---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configuring External Key Management Service

# Configuring External Key Management Service {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Set up External Key Management Service (EKMS) to encrypt ServiceNow data using your Amazon Web Service Key Management System (AWS KMS) keys.

## Configuration Overview {#configuring-external-key-management__section_pyf_dbm_k3c}

Configuring External Key Management Service (EKMS) involves installing the plugin, connecting to AWS KMS, and setting up encryption for specific fields. Complete these tasks to establish external key management for your ServiceNow data.

## Configuration Workflow {#configuring-external-key-management__section_zlj_22m_k3c}

1. Activate the EKMS plugin and assign required user roles
2. Configure the AWS KMS key definition with connection credentials
3. Create cryptographic modules that use external key wrapping
4. Specify which table fields should be encrypted
5. Set up access policies to control data visibility
6. Test encryption and access control to verify the configuration

## Prerequisites

Before configuring EKMS, verify that you have:

* AWS KMS access through your organization's request process
* Created or identified an AWS KMS key
* Identity and Access Management (IAM) user credentials with KMS permissions
* IAM user configured with at least these permissions: kms:DescribeKey, kms:Encrypt, and kms:Decrypt
* Admin, Security Admin, and Crypto Manager roles in ServiceNow
* **[Activate External Key Management Service](https://servicenow-prod.fluidtopics.net/AqWBOuoYCxt08eZyLfOqRQ)**   
  Install the External Key Management Service (EKMS) plugin and configure user permissions to enable external key management functionality.
* **[Configure an external key definition](https://servicenow-prod.fluidtopics.net/ljQ3vNp3pALVUrun2sAIIw)**   
  Configure your external encryption key to use in External Key Management Service (EKMS).
* **[Create a cryptographic module with external key wrapping](https://servicenow-prod.fluidtopics.net/721K8IKp~YSc5rn8w7iqDw)**   
  Create a cryptographic module that uses external Amazon Web Services Key Management System (AWS KMS) key wrapping to encrypt ServiceNow data.
* **[Create Encrypted Field Configurations](https://servicenow-prod.fluidtopics.net/bXF45FU2G8xLBqmkMqrRyQ)**   
  Configure specific table fields to be encrypted using your External Key Management Service (EKMS) cryptographic module with external Amazon Web Services Key Management System (AWS KMS) key wrapping.
* **[Set up Module Access Policies](https://servicenow-prod.fluidtopics.net/nBRMQAtk04wAF4Jhfpr2uw)**   
  Define which user roles can view encrypted data in clear text by configuring module access policies for External Key Management Service (EKMS).
* **[Test an external key definition](https://servicenow-prod.fluidtopics.net/F6NOlVR3x7kGZrGmUHku~Q)**   
  Test your external encryption key to use in External Key Management Service (EKMS).

**Zugehörige Konzepte**   

* [External Key Management Service](https://servicenow-prod.fluidtopics.net/GROM6j6kSkoH7I54uwdD7g "External Key Management Service (EKMS) enables you to integrate Field Encryption with your own external key management systems.")  
**Zugehörige Tasks**   

* [Activate External Key Management Service](https://servicenow-prod.fluidtopics.net/AqWBOuoYCxt08eZyLfOqRQ "Install the External Key Management Service (EKMS) plugin and configure user permissions to enable external key management functionality.")
* [Configure an external key definition](https://servicenow-prod.fluidtopics.net/ljQ3vNp3pALVUrun2sAIIw "Configure your external encryption key to use in External Key Management Service (EKMS).")
* [Create a cryptographic module with external key wrapping](https://servicenow-prod.fluidtopics.net/721K8IKp~YSc5rn8w7iqDw "Create a cryptographic module that uses external Amazon Web Services Key Management System (AWS KMS) key wrapping to encrypt ServiceNow data.")
* [Create Encrypted Field Configurations](https://servicenow-prod.fluidtopics.net/bXF45FU2G8xLBqmkMqrRyQ "Configure specific table fields to be encrypted using your External Key Management Service (EKMS) cryptographic module with external Amazon Web Services Key Management System (AWS KMS) key wrapping.")

