---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configuring the Key Management Framework

# Configuring the Key Management Framework {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.
* **[Assign Key Management Framework roles](https://www.servicenow.com/docs/_juP4mLYmvpU2VvSgMsCdw)**   
  Administrators with the security_admin role can assign Key Management Framework (KMF) admins, who in turn can assign other Key Management Framework roles.
* **[Configure field encryption settings to select key type](https://www.servicenow.com/docs/A0CIBkAzKS6fOwfAGTV04g)**   
  Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.
* **[Create a cryptographic module](https://www.servicenow.com/docs/c2M~jmt1xxwHi5RBTn8xXQ)**   
  Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.
* **[Create a module access policy](https://www.servicenow.com/docs/TDX4ZBtW4gnm2mZdPW1G_A)**   
  Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.
* **[Create a cryptographic module life-cycle policy](https://www.servicenow.com/docs/IzMt6uOqkx5ASEHgC4C3Dg)**   
  Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.

