Standards alignment

MIPS Standards Alignment

MIPS helps organizations establish controlled and auditable certificate lifecycle processes through ServiceNow and CyberArk Certificate Manager. MIPS supports both the SaaS and Self-Hosted editions of CyberArk Certificate Manager. Most customer environments configure the edition that best aligns with their existing architecture and operational model.

The information below explains how MIPS capabilities support selected PKI and machine identity practices. It does not represent a claim that MIPS itself is certified by NIST or validated under FIPS.

Platform support

CyberArk Certificate Manager Integration

MIPS integrates ServiceNow certificate-management workflows with CyberArk Certificate Manager. Customers may use CyberArk Certificate Manager, SaaS or CyberArk Certificate Manager, Self-Hosted based on their architecture, licensing and operational requirements.

CyberArk Certificate Manager, SaaS

MIPS integrates ServiceNow certificate lifecycle workflows with the CyberArk Certificate Manager SaaS platform.

  • Cloud-delivered certificate lifecycle management
  • ServiceNow request and approval orchestration
  • Certificate issuance, renewal and lifecycle operations
  • Policy-based certificate management
  • Integration using approved APIs
  • SaaS access through the venafi.cloud service domain

CyberArk Certificate Manager, Self-Hosted

MIPS integrates ServiceNow certificate lifecycle workflows with CyberArk Certificate Manager, Self-Hosted, formerly Venafi Trust Protection Platform.

  • Customer-managed deployment
  • ServiceNow request and approval orchestration
  • Certificate issuance, renewal and lifecycle operations
  • Policy-based certificate management
  • Integration using approved APIs
  • Customer-managed connectivity and infrastructure

Platform support: MIPS supports both CyberArk Certificate Manager, SaaS and CyberArk Certificate Manager, Self-Hosted. Most customer deployments configure one edition based on their architecture and operational requirements.

Architecture

Security and Cryptographic Responsibility

MIPS is a ServiceNow workflow and integration application. It uses API calls from ServiceNow to CyberArk Certificate Manager to request and orchestrate certificate lifecycle operations.

  • MIPS does not generate private keys.
  • MIPS does not store private keys.
  • MIPS does not store passwords.
  • MIPS does not perform certificate-signing operations.
  • MIPS does not implement cryptographic algorithms.
  • CyberArk Certificate Manager performs the certificate and cryptographic operations.
  • The applicable certificate data and lifecycle status are returned to MIPS through the integration.
  • Sensitive private-key material is not stored in MIPS.

When an authorized user requests a certificate package containing a private key, CyberArk Certificate Manager generates the private key and the resulting download is delivered to the user's browser. The private key is not stored in MIPS.

NIST SP 800-57

Key and certificate lifecycle governance.

MIPS supports practices described in NIST SP 800-57. It supports operational processes involving the following, while cryptographic operations depend on the connected platforms and the customer's configuration.

  • Certificate inventory
  • Installed-location tracking
  • Ownership
  • Request and approval workflows
  • Issuance
  • Renewal
  • Rotation
  • Revocation
  • Retirement
  • Decommissioning
  • Role-based access
  • Audit history
  • Reporting
  • Incident-response support
NIST SP 800-131A Revision 2

Support for organizational cryptographic policies.

MIPS helps organizations govern certificate requests through controlled ServiceNow workflows while leveraging CyberArk Certificate Manager, certificate authority templates and customer-defined policies for approved algorithms, key lengths and certificate configurations.

MIPS does not directly implement cryptographic algorithms. Cryptographic-policy enforcement may occur in CyberArk Certificate Manager, the certificate authority, certificate templates, HSMs or other customer-configured cryptographic components.

FIPS-validated environments

FIPS-Validated Environments

MIPS is a workflow and integration application. FIPS validation applies to specific cryptographic modules and approved operating configurations within the deployment — not to the MIPS workflow layer.

  • FIPS validation applies to specific cryptographic modules.
  • MIPS is a workflow and integration application.
  • MIPS does not generate or store private keys.
  • MIPS does not perform cryptographic algorithms or certificate signing.
  • CyberArk Certificate Manager and the customer's certificate authorities, HSMs and cryptographic modules perform the cryptographic operations.
  • FIPS validation does not automatically transfer from CyberArk, ServiceNow, an HSM or a certificate authority to MIPS.
  • The customer is responsible for verifying that each applicable cryptographic module is validated and configured in its approved operating mode.
Shared responsibility

Who does what.

Certificate lifecycle governance is a shared responsibility across MIPS, ServiceNow, CyberArk Certificate Manager, and the customer's own architecture and policies.

MIPS

  • Service requests
  • Approval orchestration
  • Certificate lifecycle workflows
  • Certificate ownership
  • ServiceNow records
  • Installed-location tracking
  • Audit history
  • Reporting
  • API orchestration with CyberArk Certificate Manager

ServiceNow

  • Service Catalog
  • Workflow execution
  • Roles and access controls
  • CMDB relationships
  • Change management
  • Notifications
  • Platform data protection
  • Operational records

CyberArk Certificate Manager

  • SaaS or Self-Hosted deployment
  • Certificate generation
  • Private-key generation
  • Certificate enrollment
  • Certificate renewal
  • Certificate revocation
  • Certificate retirement and decommissioning
  • Certificate policy enforcement
  • Machine identity automation
  • Cryptographic operations

Customer

  • Deployment selection
  • Security architecture
  • Product licensing
  • Network connectivity
  • Platform configuration
  • Certificate authority configuration
  • HSM selection
  • Access assignments
  • Policy definition
  • Compliance assessment
Compatibility

Product Compatibility

MIPS v9 supports CyberArk Certificate Manager, SaaS and Self-Hosted, including current and older customer deployments.

MIPS v9 has been tested against both CyberArk Certificate Manager, SaaS and Self-Hosted, including current and older customer deployments.

Public release
MIPS v9
Compatibility status
Supported
Review date
Current as of publication
References

Official references.

The following are official publications hosted by NIST. These links are provided for reference only and do not imply endorsement of MIPS by NIST or the United States government.

Terminology note: CyberArk Certificate Manager products were previously marketed under the Venafi brand. Some existing deployments, customer documentation and service URLs may continue to use Venafi terminology, including the venafi.cloud login domain used for CyberArk Certificate Manager, SaaS.

Important disclaimer

Read this before relying on the above.

Standards note: MIPS supports workflows and controls that can help organizations align with established PKI and machine identity practices. Compliance and cryptographic validation depend on the customer's architecture, policies, configurations, certificate authorities, underlying platforms and validated cryptographic modules.

The information provided on this page is intended to explain how MIPS may support an organization's security and certificate-management practices. It is not legal, regulatory, audit, or compliance advice. Use of MIPS does not by itself guarantee compliance with any standard, regulation, or organizational policy.