Configuring the discovery of cryptographic assets
Configuring the discovery of cryptographic assets involves setting up certificate and cloud discovery.
Cryptographic Asset Compliance inventories the assets that ServiceNow Certificate Inventory and Management and ServiceNow Discovery discovers rather than running discovery of cryptographic assets itself.
- Certificate discovery in Certificate Inventory and Management to catalog certificates (on-premises and URL-based). For more information, see Visibility to TLS certificates.
- Cloud discovery in Discovery to catalog keys from AWS KMS and Azure Key Vault. For more information, see Discovery for cloud environment.
After discovery is set up, a scheduled job syncs discovered assets into Cryptographic Asset Compliance periodically.
Onboarding from the Home page
The Home page includes a guided onboarding that helps you configure cloud and certificate discovery. The banner is collapsible and is displayed until the discovery of all cryptographic assets is configured.
The Certificates card indicates whether certificate discovery is configured by displaying either the Setup required or Configured states.
- Setup required: Cloud discovery is not configured for AWS KMS and Azure Key Vault.
- Partially configured: Cloud discovery is configured for either AWS KMS or Azure Key Vault.
- Configured: Cloud discovery is configured for both AWS KMS and Azure Key Vault.