<h2>Cloud Encryption with Key Management</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="concept" /><meta name="DC.title" content="Cloud Encryption with Key Management" /><meta name="abstract" content="ServiceNow Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow Platform Encryption subscription bundle." /><meta name="description" content="ServiceNow Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow Platform Encryption subscription bundle." /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-08-03" /><meta name="DC.date.modified" content="2024-08-16" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="dare-overview" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Cloud Encryption with Key Management</title></head><body id="dare-overview"> <h1 class="title topictitle1" id="ariaid-title1"><span class="ph">Cloud Encryption</span> with Key Management</h1> <div class="body conbody"><p class="shortdesc"><span class="ph">ServiceNow®</span> <span class="ph">Cloud Encryption</span> offers encrypted storage for the database using block encryption, along with enhanced key management. <span class="ph">Cloud Encryption</span> is available with the <span class="ph">ServiceNow®</span> Platform Encryption subscription bundle.</p> <div class="p"><span class="ph">Cloud Encryption</span> offers:<ul class="ul" id="dare-overview__ul_jhg_jjq_frb"><li class="li">Segregation of duties.</li><li class="li">Rotation of <span class="ph">ServiceNow</span> Managed keys.</li><li class="li">Customer-Managed keys option.<div class="note"><span class="notetitle">Note:</span> Consider this option if your organization requires you to use key material generated by your own cryptographic tools or libraries, an enterprise key management system, or a hardware security module (HSM). See <a class="xref" href="../task/key-mgmt-operations-ce.html" title="The Key Management Operations sub-module provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.">Key management operations</a> for details.</div> </li></ul> </div> <p class="p">The following diagram shows how <span class="ph">Cloud Encryption</span> works.</p> <div class="fig fignone" id="dare-overview__fig_s14_4w4_4rb"><span class="figcap"><span class="fig--title-label">Figure 1. </span>Cloud Encryption Overview</span> <img class="image" id="dare-overview__image_hwf_z5n_frb" width="800" src="../image/cloud-encryption-diagram.png" alt="Cloud Encryption overview diagram." /> </div> <div class="p">The <span class="ph">Cloud Encryption</span> Key Management module consists of the following submodules:<ul class="ul" id="dare-overview__ul_dbr_tjq_frb"><li class="li"><a class="xref" href="../task/key-mgmt-operations-ce.html" title="The Key Management Operations sub-module provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.">Key management operations</a>:<ul class="ul" id="dare-overview__ul_amd_gxq_frb"><li class="li">Access the list of keys.</li><li class="li">Perform key rotation operations.</li><li class="li">Withdraw customer-managed key.</li></ul> </li><li class="li"><a class="xref" href="../task/key-mgmt-transactions-ce.html" title="The Key Management Transactions submodule displays all transactions that have occurred for the keys in your ServiceNow instance.">Key management transactions</a>:<p class="p">Reference all transactions that have occurred for the keys that have been used.</p> <p class="p">Use your own customer-managed key for encryption.</p> </li></ul> </div> <p class="p">In certain circumstances, you may opt for a key withdrawal request when using a customer-managed key. To do so, you must license the Cloud Encryption Withdraw and Resupply optional add-on SKU and then request the key withdrawal functionality be activated by a <span class="ph">Customer Service and Support</span> team member. </p> <p class="p">The Quorum Control Policy Settings option becomes available when the withdrawal feature is activated, otherwise the module isn’t visible on the menu. This feature can be activated only when using customer-managed keys. This policy enables settings to be configured regarding quorum when the withdrawal feature is activated. For more details on this feature, see <a class="xref" href="quorum-ctrl-policy.html" title="The Quorum Control Policy specifies the minimum number of approvals required among the total number of selected approvers to reach quorum for customer managed key withdrawal.">Quorum Control Policy</a>.</p> <p class="p"><span class="ph">Cloud Encryption</span> supports production and non-production instances for MariaDB and RaptorDB databases. Cloud Encryption is supported in the <span class="ph">ServiceNow</span> Commercial Cloud, Government Customer Cloud (GCC) pod 101, and <span class="ph">ServiceNow</span> Protected Platform – Australia (SPP-AU).</p> <div class="section" id="dare-overview__section_hb4_dsl_kcc"><h2 class="title sectiontitle">Licensing and enabling <span class="ph">Cloud Encryption</span></h2> <p class="p">For information about licensing <span class="ph">Cloud Encryption</span>, see <a class="xref" href="../../encryption/reference/encryption-sku.html" title="With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.">Encryption and Key Management subscription bundle</a>.</p> <p class="p">For licensed customers with new instances, the new instance provisioning will include <span class="ph">Cloud Encryption</span>.</p> <p class="p">For licensed customers with existing instances, to request an instance be moved to <span class="ph">Cloud Encryption</span>, follow the instructions in <a class="xref" href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1117369" target="_blank" rel="noopener noreferrer">KB1117369</a>. You must have the customer admin or partner admin role to request the Service Catalog item to Enable Cloud Encryption on your instance. Enabling this feature requires a one-hour maintenance window.</p> </div> <div class="section" id="dare-overview__section_n31_sm2_w1c"><h2 class="title sectiontitle">Cloud Encryption UI</h2> <p class="p">When Cloud Encryption is enabled, the Cloud Encryption user interface (UI) is visible to the security_admin user when this user has the sn_kmf.admin role.</p> <p class="p">To access the Cloud Encryption UI by searching for <span class="ph uicontrol">Cloud Encryption Key Management</span> in the navigation bar. Navigate to the <span class="ph uicontrol">Key Management Operations</span> section to see information about encryption keys, such as details of the active key, and whether Cloud Encryption is enabled for the instance.</p> </div> </div> </body></html></div>