---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Create a cryptographic module life-cycle policy

# Create a cryptographic module life-cycle policy {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.

## Vorbereitungen

Role required: sn_kmf.cryptographic_manager

## Warum und wann dieser Vorgang ausgeführt wird

A cryptographic module life-cycle policy is an instance-level policy. The more exposure that a cryptographic key has, the more likely it can be compromised. Safeguard keys by limiting how long the keys can be used and who can
use them.

The following features govern cryptographic modules:

* Instance policies set boundaries for the instance. For example, if you specify in an instance policy that the expiration date should never be more than two years after the activation date, you can't use the life-cycle rules to set an
  expiration date five years after the activation date.

* Instance life-cycle templates enable you to set different policies for different keys. Templates offer default life-cycle rules for cryptographic modules so that they don't have to be re-created for every module. For example, you can set
  different expiration dates for symmetric data encryption keys than for public key wrapping keys.

* Life-cycle rules affect the keys directly. For example, if you specify in the life-cycle rules that the expiration date should be two years after the activation date, keys will expire two years after the activation date.

{#create-cryptographic-module-lifecycle-policy__ul_rzd_44g_qnb}

## Prozedur

1. Navigate to AllKey ManagementLifecycle PoliciesInstance Policies.
2. Select New.
3. Complete the form.  
   Cryptographic Life-cycle Policies fields{#create-cryptographic-module-lifecycle-policy__simpletable_yph_jrg_qnb__entry__2}

   | Field | Description |
   |-|-|
   | Applies to | Read only. The key that the life cycle applies to. |
   | Active | Select to activate the policy. |
   | Policy condition | Conditional statements that specify when to activate, renew, deactivate, and destroy the cryptographic module. |
   | Result | Reject to revoke access to the cryptographic module, or Track to permit access and monitor use of the cryptographic module. |
   [ ]

   {#create-cryptographic-module-lifecycle-policy__simpletable_yph_jrg_qnb}

## Nächste Maßnahme

If you want to add exceptions to this life-cycle policy at the module level, see [Create module life-cycle policy exceptions](https://servicenow-prod.fluidtopics.net/JSnNYUsmWzeVWJIuTAZtjQ "Create a module policy exception to change the life-cycle policy of a key only for a specific on one instance.").
* **[Create module life-cycle policy exceptions](https://servicenow-prod.fluidtopics.net/JSnNYUsmWzeVWJIuTAZtjQ)**   
  Create a module policy exception to change the life-cycle policy of a key only for a specific on one instance.

