Exploring Cryptographic Asset Compliance
Summarize
Summary of Exploring Cryptographic Asset Compliance
Cryptographic Asset Compliance in ServiceNow provides centralized visibility and control over cryptographic assets such as certificates and cloud keys. This capability is essential for organizations to proactively assess risks related to cryptography and prepare for post-quantum cryptography (PQC) challenges posed by advances in quantum computing. By automatically discovering and inventorying cryptographic assets across cloud and on-premises environments, it enables informed risk assessments and migration planning.
Show less
Key Features
- Automated Discovery: Integrates with ServiceNow Certificate Inventory and Management, and cloud discovery tools for AWS and Azure, to automatically find and sync cryptographic assets.
- Comprehensive Inventory: Consolidates certificates, AWS KMS keys, and Azure Key Vault keys into a single inventory for easy analysis.
- Risk Assessment: Identifies vulnerabilities such as weak or quantum-vulnerable algorithms, and certificate authority trust or ownership issues, with AI-generated summaries and recommendations.
- Monitoring and Reporting: Provides dashboards to track asset health, PQC compliance status, and quantum vulnerabilities, supporting ongoing maintenance and remediation efforts.
- Role-Based Access: Defines specific user roles including Cryptographic Asset Admin for configuration, and Cryptographic Asset User for monitoring and compliance activities.
Typical Workflow
- Set Up Discovery: Configure certificate and cloud key discovery to populate the cryptographic asset inventory.
- Review Inventory: Analyze the accumulated cryptographic assets across all sources.
- Assess Risks: Evaluate risk indicators related to cryptographic strength and trustworthiness.
- Monitor and Maintain: Utilize dashboards and reports to continuously track asset health and PQC readiness.
Intended Users and Benefits
- SecOperations Engineers: Gain visibility into cryptographic assets to prioritize remediation and PQC migration efforts.
- Compliance and Governance Managers: Generate audit-ready reports to demonstrate regulatory compliance and track risk exposure.
- PKI Engineers: Manage certificate lifecycles, configure discovery sources, and monitor expiration and risk indicators to ensure operational continuity.
Practical Benefits for ServiceNow Customers
- Establishes a trusted, continuously updated inventory of cryptographic assets.
- Enables proactive identification of cryptographic vulnerabilities and PQC readiness gaps.
- Supports regulatory compliance with detailed audit reports and risk tracking.
- Facilitates coordinated remediation and migration planning across security, compliance, and PKI teams.
Next Steps
Customers can explore related topics such as post-quantum cryptography concepts, cryptographic risk indicators, and Policy as Code Engine policies to deepen their understanding and improve cryptographic asset governance.
Cryptographic Asset Compliance provides centralized visibility and control of cryptographic assets for proactive risk assessment and post-quantum cryptography (PQC) readiness.
Cryptographic Asset Compliance overview
As quantum computing advances are anticipated to threaten traditional cryptographic algorithms, organizations need comprehensive visibility into their cryptographic assets. Cryptographic Asset Compliance addresses this challenge by automatically inventorying cryptographic assets like certificates, AWS KMS keys, and Azure Key Vault keys across cloud and on-premises environments. This visibility helps you assess your PQC readiness and plan migration strategies.
Cryptographic Asset Compliance workflow
The typical workflow when implementing Cryptographic Asset Compliance includes the following activities:
- Set up discovery: Set up certificate discovery in ServiceNow Certificate Inventory and Management and cloud discovery in ServiceNow Discovery (for AWS and Azure) so cryptographic assets can be found. A scheduled job then syncs the discovered assets into Cryptographic Asset Compliance.
- Review inventory: Analyze discovered cryptographic assets in the inventory, including certificates and keys across all connected sources.
- Assess risks: Review the risk indicators identified for your assets, such as weak or quantum-vulnerable algorithms and certificate authority trust or ownership gaps. Use the AI-generated summary and recommendations to understand each asset's risk.
- Monitor and maintain: Use dashboards to track cryptographic asset health, PQC compliance status, and quantum vulnerable algorithms.
Cryptographic Asset Compliance users
| User | Description |
|---|---|
| SecOperations Engineer | Need visibility into cryptographic asset inventory to identify keys and certificates for PQC migration planning. They monitor asset health, identify vulnerable algorithms, and prioritize remediation. |
| Compliance and Governance Manager | Require audit-ready reports of cryptographic assets and quantum risk exposure to meet regulatory requirements. They generate compliance reports, track policy adherence, monitor risk indicators, and document remediation efforts. |
| PKI Engineer | Manage certificate life cycle, configure discovery sources, define risk indicators, and monitor certificate expiration. They contribute to proper cryptographic asset governance and operational continuity. |
Cryptographic Asset Compliance benefits
| Benefit | Method | Users |
|---|---|---|
| Establish a trusted, up-to-date inventory of cryptographic assets and monitor its risk and PQC readiness by configuring asset discovery and the certificate authorities your organization trusts. | Cryptographic Asset admin sn_itom_cac.admin |
|
| Monitor the health of cryptographic assets, investigate risk indicators, and track PQC readiness to support remediation and compliance planning, using read access that doesn't change configuration. | Cryptographic Asset user sn_itom_cac.user |