---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Key management actions

# Key management actions {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle
operations.
The following table provides a summary of the key life cycle operations and management actions. The cryptographic module purpose is applied to the data with the cryptographic module configuration and has no impact on data.  
{#key-management-actions__table_mvb_drb_smb__entry__2}

| Key management action | Description |
|-|-|
| Generate key  | Generates  a  new key for the given  cryptographic module. A first generated key is set to active.  |
| Rotate key  | Deactivates  the current  key and  generates a new  one. The  new  module key is set to current  (active).  |
| Revoke key | Marks  the current key  and life cycle state as revoked. The cryptographic module auto-generates a new key on new data and sets the key status to active. Revoked means that the key is no longer used for encryption. However, it can still be used for decryption. You can't destroy a key. |
| Suspend key | Marks  the current key as suspended.  Manually  resume the suspended  key or revoke  the suspended key to generate  a new module key before using the cryptographic module again. |
| Resume key | Marks a suspended key as the active key. |
| Renew key | Extends the life of the current key. The Renew button becomes available under the following circumstances: * You're assigned the cryptographic manager role. * The life-cycle state is marked to either Active or Renewed. * An expiration date is set in the module life cycle definition. {#key-management-actions__ul_tzj_hnv_d4b} |
[ ]

{#key-management-actions__table_mvb_drb_smb}
* **[View and manage keys](https://servicenow-prod.fluidtopics.net/Q04axqG00a5FESkyjpKD4A)**   
  Review the status of any key to determine further key action, such as when to renew, rotate, suspend, deactivate, or destroy a current key.
* **[Rotate keys](https://servicenow-prod.fluidtopics.net/kC1A~8KQpyWSFSn27nyliQ)**   
  For increased security, you can rotate your cryptographic keys on a pre-determined schedule. Key rotation is when you retire an encryption key and replace that old key by generating a new cryptographic key.

