Professional Data EngineerManaging and securing dataMedium

A healthcare provider is storing patient medical records in Cloud Storage. Due to HIPAA regulations, they must ensure that all data is encrypted at rest using keys managed by the organization, and that these keys can be revoked when necessary. The data engineering team needs to implement a solution that provides the highest level of control over the encryption keys. Which encryption method should they choose for Cloud Storage?

  1. ACustomer-managed encryption keys (CMEK)
  2. BClient-side encryption
  3. CGoogle-managed encryption keys
  4. DCustomer-supplied encryption keys (CSEK)
Show answer & explanation

Correct answer: D. Customer-supplied encryption keys (CSEK)

Customer-supplied encryption keys (CSEK) provide the highest level of control over encryption keys, as the customer generates and manages the keys entirely, supplying them with each request. This allows for revocation by simply not supplying the key.

Why the other options are wrong

  • A. CMEK uses keys stored in Cloud KMS, which Google manages on behalf of the customer, offering less direct control than CSEK.
  • B. Client-side encryption encrypts data before it leaves the client, but the question implies encryption at rest within Cloud Storage, where the key management method is the focus.
  • C. Google-managed encryption keys offer no organizational control over the keys.

Cloud Storage CSEK

Customer-supplied encryption keys (CSEK) for Cloud Storage allow users to provide their own AES-256 encryption keys, which are then used by Cloud Storage to encrypt and decrypt objects. The keys are not stored by Google.

  • Highest level of key control for the customer.
  • Key must be supplied with every request (upload/download).
  • Key is never stored by Google.

Memory trick: Cloud Keys Secure Every Data.

More Managing and securing data questions