<h2>Cloud Security Customer Resources</h2><br/><div style="overflow-x:auto"><div style="font-family: Arial, Helvetica, sans-serif; align-items: stretch; flex-wrap: nowrap; width: 90%; background-color: #032d42; height: auto; min-height: 80px; padding: 10px 0px 10px 0px;"> <div style="font-family: Arial, Helvetica, sans-serif; color: #ffffff; margin-left: 10px; min-height: auto; flex-grow: 1; flex-basis: 100%; position: relative; left: 10%; padding: 10px 10px 10px 0; background-repeat: no-repeat;"><img style="margin-left: 10px;" title="Customer Security and Trust" src="/sys_attachment.do?sys_id=6330ec83935c6ed0d9743f986cba10ae" alt="CST Logo" width="148" height="66" /> <h2 style="font-family: Arial, Helvetica, sans-serif; color: white; font-size: 2.2em; line-height: 1.4em;">Cloud Security Customer Resources</h2> <h4 style="font-family: Arial, Helvetica, sans-serif; color: white; font-size: 1.4em; font-weight: normal; line-height: 1.2em; width: 75%;">This KB article provides links to important cloud security resources for ServiceNow customers. We recommend that you bookmark this page for future reference as it is regularly updated. </h4> </div> </div> <table style="font-family: Arial, Helvetica, sans-serif; width: 90%; border-collapse: collapse; border: none; height: auto;" title="Cloud Security Customer Resources" border="1" summary="" cellspacing="0" cellpadding="0"><tbody><tr style="font-family: Arial, Helvetica, sans-serif; font-size: 1.4em; height: 2em; color: #fff; background: #032D42; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px;" width="30%"><strong>Resource Name</strong></td><td style="padding: 10px 10px 10px 10px;"><strong>Description</strong></td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" title="Security Contact" href="/kb?id=kb_article_view&sysparm_article=KB0547262" target="_blank" rel="noopener noreferrer"><img style="display: block; margin-left: auto; margin-right: auto;" title="Security Contact" src="/sys_attachment.do?sys_id=4f30ec83935c6ed0d9743f986cba102a" alt="Security Contact" width="64" height="64" /><br />Named Security Contact</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">The ServiceNow Security Office (SSO)'s primary contact with a company is the <strong>named security contact(s)</strong> specified by the customer.</p> <p style="font-size: 1.2em;">Named security contacts must be authorized to deal with potentially sensitive security matters and must be contactable at all times. ServiceNow strongly advises that customers include both an email distribution list and an individual to fulfill this requirement.</p> <p style="font-size: 1.2em;">Therefore, the named security contact(s) must always be kept up-to-date.</p> <p style="font-size: 1.2em;"><a title="Instructions for updating the named security contact" href="/kb?id=kb_article_view&sysparm_article=KB0547262" target="_blank" rel="noopener noreferrer">Instructions for updating the named security contact</a>.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline; color: #808080;" title="Shared Responsibility Model" href="https://www.servicenow.com/standard/resource-center/white-paper/wp-shared-responsibility-model.html" target="_blank" rel="noopener noreferrer"><img style="display: block; margin-left: auto; margin-right: auto;" title="Shared Responsibility Model" src="/sys_attachment.do?sys_id=f230ac83935c6ed0d9743f986cba10ac" alt="Shared Responsibility Model icon" width="64" height="64" /><br />Shared Responsibility Model</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">Security is a partnership between ServiceNow and the customer, both with specific responsibilities. This document outlines those responsibilities and provides links to guidance on implementing security features and controls.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline; color: #808080;" title="Security Best Practices Guide" href="https://www.servicenow.com/standard/success/playbook/instance-security-best-practice.html" target="_blank" rel="noopener noreferrer"><img style="padding-right: 10 px;" title="Security Best Practices Guide" src="/sys_attachment.do?sys_id=2f30ec83935c6ed0d9743f986cba1083" alt="Security Best Practices Guide icon" width="64" height="64" /><br />Security Best Practices Guide<br /></a><a style="font-family: Arial, Helvetica, sans-serif; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline; color: #808080;" title="Security Best Practices Video" href="https://servicenowsecurity.gallery.video/detail/videos/security-best-practices/video/6353891094112/security-is-a-journey-not-a-destination-full-webinar" target="_blank" rel="noopener noreferrer">Security Best Practices Video</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">The <a title="ServiceNow Security Best Practices Guide" href="https://www.servicenow.com/standard/success/playbook/instance-security-best-practice.html" target="_blank" rel="noopener noreferrer">ServiceNow Security Best Practices Guide</a> provides guidance on key considerations customers should address when securing their Now Platform instance under the Shared Responsibility Model.</p> <p style="font-size: 1.2em;">The <a style="text-decoration: underline; color: #808080;" title="Security Best Practices Video" href="https://servicenowsecurity.gallery.video/detail/videos/security-best-practices/video/6353891094112/security-is-a-journey-not-a-destination-full-webinar" target="_blank" rel="noopener noreferrer">Security Best Practices Video</a> (Security is a Journey, Not a Destination) provides an introduction to how to secure a Now Platform instance to help build the right security framework.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" title="Security White Papers and How-to Guides" href="/kb_view.do?sysparm_article=KB0756571" target="_blank" rel="noopener noreferrer"> <img style="padding-right: 10 px;" title="Security White Papers and How to Guides" src="/sys_attachment.do?sys_id=e66b28cb93dc6ed0d9743f986cba1052" alt="Security White Papers and How to Guides" width="64" height="64" /><br />Cloud Security White Papers, Guides, and Knowledge Articles</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;"><a title="Cloud Security White Papers, Guides, and Knowledge Articles" href="http://support.servicenow.com/kb_view.do?sysparm_article=KB0756571" target="_blank" rel="noopener noreferrer">This page</a> provides white papers, knowledge articles, guides, and other resources related to the security and privacy of customer data and the Now Platform.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline; color: #808080;" href="https://servicenowsecurity.gallery.video/" target="_blank" rel="noopener noreferrer"><img style="padding-right: 10 px;" title="ServiceNow Security Videos" src="/sys_attachment.do?sys_id=5330ec83935c6ed0d9743f986cba1066" alt="Videos on Demand icon" width="64" height="64" /><br />ServiceNow Security Videos</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">The <a title="ServiceNow Security Videos" href="https://servicenowsecurity.gallery.video/" target="_blank" rel="noopener noreferrer">ServiceNow Security Videos</a> page provides a collection of informational videos spanning a broad range of topics including: Security Overview, Security Use Cases, ServiceNow Security Center, Security Products, Compliance, and Security Best Practices.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" title="ServiceNow Trust Site" href="https://www.servicenow.com/company/trust.html" target="_blank" rel="noopener noreferrer"> <img style="padding-right: 10 px;" title="ServiceNow Trust Site" src="/sys_attachment.do?sys_id=9b30ec83935c6ed0d9743f986cba1063" alt="ServiceNow Trust Site" width="64" height="64" /><br />ServiceNow Trust Site</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">Visit the <a title="ServiceNow Trust site" href="https://www.servicenow.com/company/trust.html" target="_blank" rel="noopener noreferrer">ServiceNow Trust site</a> to learn more about our commitment to <a title="compliance" href="https://www.servicenow.com/company/trust/compliance.html" target="_blank" rel="noopener noreferrer">compliance</a>, <a title="security" href="https://www.servicenow.com/company/trust/security.html" target="_blank" rel="noopener noreferrer">security</a>, and <a title="privacy" href="https://www.servicenow.com/company/trust/privacy.html" target="_blank" rel="noopener noreferrer">privacy</a>. The Trust site also provides information on industry solutions for regulated markets including <a title="GDPR" href="https://www.servicenow.com/company/trust/gdpr.html" target="_blank" rel="noopener noreferrer">GDPR</a> and with other resources.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" title="Security Knowledge Base" href="/kb?id=kb_browse&kb_knowledge_base=7c8751eadbd95d9055b5e14c13961967" target="_blank" rel="noopener noreferrer"> <img style="padding-right: 10 px;" title="Security Knowledge Base" src="/sys_attachment.do?sys_id=8b30ec83935c6ed0d9743f986cba100a" alt="Security Knowledge Base" width="64" height="64" /><br />Security Knowledge Base</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">The <a title="ServiceNow Security Knowledge Base" href="/kb?id=kb_browse&kb_knowledge_base=7c8751eadbd95d9055b5e14c13961967" target="_blank" rel="noopener noreferrer">ServiceNow Security Knowledge Base</a> includes articles on customer penetration testing, security advisories, Global Security Support Center (GSSC), Common Vulnerabilities and Exposures (CVE), security compliance, and other security-related resources.<br /><br /><em>*Please ensure that you are signed in to see all available articles. </em></p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" href="/kb?id=kb_article_view&sysparm_article=KB0959484" target="_blank" rel="noopener noreferrer"><img style="padding-right: 10 px;" title="ServiceNow CORE Compliance Portal" src="/sys_attachment.do?sys_id=f9cb644f93dc6ed0d9743f986cba10e7" alt="ServiceNow CORE Compliance Portal" width="64" height="64" /><br />ServiceNow CORE Compliance Portal</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">The CORE Compliance Portal enables ServiceNow customers to quickly find documentation they need to help address their internal audit and vendor assessment requirements related to features of the Now Platform.</p> <p style="font-size: 1.2em;"><a title="CORE Compliance Overview video" href="https://servicenowsecurity.gallery.video/detail/videos/compliance/video/6350208237112/the-core-compliance-portal" target="_blank" rel="noopener noreferrer">CORE Compliance Overview video</a> </p> <p style="font-size: 1.2em;">Find out how to access the CORE Compliance Portal <a title="Request access to CORE Compliance Portal" href="/kb?id=kb_article_view&sysparm_article=KB0564067" target="_blank" rel="noopener noreferrer">here</a>.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" title="ServiceNow Security Advisories" href="/kb?id=kb_article_view&sysparm_article=KB0870307" target="_blank" rel="noopener noreferrer"> <img title="ServiceNow Security Advisories" src="/sys_attachment.do?sys_id=0730ec83935c6ed0d9743f986cba102d" alt="ServiceNow Security Advisories" width="64" height="64" /><br />ServiceNow Security Advisories</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">The <a title="ServiceNow Security Advisories page" href="/kb?id=kb_article_view&sysparm_article=KB0870307" target="_blank" rel="noopener noreferrer">ServiceNow Security Advisories page</a> allows customers to learn more about the ServiceNow security posture related to specific security events and CVEs (Common Vulnerabilities and Exposures).</p> <p style="font-size: 1.2em;">These advisories are limited to the scope of the Now Platform and supporting ServiceNow cloud environments.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline;" title="Penetration Testing" href="/kb?id=kb_article_view&sysparm_article=KB1119943" target="_blank" rel="noopener noreferrer"> <img style="padding-right: 10 px;" title="Penetration Testing" src="/sys_attachment.do?sys_id=cf30ac83935c6ed0d9743f986cba10c9" alt="Penetration Testing" width="64" height="64" /><br />How to Request a Penetration Test</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">Customers are permitted to perform one penetration test per calendar year on their own Now Platform instances.</p> <p style="font-size: 1.2em;">Testing scheduling must be pre-approved and conducted at a date and time agreed upon by ServiceNow and the customer. Pre-approval is necessary for ServiceNow to continue monitoring activities and to differentiate potential attacks from authorized customer testing.</p> <p style="font-size: 1.2em;">As a condition of testing, customers are required to share the validated steps to reproduce any finding with ServiceNow in accordance with the <a title="Customer Penetration Testing Process Overview" href="/kb?id=kb_article_view&sysparm_article=KB1119943" target="_blank" rel="noopener noreferrer">documented process</a>.</p> </td></tr><tr style="height: 1.4em; color: #333; border: 1pt solid #a3a3a3;"><td style="padding: 10px 10px 10px 10px; text-align: center;"><a style="font-family: Arial, Helvetica, sans-serif; color: #808080; font-size: 1.4em; line-height: 1.6em; font-weight: bold; text-decoration: underline; padding-right: 10px; padding-left: 10px;" title="Reporting Security Incidents, Concerns, and Findings" href="/kb?id=kb_article_view&sysparm_article=KB1048209" target="_blank" rel="noopener noreferrer"><img title="Reporting Security Incidents, Concerns, and Findings" src="/sys_attachment.do?sys_id=0f30ec83935c6ed0d9743f986cba1005" alt="Reporting Security Incidents, Concerns, and Findings" width="64" height="64" /><br />Reporting Security Incidents, Concerns, and Findings</a></td><td style="padding: 10px 10px 10px 10px;"> <p style="font-size: 1.2em;">Customer security incidents, concerns, and findings are reported via Now Support. Please follow the instructions found in the article <a title="Instructions for customers to report security incidents, concerns, and findings" href="/kb?id=kb_article_view&sysparm_article=KB1048209" target="_blank" rel="noopener noreferrer">here</a>.</p> </td></tr></tbody></table></div>