logo

NJP

Asset Security Posture Management

Asset Security Posture Management

by Service-now.com

Get visibility into and automate remediation workflow for security tool coverage gaps and combinations with vulnerabilities in enterprise assets.

0 installs 0 reviews v5.5.2 Scoped Application Free-ish (consumes 9 tables) 9 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 9 -9
244 days of no change
2025-08-25 8 +1
13 days of no change
2025-08-11 7 +1
69 days of no change
2025-06-02 6 +1
82 days of no change
2025-03-11 5 +1
43 days of no change
2025-01-26 4 +1

About

This application provides you with visibility into your enterprise asset inventory and security tool coverage. Use policies provided with the product to identify assets missing key security tools, such as endpoint protection, configuration management, and vulnerability scanning. These policies also identify assets with critical combinations such as missing security tools, vulnerabilities, and internet exposure. Cybersecurity teams can copy existing policies to create their own so they can monitor assets for security tool configurations that are specific to their environments and automate the remediation workflow for identified security gaps.

Key Features

- Visibility into assets with missing critical security tool coverage, such as endpoint protection and vulnerability assessment.
- Visibility into high-risk combinations that include security tool coverage issues, vulnerabilities, and internet exposure. Note: Currently, only Amazon Web Services (AWS) assets are supported for internet exposure analysis.
- Connect seamlessly with various security and IT tools. Generate insights on the security hygiene and posture of your assets with supported API-based integrations for service graph connectors.
- Use data that has been imported into Vulnerability Response to identify assets with critical and high-risk combinations.
- Create custom policies and insights to monitor assets for their compliance with desired security tool configuration. Identify assets that have critical combinations of missing security tools, vulnerabilities, and internet exposure.

With advanced policy features:

- Create new policies that inherit the conditions of other policies.
- Exclude assets that match existing policies or that are associated with approved exceptions in the Integrated Risk Management (IRM) product.
- Perform an instant search for assets based on:
-
- Connectors and tools that reported these assets in the CMDB.
- Metadata reported by different tools. For example, with agent-version and core asset data from the CMDB, search for operating system and host-name.
- Converting your searches into a policy for continuous monitoring. 

- View complete metadata reported by various connectors or tools for any given asset identified by search queries or policies in the Security Posture Control product.
- Create custom insights to visualize the overall security hygiene and posture of your enterprise assets.
- Control the prioritization of vulnerable items in Vulnerability Response with insights from Security Posture Control. For example, increase the risk score for vulnerable items identified on assets with missing endpoint protection.

 

Version History (6)
v5.5.2 2026-06-16 16:46:52
The following enhancements and changes support internal security directives. Enhancements to the Asset Security Posture Management (CAASM) tables ...
v5.5.1 2025-12-11 14:52:45
New The Service Graph Connector for XM Cyber (XM Cyber SGC) is supported in Security Posture Control.
v5.3.5 2025-07-31 15:39:17
Fixed: Asset profile-based filtering in custom insights.
v5.3.4 2025-05-01 18:58:36
New: Supporting changes for Amazon Web Services (AWS) Web Application Firewall (WAF) as a mitigation controls source. Supporting changes for the a...
v5.3.2 2025-01-30 16:08:55
Fixed: Retired assets are filtered out from key insights. The logic for use cases on the Connectors and Dashboard pages. Conditions for policies t...
v5.1.2 2024-12-05 15:48:33
Fixed: The "With IRM Exception" connection in policy builder now renders the properties properly.
ID: be9f34e2d3eea110f0909b3392fad296 · Published: Jun 2026 · Updated: Sep 09, 2026