How to set up Cloud Encryption

Max19
Tera Contributor

Hi all,

 

I like to check if there are any documentations on how we can set up cloud encryption? Or are the steps performed by ServiceNow?

 

Many thanks in advance.

Max

3 REPLIES 3

Community Alums
Not applicable

Hi @Max19 ,

ServiceNow® Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow® Platform Encryption subscription bundle.

Cloud Encryption offers:
  • Segregation of duties.
  • Rotation of ServiceNow Managed keys.
  • Customer Managed keys option.
    Note: You may want to use this option if your organization requires you to use key material generated by your own crypto tools or libraries, enterprise key management system, or hardware security module (HSM). See Configure Customer Managed key settings for details.

The following diagram shows how Cloud Encryption works.

Cloud Encryption Overview
 
SandeepDutta_1-1673507068700.png

 

The Cloud Encryption Key Management module consists of the following submodules:

In certain circumstances, a key withdrawal request may be opted for when using Customer Managed keys. You must first request the key withdrawal functionality from Customer Service and Support and complete a legal addendum.

For information on obtaining Cloud Encryption, see Encryption and Key Management subscription bundle.

 

Key Management Operations 

 

Community Alums
Not applicable

kushal Tayade
Mega Guru

You need to first confirm you have license entitlement for cloud encryption from your account manager since there is a need to have specialized hardware. Once you purchase license entitlement, You can request Instance Cloud Encryption via now support by following these steps:

  1. Navigate to Now Support
  2. Click on the Automation Store.
  3. On the left side, click on Service Catalog, Click on Instance Management.
  4. Navigate through the pages and find Enable Cloud Encryption on your instance. Click on Request.