Professional Data EngineerManaging and securing dataMedium
A financial institution is migrating its on-premises data archive to Google Cloud Storage. The archive contains sensitive customer transaction records that must be encrypted at rest. The institution has a strict compliance requirement to manage its own encryption keys entirely outside of Google Cloud's infrastructure, while still leveraging Google Cloud Storage for data durability and availability. Which encryption option should the data engineering team recommend?
- AGoogle-Managed Encryption Keys (GMEK) for Cloud Storage
- BCustomer-Managed Encryption Keys (CMEK) via Cloud Key Management Service (KMS)
- CClient-side encryption before uploading to Google Cloud Storage
- DCustomer-Supplied Encryption Keys (CSEK) for Cloud Storage
Show answer & explanationAnswer & explanation
Correct answer: D. Customer-Supplied Encryption Keys (CSEK) for Cloud Storage
Customer-Supplied Encryption Keys (CSEK) allow the customer to provide their own encryption keys directly to Google Cloud Storage for each object. This meets the requirement of managing keys entirely outside of Google Cloud's infrastructure, as the keys are never stored by Google.
Why the other options are wrong
- A. GMEK uses keys managed entirely by Google, which does not meet the requirement for customer key management.
- B. CMEK uses keys managed by the customer within Cloud KMS, which is still a Google-managed service, not entirely outside Google Cloud infrastructure.
- C. While client-side encryption is an option, CSEK specifically integrates this concept with Cloud Storage, allowing the service to handle decryption on retrieval, which is more robust than purely client-side encryption without integration.
Customer-Supplied Encryption Keys (CSEK)
CSEK is an encryption option for Google Cloud Storage where the customer provides their own encryption keys to encrypt and decrypt objects. Google Cloud Storage uses these keys for cryptographic operations but does not store them.
- Keys are generated and managed by the customer, outside Google Cloud.
- Keys are provided with each request to encrypt/decrypt objects.
- Offers maximum control over key management to the customer.
Memory trick: Google's got keys, but sometimes *you* bring yours.