Professional Data EngineerManaging and securing dataHard

A financial services company is migrating its on-premises transactional database to Cloud Spanner. The database contains highly sensitive client financial records, and the company has a strict regulatory requirement that all encryption keys for this data must be stored and managed in a FIPS 140-2 Level 3 certified hardware security module (HSM) that is physically located within their own data centers. They want to ensure that Cloud Spanner uses these keys for encrypting the data at rest. Which solution should the data engineering team choose?

  1. AEncrypt data at the application layer before writing to Cloud Spanner and manage keys themselves.
  2. BImplement Customer-Managed Encryption Keys (CMEK) for Cloud Spanner with Cloud KMS External Key Manager (EKM).
  3. CUse Google-Managed Encryption Keys (GMEK) for Cloud Spanner and rely on Google's certifications.
  4. DConfigure Customer-Managed Encryption Keys (CMEK) for Cloud Spanner using Cloud KMS software keys.
Show answer & explanation

Correct answer: B. Implement Customer-Managed Encryption Keys (CMEK) for Cloud Spanner with Cloud KMS External Key Manager (EKM).

The requirement for physically located FIPS 140-2 Level 3 certified HSMs in their own data centers points directly to Cloud KMS's External Key Manager (EKM). This allows Cloud Spanner to use encryption keys that are managed in the customer's external, on-premises HSMs, meeting the stringent regulatory and physical isolation requirements.

Why the other options are wrong

  • A. While application-layer encryption is possible, it adds significant complexity to the application, losing the benefits of Cloud Spanner's native encryption integration and potentially hindering performance and manageability compared to CMEK/EKM.
  • C. GMEK does not allow the customer to manage their own keys, thus failing the regulatory requirement.
  • D. Cloud KMS software keys or even regular Cloud KMS HSM keys (managed by Google) do not meet the requirement of keys being physically located within the *customer's own data centers*.

Cloud Spanner with Cloud KMS External Key Manager (EKM)

Cloud Spanner can integrate with Cloud KMS to use Customer-Managed Encryption Keys (CMEK). When combined with Cloud KMS External Key Manager (EKM), this allows Cloud Spanner to encrypt data at rest using keys that are physically managed in the customer's own external key management systems, such as on-premises FIPS 140-2 Level 3 certified HSMs.

  • Enables Cloud Spanner to use customer-managed keys from external HSMs.
  • Keys are stored and controlled outside Google Cloud infrastructure.
  • Meets strict compliance for key sovereignty and physical isolation.
  • Cloud Spanner data is encrypted/decrypted using these external keys.

Memory trick: Spanner stretches globally, but the key stays home.

More Managing and securing data questions