Exploring Field Encryption
Summarize
Summary of Exploring Field Encryption
Field Encryption enhances data security by blocking all users, scripts, and processes from accessing encrypted data by default. It includes an access control feature that works alongside Access Control Lists (ACLs) to enable authorized access to encrypted data through specific configurations.
Show less
Key Features
- Access Control: Access is managed through a combination of Field Encryption Modules, Encrypted Field Configurations, and Module Access Policies (MAPs). Each MAP defines which users, scripts, or processes can access specific encrypted fields.
- Field Encryption Starter vs. Enterprise:
- Starter: Limited to 5 encrypted fields, no attachment encryption, and basic key management through ServiceNow Support.
- Enterprise: Unlimited encrypted fields, supports attachment encryption, and allows for managing keys directly within the instance.
- Key Management Framework Roles: Different roles, such as KMF Admin and KMF Operator, handle configuration, key management, and encryption processes.
- Cloning Considerations: When cloning instances, encrypted data is copied, but the target instance cannot decrypt it until a key exchange is performed, as keys are re-encrypted during the process.
Key Outcomes
By implementing Field Encryption, ServiceNow customers can ensure that sensitive data is securely stored with controlled access, reducing the risk of unauthorized data exposure. Understanding the differences between the Starter and Enterprise versions helps customers choose the right solution for their encryption needs. Proper management of encryption keys and access policies will enable businesses to maintain compliance and data integrity.
Learn the details of Field Encryption Starter and Field Encryption Enterprise
Encryption-backed access control
By default, Field Encryption blocks all users, scripts, and system processes from accessing encrypted data. However, Field Encryption has an access control feature that works in combination with Access Control Lists (ACLs). This feature is also separate from ACLs and ensures only the correct users, scripts, or system processes can access encrypted data.
You can configure the access control feature of Field Encryption through a combination of Field Encryption Modules, Encrypted Field Configurations, and Module Access Policies. The next image shows how these three components work together.
By default, encrypted data is locked down from all access. A MAP defines which accessor (users, scripts, and system processes) can be authorized to access the data.
You can configure multiple MAPs to apply different access rules to different encrypted fields. In this diagram, Module Access Policy A covers columns A, B, C, and D. Module Access Policy B covers column E. Each policy has its own rules per accessor.
Access rules can differ between two policies for each accessor type. The following table reflects the access rules defined for Module Access Policy A and Module Access Policy B. Module Access Policy A applies to columns A, B, C, and D. Module Access Policy B applies to column E.
| Accessor | MAP A Columns A, B, C, D |
MAP B Column E |
|---|---|---|
| Role A | Allow | Block |
| Role B | Allow | Block |
| Role C | Block | Allow |
| Script A | Allow | Block |
| Script B | Block | Block |
| Script C | Block | Allow |
| System Context Processes | Block | Allow |
Differences between Field Encryption Starter and Field Encryption Enterprise
The feature-set is different between Field Encryption Starter and Field Encryption Enterprise.
| Feature | Field Encryption Starter | Field Encryption Enterprise |
|---|---|---|
| Number of encrypted fields | Up to 5 encrypted fields Note: Field Encryption Starter limits the number of encrypted fields, not encryption modules or contexts. Field Encryption replaces the deprecated Column Level Encryption product, which used a module and context-based limit. |
No restriction on number of encrypted fields |
| Attachment encryption | No | Yes |
| Key management | None (Contact ServiceNow Support for key rotation) | Manage keys from your instance with no involvement from ServiceNow Support |
| Supported data types | All supported data types | All supported data types |
| Number of Field Encryption Modules | No restriction | No restriction |
| Number of Module Access Policies | No restriction | No restriction |
Field Encryption users
| User | Description |
|---|---|
| Key Management Framework (KMF)Admin or KMF Cryptographic Manager | These roles are used to configure elements of Field Encryption.
|
| KMF Cryptographic Operator | Configures properties for customer supplied keys |
Field Encryption and record history
Changes to fields encrypted with Field Encryption are not tracked in the activity stream for the record or in the record history [sys_history_set] table.
Encryption on system tables
Field Encryption currently doesn't support the encryption of fields and attachments of system tables (tables that begin with sys_).
Cloning considerations
When you clone an instance that uses Field Encryption, the encrypted field data and encryption modules are copied to the target instance. Because encryption keys are re-encrypted with a secondary key that is unique to the source instance, the target instance can't decrypt the field data after cloning.
Until a key exchange is performed, encrypted fields on the cloned instance appear empty or unreadable. This is expected behavior and does not indicate data corruption or loss.
To restore access to encrypted fields on the target instance, complete a key exchange from the source instance. See Configure Key Exchange.