Exploring Cryptographic Asset Compliance

  • Release version: Australia
  • Updated December 19, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Exploring Cryptographic Asset Compliance

    Cryptographic Asset Compliance in ServiceNow provides centralized visibility and control over cryptographic assets such as certificates and cloud keys. This capability is essential for organizations to proactively assess risks related to cryptography and prepare for post-quantum cryptography (PQC) challenges posed by advances in quantum computing. By automatically discovering and inventorying cryptographic assets across cloud and on-premises environments, it enables informed risk assessments and migration planning.

    Show full answer Show less

    Key Features

    • Automated Discovery: Integrates with ServiceNow Certificate Inventory and Management, and cloud discovery tools for AWS and Azure, to automatically find and sync cryptographic assets.
    • Comprehensive Inventory: Consolidates certificates, AWS KMS keys, and Azure Key Vault keys into a single inventory for easy analysis.
    • Risk Assessment: Identifies vulnerabilities such as weak or quantum-vulnerable algorithms, and certificate authority trust or ownership issues, with AI-generated summaries and recommendations.
    • Monitoring and Reporting: Provides dashboards to track asset health, PQC compliance status, and quantum vulnerabilities, supporting ongoing maintenance and remediation efforts.
    • Role-Based Access: Defines specific user roles including Cryptographic Asset Admin for configuration, and Cryptographic Asset User for monitoring and compliance activities.

    Typical Workflow

    • Set Up Discovery: Configure certificate and cloud key discovery to populate the cryptographic asset inventory.
    • Review Inventory: Analyze the accumulated cryptographic assets across all sources.
    • Assess Risks: Evaluate risk indicators related to cryptographic strength and trustworthiness.
    • Monitor and Maintain: Utilize dashboards and reports to continuously track asset health and PQC readiness.

    Intended Users and Benefits

    • SecOperations Engineers: Gain visibility into cryptographic assets to prioritize remediation and PQC migration efforts.
    • Compliance and Governance Managers: Generate audit-ready reports to demonstrate regulatory compliance and track risk exposure.
    • PKI Engineers: Manage certificate lifecycles, configure discovery sources, and monitor expiration and risk indicators to ensure operational continuity.

    Practical Benefits for ServiceNow Customers

    • Establishes a trusted, continuously updated inventory of cryptographic assets.
    • Enables proactive identification of cryptographic vulnerabilities and PQC readiness gaps.
    • Supports regulatory compliance with detailed audit reports and risk tracking.
    • Facilitates coordinated remediation and migration planning across security, compliance, and PKI teams.

    Next Steps

    Customers can explore related topics such as post-quantum cryptography concepts, cryptographic risk indicators, and Policy as Code Engine policies to deepen their understanding and improve cryptographic asset governance.

    Cryptographic Asset Compliance provides centralized visibility and control of cryptographic assets for proactive risk assessment and post-quantum cryptography (PQC) readiness.

    Cryptographic Asset Compliance overview

    As quantum computing advances are anticipated to threaten traditional cryptographic algorithms, organizations need comprehensive visibility into their cryptographic assets. Cryptographic Asset Compliance addresses this challenge by automatically inventorying cryptographic assets like certificates, AWS KMS keys, and Azure Key Vault keys across cloud and on-premises environments. This visibility helps you assess your PQC readiness and plan migration strategies.

    Cryptographic Asset Compliance workflow

    The typical workflow when implementing Cryptographic Asset Compliance includes the following activities:

    1. Set up discovery: Set up certificate discovery in ServiceNow Certificate Inventory and Management and cloud discovery in ServiceNow Discovery (for AWS and Azure) so cryptographic assets can be found. A scheduled job then syncs the discovered assets into Cryptographic Asset Compliance.
    2. Review inventory: Analyze discovered cryptographic assets in the inventory, including certificates and keys across all connected sources.
    3. Assess risks: Review the risk indicators identified for your assets, such as weak or quantum-vulnerable algorithms and certificate authority trust or ownership gaps. Use the AI-generated summary and recommendations to understand each asset's risk.
    4. Monitor and maintain: Use dashboards to track cryptographic asset health, PQC compliance status, and quantum vulnerable algorithms.

    Cryptographic Asset Compliance users

    User Description
    SecOperations Engineer Need visibility into cryptographic asset inventory to identify keys and certificates for PQC migration planning. They monitor asset health, identify vulnerable algorithms, and prioritize remediation.
    Compliance and Governance Manager Require audit-ready reports of cryptographic assets and quantum risk exposure to meet regulatory requirements. They generate compliance reports, track policy adherence, monitor risk indicators, and document remediation efforts.
    PKI Engineer Manage certificate life cycle, configure discovery sources, define risk indicators, and monitor certificate expiration. They contribute to proper cryptographic asset governance and operational continuity.

    Cryptographic Asset Compliance benefits

    Benefit Method Users
    Establish a trusted, up-to-date inventory of cryptographic assets and monitor its risk and PQC readiness by configuring asset discovery and the certificate authorities your organization trusts. Cryptographic Asset admin

    sn_itom_cac.admin

    Monitor the health of cryptographic assets, investigate risk indicators, and track PQC readiness to support remediation and compliance planning, using read access that doesn't change configuration. Cryptographic Asset user

    sn_itom_cac.user