Create Encrypted Field Configurations
Configure specific fields to be encrypted using your External Key Management Service (EKMS) cryptographic module with external Amazon Web Services Key Management System (AWS KMS) key wrapping.
Before you begin
Roles required: admin, security_admin, and sn_kmf.cryptographic_manager
Confirm that you have created a cryptographic module with external key wrapping enabled. See Configure an external key definition.
About this task
An Encrypted Field Configuration (EFC) connects a specific table column to your EKMS cryptographic module. EFC creates a secure encryption chain where your data can only be decrypted if both the ServiceNow data encryption key (DEK) and your external AWS key are available.
Procedure
Result
The field's data established by the EFC are encrypted using the Data Encryption Key (DEK) that is wrapped by your AWS KMS key.