The Sarbanes-Oxley (SOX) Content Pack provides predefined GRC content to help organizations work toward SOX compliance. The content pack includes scope, policies, controls, risks, audit tasks, test plans, dashboards, and reports.
Users with the Compliance Admin (sn.compliance.admin), Risk Admin (sn.risk.admin), or Audit Admin (sn.audit.admin) role can edit the content to meet their organization's SOX requirements. The SOX Content Pack covers the three ServiceNow® GRC core applications, namely Policy and Compliance Management, Risk Management, and Audit Management, and establishes relationships across content elements in those applications.
New
Query range ACLs include the following enhancements:
- Consistent access control — All tables include standardized query range security ACLs. These ACLs ensure that authenticated users with appropriate read permissions can query records consistently across the platform.
- Seamless upgrade experience — New query ACL rules are installed automatically during upgrade, with no administrator action required. Automated upgrade scripts handle the transition, including detecting and processing previously customized ACLs to ensure existing processes continue without interruption.
Post-upgrade review for customized ACLs:
- If the instance includes administrator-modified query range ACLs, review those records after upgrade to confirm they align with the intended access policy.
Changed
- Validated plugin dependencies to prevent ACLs from referencing roles provided by uninstalled optional plugins.
One of the following plugins for GRC must be installed and active:
- GRC: Policy and Compliance Management (com.sn_compliance)
- GRC: Audit Management (com.sn_audit)
- GRC: Risk Management (com.sn_risk)
- Integrated Risk Management Standard
Permissions and roles:
- Role required to install the app: System Administrator (admin)