A security architect is evaluating a new cloud-native application that processes sensitive customer data across multiple regions. The application utilizes managed databases and storage services. The architect needs to ensure that all data at rest within these cloud services is encrypted using customer-managed encryption keys (CMEK) and that the key management infrastructure provides strong hardware-backed security. Which solution BEST addresses these requirements?
- AUtilizing default cloud provider encryption with platform-managed keys.
- BDeploying a software-based Key Management System (KMS) within a private subnet.
- CIntegrating with the cloud provider's Hardware Security Module (HSM) service for CMEK.
- DImplementing application-layer encryption before data is sent to cloud storage.
Show answer & explanationAnswer & explanation
Correct answer: C. Integrating with the cloud provider's Hardware Security Module (HSM) service for CMEK.
Integrating with the cloud provider's HSM service for CMEK provides customer control over encryption keys while leveraging hardware-backed security for key generation and storage, meeting both the 'customer-managed' and 'hardware-backed' requirements. This is a common and robust solution for sensitive data in the cloud.
Why the other options are wrong
- A. Platform-managed keys do not provide customer control over the encryption keys, failing the 'customer-managed' requirement.
- B. A software-based KMS, even in a private subnet, does not offer the 'hardware-backed security' for key material that an HSM provides, making it less secure for highly sensitive data.
- D. Application-layer encryption requires significant development effort and managing keys outside the cloud provider's integrated services, which can be complex and less efficient for managed services.
HSM with CMEK
Hardware Security Modules (HSMs) provide a tamper-resistant environment for cryptographic key generation, storage, and operations. When used with Customer-Managed Encryption Keys (CMEK), it allows cloud customers to control their encryption keys while benefiting from the hardware-backed security of the HSM.
- Keys are generated and stored in a secure hardware module.
- Customers retain control over their encryption keys.
- Provides strong cryptographic assurances for data at rest.
Memory trick: HSM with CMEK: Hardware secures my Cloud Encryption Keys.