Cloud Encryption with Key Management
Summarize
Summary of Cloud Encryption with Key Management
ServiceNow® Cloud Encryption provides encrypted database storage through block encryption and improved key management. This feature is part of the ServiceNow® Platform Encryption subscription bundle, enabling organizations to secure their data effectively.
Show less
Key Features
- Segregation of Duties: Ensures distinct roles in key management operations.
- Key Rotation: Automated rotation of ServiceNow managed keys.
- Customer-Managed Keys: Allows organizations to utilize keys generated by their own cryptographic tools or systems, such as HSMs.
- Key Management Operations: Access key lists, perform key rotations, and manage customer keys.
- Key Management Transactions: Track all key-related transactions.
- Quorum Control Policy Settings: Configurable settings when the key withdrawal feature is activated.
Key Outcomes
Upon enabling Cloud Encryption, customers can expect:
- Enhanced security for both production and non-production instances of MariaDB and RaptorDB databases.
- Visibility of the Cloud Encryption UI for users with the snkmf.admin role.
- Access to detailed information about encryption keys, including active key status and Cloud Encryption status on instances.
To enable Cloud Encryption, licensed customers must follow specific procedures, including requesting an instance move and scheduling a maintenance window.
ServiceNow® Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow® Platform Encryption subscription bundle.
- Segregation of duties.
- Rotation of ServiceNow Managed keys.
- Customer-Managed keys option.Note:Consider this option if your organization requires you to use key material generated by your own cryptographic tools or libraries, an enterprise key management system, or a hardware security module (HSM). See Key management operations for details.
The following diagram shows how Cloud Encryption works.
- Key management operations:
- Access the list of keys.
- Perform key rotation operations.
- Withdraw customer-managed key.
- Key management transactions:
Reference all transactions that have occurred for the keys that have been used.
Use your own customer-managed key for encryption.
In certain circumstances, you may opt for a key withdrawal request when using a customer-managed key. To do so, you must license the Cloud Encryption Withdraw and Resupply optional add-on SKU and then request the key withdrawal functionality be activated by a Customer Service and Support team member.
The Quorum Control Policy Settings option becomes available when the withdrawal feature is activated, otherwise the module isn’t visible on the menu. This feature can be activated only when using customer-managed keys. This policy enables settings to be configured regarding quorum when the withdrawal feature is activated. For more details on this feature, see Quorum Control Policy.
Cloud Encryption supports production and non-production instances for MariaDB and RaptorDB databases. Cloud Encryption is supported in the ServiceNow Commercial Cloud, Government Customer Cloud (GCC) pod 101, and ServiceNow Protected Platform – Australia (SPP-AU).
Licensing and enabling Cloud Encryption
For information about licensing Cloud Encryption, see Encryption and Key Management subscription bundle.
For licensed customers with new instances, the new instance provisioning will include Cloud Encryption.
For licensed customers with existing instances, to request an instance be moved to Cloud Encryption, follow the instructions in KB1117369. You must have the customer admin or partner admin role to request the Service Catalog item to Enable Cloud Encryption on your instance. Enabling this feature requires a one-hour maintenance window.
Cloud Encryption UI
When Cloud Encryption is enabled, the Cloud Encryption user interface (UI) is visible to the security_admin user when this user has the sn_kmf.admin role.
To access the Cloud Encryption UI by searching for Cloud Encryption Key Management in the navigation bar. Navigate to the Key Management Operations section to see information about encryption keys, such as details of the active key, and whether Cloud Encryption is enabled for the instance.