---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Key Management Framework

# Key Management Framework {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.
Key Management refers to the activities involved in handling your cryptographic keys and related security parameters during the key's life cycle. Key Management Framework is based on [National Institute of Standards and Technology (NIST) 800-57](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf) guidelines. In accordance with these guidelines, you can use KMF to:

* Assign dedicated roles for cryptographic management and operations, auditing, and integration.
* Create cryptographic modules to configure of cryptographic specifications for unique cryptographic purposes and key types.
  * Symmetric key: encryption and decryption, key wrapping and unwrapping, and authentication
  * Asymmetric key: digital signature generation and verification, encryption and decryption, key wrapping and unwrapping
  {#encryption__ul_dgq_ptc_snb}
* Manage your key life cycle to generate, rotate, revoke, and suspend keys, including support of several key life cycle states
* Create module access policies (MAPs) to enforce access controls, to grant access only to users and scripts that you choose.
* Protect your cryptographic keys with the Federal Information Processing Standard (FIPS) 140-2-L3 hardware Root of Trust (RoT), Public Key Infrastructure (PKI), key hierarchy, and envelope encryption.
* Assign the auditing role to users to can then view auditing information such as key usage statistics.
{#encryption__ul_uyg_53v_kmb}

## Get started {#encryption__section_ucy_yrq_dsb}

|-|-|-|
| [Exploring the Key Management Framework](https://servicenow-prod.fluidtopics.net/2_x4ht_V5js14q8h1AWqBA "Learn about the components of the Key Management Framework (KMF), and how to use them to manage how cryptographic operations are performed on your instance.") [Learn about the components of the Key Management Framework, and how to use them to manage how cryptographic operations are performed on your instance.](https://servicenow-prod.fluidtopics.net/2_x4ht_V5js14q8h1AWqBA "Learn about the components of the Key Management Framework (KMF), and how to use them to manage how cryptographic operations are performed on your instance.") | [Configuring the Key Management Framework](https://servicenow-prod.fluidtopics.net/40e2dCXudjmYbSCNDH4tog "Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.") [Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.](https://servicenow-prod.fluidtopics.net/40e2dCXudjmYbSCNDH4tog "Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.") | [Key Management Framework Reference](https://servicenow-prod.fluidtopics.net/2OdvTPyfD~by6u_S5Urmrg "The Key Management Framework (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your ServiceNow instance. The ServiceNow Key Management Framework provides a secure and comprehensive interface for instance-side cryptographic key management services.") [Review additional Key Management reference materials](https://servicenow-prod.fluidtopics.net/2OdvTPyfD~by6u_S5Urmrg "The Key Management Framework (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your ServiceNow instance. The ServiceNow Key Management Framework provides a secure and comprehensive interface for instance-side cryptographic key management services.") |
|   | [Key Management Framework actions](https://servicenow-prod.fluidtopics.net/NGmgWoxP2Pw2QP6mkUZUOQ "One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.") [One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.](https://servicenow-prod.fluidtopics.net/NGmgWoxP2Pw2QP6mkUZUOQ "One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.") |   |
[ ]

{#encryption__table_y4x_cxd_nzb}

## Activation information {#encryption__section_phy_rtz_fvb}

The ServiceNow Platform Encryption subscription bundle is a group commercial entitlement that includes Key Management Framework, Field Encryption Enterprise, Cloud Encryption, and Database Encryption.

Field Encryption Enterprise is the unlimited license of Field Encryption. The Field Encryption Enterprise plugin is available with the activation of the com.glide.now.platform.encryption plugin. For details, see [Encryption and Key Management subscription bundle](https://servicenow-prod.fluidtopics.net/1ecP56AMSSFdlBEyW4Jngg "With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.").  
Hinweis:  
KMF doesn't support domain separation, but can be used with on-premise instances.
* **[Exploring the Key Management Framework](https://servicenow-prod.fluidtopics.net/2_x4ht_V5js14q8h1AWqBA)**   
  Learn about the components of the Key Management Framework (KMF), and how to use them to manage how cryptographic operations are performed on your instance.
* **[Configuring the Key Management Framework](https://servicenow-prod.fluidtopics.net/40e2dCXudjmYbSCNDH4tog)**   
  Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.
* **[Key Management Framework Reference](https://servicenow-prod.fluidtopics.net/2OdvTPyfD~by6u_S5Urmrg)**   
  The Key Management Framework (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your ServiceNow instance. The ServiceNow Key Management Framework provides a secure and comprehensive interface for instance-side cryptographic key management services.
* **[Key management actions](https://servicenow-prod.fluidtopics.net/NGmgWoxP2Pw2QP6mkUZUOQ)**   
  One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.
* **[Import a key from a web service](https://servicenow-prod.fluidtopics.net/LJgZg8VNdUMfFPJrzbTVog#import-key-webservice-1)**   
  Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
* **[Key Management Framework Health](https://servicenow-prod.fluidtopics.net/kaNXHHuesASeolpwBG5fqg)**   
  Access on-demand health status information for the Key Management Framework. Warning and malfunction errors contain a detailed message.
* **[Prepare your instance for GlideEncrypter deprecation](https://servicenow-prod.fluidtopics.net/jHHO6IK9j_8KZOmDKMaMoA)**   
  Use an instance scan script to find and remove GlideEncrypter API calls on your instance. Removing these calls is a necessary step in deprecating 3DES encryption on your instance.
* **[Key Management Framework Resource Exchange](https://servicenow-prod.fluidtopics.net/yMNf5uG7D5KU6R8q6D9k9Q)**   
  ServiceNow® Resource Exchange is a KMF feature that gives you the capability to exchange resources between instances in a secure manner.
* **[Infrastructure Security](https://servicenow-prod.fluidtopics.net/7N6Gh5qlVffx~b7cCvR3sQ)**   
  Use Infrastructure security tools to create, upload, and manage certificates your instance uses to encrypt traffic from client to server.
* **[Password2 encryption with the Key Management Framework (KMF)](https://servicenow-prod.fluidtopics.net/1MbnA_V3~WeKVK8F3Q1g0Q)**   
  Supported by the Key Management Framework, use the Password2 (2-way encrypted) field type to encrypt and decrypt custom fields with segregation of duties, key protection, and life-cycle management. It works in accordance with NIST 800-57 guidelines and provides FIPS 140-2-L3 protection.

