https://servicenow-prod.fluidtopics.net/2_4UJXYsmQ5Swivbgz3F0w "Key and configured (custom) insights provide you with visual reports that are created and updated by the assessment criteria that match your assets. Insights help you monitor security controls metrics on a dashboard."). |
| Asset search | Quickly search for assets in your environment based on conditions you set. Verify that you can locate assets with a set of conditions before you commit those conditions to a policy. You can refine these searches so you get a preview of assets that meet your search criteria. When you are ready, you can save your conditions as a policy. See [Create an asset search in Security Posture Control](https://servicenow-prod.fluidtopics.net/dwENeAgrJKwnJTGg7dIMxw "Set your conditions and search for assets by specific service graph connector products or for assets that have specific data reported by a connector."). |
| Asset profiles | Create and define asset profiles to monitor different categories of devices with your SPC policies. Incorporate your asset profiles into your policies so you can run policies for specific types of assets. Filter the insights in the Configured Insights dashboard so they are based on your asset profiles. See [Create an asset profile in Security Posture Control](https://servicenow-prod.fluidtopics.net/vh481hNXK~ymw8ot5VKytg "Create an asset profile with conditions to group assets. You can use these asset profiles in your policies."). |
| Policies and findings | Create, clone, edit, and activate policies. There are policies that are included with the application, and you can create your own. Policies audit your assets to find matches for potential violations. Insights, visualizations, and use cases depend on policies. See [Policies for Security Posture Control](https://servicenow-prod.fluidtopics.net/7BrLaYpUwbNdt6zWL4uEOg "Policies audit your assets based on data imported from your service graph connectors to help you find potential violations."). Assets that match policy conditions are reported as Findings and are mapped to the Configuration Compliance application for remediation. See [Security Posture Control: Configuring and viewing your findings](https://servicenow-prod.fluidtopics.net/Jq72Hv5lApUN9oI_bFumzQ "You can view the findings generated by the evaluation of policies in Security Posture Control in the Security Posture Control Workspace."). |
| Connectors and use cases setup | Activate and view the status of installed service graph connectors (SGC)s and API integrations. Service Graph Connectors and API integrations are sources you use for importing data about your assets.  A wide variety of (SGC)s are supported and are available from the ServiceNow® Store. Set up and monitor key use cases. Use cases are different scenarios that you configure to help you identify specific types of tool coverage gaps. Each use case requires a policy or policies to audit your assets for potential violations. See [Use cases, policy examples, and supported service graph connectors in Security Posture Control](https://servicenow-prod.fluidtopics.net/kVeUHDr821P1Nf_NIDW~vg "Use cases are different scenarios that you configure to help you identify specific types of tool coverage gaps. Each use case requires a policy or policies to audit your assets for potential violations. You can also define your own policies to help you fulfill requirements for your specific internal security standards."). |
| Custom insight builder | Create your own data visualizations. Custom insights provide you with visual reports that are updated by the audit results of your policies and imported data. Once you activate them, your custom insights are displayed on the dashboard in the Configured insights module. You can determine where data for an insight is displayed on the dashboard by using Groups. See [Create and activate a configured insight for Security Posture Control](https://servicenow-prod.fluidtopics.net/z5xdn2ITe2Fbe1GQlCPrAg "You can create your own insights. Configured insights are insights that you can create either using existing policies or your own custom policies."). |
[Table 1. Modules]

{#spc-workspace__table_m5z_sdd_mzb}

## Using the modules of the workspace to identify gaps in tool coverage {#spc-workspace__section_pl1_2bc_ccc}

Identifying security tool gaps requires you to perform the following steps.

1. Set up and activate API connections with any of the tools that you are using in various categories. You can use Service Graph Connectors for products that are available from the ServiceNow Store for the API connections that are required. For more information about the supported service graph connectors, see [Service Graph Connectors for Security Posture Control](https://servicenow-prod.fluidtopics.net/tgxGss~woYQ4slX9~7hyLw "Security Posture Control relies on API integrations or Service Graph Connectors as a key source for the asset data used to identify security gaps.") and [Service Graph Connectors](https://www.servicenow.com/docs/access?context=cmdb-sgc-available&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US). Supported service graph connectors are available from the ServiceNow® Store with separate subscriptions.
2. Perform one or more asset searches based on specific criteria to get an inventory.
3. Activate the policies shipped with the Security Posture Control application. You can also or create your own policies and activate them based on the results of your asset searches.
4. Create and activate your own configured insights to help you monitor your assets.
5. To gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured, see [Using mitigation controls monitoring with Security Posture Control](https://servicenow-prod.fluidtopics.net/qJ0t1xSq~1LC6CAMMFTpRA "From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.").
6. Set up rules to automate the remediation workflow in the Configuration Compliance application.

{#spc-workspace__ol_h3b_3bc_ccc}

Identifying security tool gaps involves the following steps:

1. Activate the policies shipped with the Security Posture Control application. The Security Posture Control product finds security tool gaps by performing the following tasks:
   1. Identifies the list of all unique assets populated by various Service Graph Connectors in the CMDB.
   2. Identifies assets that are not reported by specific categories from this asset pool, for example, Endpoint Protection. Assets are identified based on the active policy that is being evaluated.
   3. Assets identified as not reported by specific categories are reported as 'Findings' or 'Test Results' in the Configuration Compliance application.
   {#spc-workspace__ol_cdf_3pn_lcc}
2. Automatically assign 'Findings' to different teams for remediation with the Configuration Compliance application.
{#spc-workspace__ol_utn_l2y_hyb}

## Creating your own policies {#spc-workspace__section_ufy_gnz_dcc}

See [Creating your own policies in the Security Posture Control application](https://servicenow-prod.fluidtopics.net/FwgODHWAP6I~VR7rpDXbMg "You can create your own custom policies to monitor data that is specific to the assets in your environment. You base these policies on data you will import from the various Service Graph Connectors you have installed and activated.") for more information about how to create your own policies.

See [Create and activate custom policies for Security Posture Control](https://servicenow-prod.fluidtopics.net/DHTaHFvZydVudRl7PnhfKQ "Create your own custom policies to monitor assets for tool coverage and other high-risk combinations.") for more information about the steps required to create a policy.

For example policies, see [Examples of base, child, and cloned policies for Security Posture Control](https://servicenow-prod.fluidtopics.net/3jRePf1q0A3v5nhKueUYRQ "You can create your own base policies that have broad sets of conditions that you can use as starting points for more complex policies.").

*[\>]: and then


