Skip to content

ServiceNow lifecycle & offboarding security checks

Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.

On ServiceNow, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the ServiceNow connector needs.

Checks (4)

severity: low Incident Auto-Assignment Disabled fix difficulty: easy #

Enable incident auto-assignment to ensure incidents are routed to the appropriate team automatically

  1. Navigate to System Properties > Incident
  2. Locate the property "glide.ui.autoassign"
  3. Change the value to "true"
  4. Save the property
  5. Verify that new incidents are automatically assigned based on assignment rules

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: high Change Approval Not Required fix difficulty: medium #

Enable change approval requirements to ensure all changes are authorized before implementation

  1. Navigate to Change > Administration > Change Properties
  2. Locate the property "com.snc.change_management.approval.required"
  3. Change the value to "true"
  4. Save the property
  5. Define approval workflows for normal and emergency change types
  6. Test the approval process end-to-end with a sample change request

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium Change Risk Assessment Disabled fix difficulty: medium #

Enable change risk assessment to ensure all changes are evaluated for risk before approval

  1. Navigate to Change > Administration > Change Properties
  2. Locate the property "change.risk.assessment_required"
  3. Change the value to "true"
  4. Save the property
  5. Configure risk assessment questions and scoring thresholds
  6. Test risk assessment with a sample change request

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-17.2

severity: medium CMDB Stale Records fix difficulty: hard #

Reduce the percentage of stale CMDB CI records by running discovery or updating records manually

  1. Navigate to Configuration > CI Class Manager
  2. Identify the CI classes with the highest number of stale records
  3. Schedule or run Discovery to automatically update CI attributes
  4. For manually managed CIs, bulk-update records with current information
  5. Consider setting up automated health checks or aging policies
  6. Target less than 10% stale CIs across all classes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.3 DORA (SaaS Security) DORA-8.1

More ServiceNow checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial