CompTIA SecurityX (CAS-005)Security ArchitectureHard
A security architect is designing a system that processes highly sensitive personal health information (PHI) and must comply with stringent regulatory requirements for data protection. The architect needs a solution to ensure that cryptographic keys used for encrypting PHI are securely generated, stored, and managed throughout their lifecycle, with strong tamper-resistance and auditability. Which technology combination is purpose-built for this requirement?
- ASoftware-based Key Management System (KMS) with file-system encryption
- BClient-side encryption using keys managed by individual users
- CHardware Security Module (HSM) integrated with a Key Management System (KMS)
- DDirect key storage in a standard database with access control lists (ACLs)
Show answer & explanationAnswer & explanation
Correct answer: C. Hardware Security Module (HSM) integrated with a Key Management System (KMS)
An HSM provides tamper-resistant hardware for key generation and storage, while a KMS manages the entire key lifecycle (creation, rotation, revocation, auditability). This combination offers the highest level of security and compliance for sensitive cryptographic keys.
Why the other options are wrong
- A. Software-based KMS and file-system encryption offer less tamper-resistance and auditability compared to hardware-backed solutions.
- B. Client-side key management by individual users lacks centralized control, auditability, and consistent security posture required for organizational compliance with PHI.
- D. Storing keys directly in a standard database is highly insecure and does not meet the requirements for strong key protection or auditability.
HSM and KMS for Key Management
The combined use of Hardware Security Modules (HSMs) for secure, tamper-resistant cryptographic key generation and storage, and a Key Management System (KMS) for managing the full lifecycle of these keys, including distribution, rotation, and auditing.
- HSMs offer FIPS-certified hardware protection for keys.
- KMS provides centralized control and automation of key operations.
- Essential for meeting high-level compliance and security requirements.
Memory trick: HSM & KMS: 'Hardware Shields Keys' and 'Keeps Management Simple'.