---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configuring the Key Management Framework

# Configuring the Key Management Framework {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.
* **[Assign Key Management Framework roles](https://www.servicenow.com/docs/cyRItYcrojvdU8lcIm0K~Q)**   
  Administrators with the security_admin role can assign Key Management Framework (KMF) admins, who in turn can assign other Key Management Framework roles.
* **[Configure field encryption settings to select key type](https://www.servicenow.com/docs/PDMdIXIdW~P7evneJD5avg)**   
  Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.
* **[Create a cryptographic module](https://www.servicenow.com/docs/6rOuBvdNPe_QPA9uZx5mIw)**   
  Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.
* **[Create a module access policy](https://www.servicenow.com/docs/n0d4HWjdevBX5MxIwBYKfQ)**   
  Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.
* **[Create a cryptographic module life-cycle policy](https://www.servicenow.com/docs/h3KnMUQZtCDkNyLnuYmwYw)**   
  Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.

