A healthcare provider stores sensitive patient medical images in Cloud Storage. Due to strict HIPAA regulations, these images must be encrypted using keys that are maintained physically isolated in a FIPS 140-2 Level 3 certified hardware security module (HSM). The provider wants to use Google Cloud services where possible but needs to integrate their existing on-premises HSMs for key management. Which encryption approach should they use?
- AGoogle-Managed Encryption Keys (GMEK) for Cloud Storage.
- BCustomer-Supplied Encryption Keys (CSEK) for Cloud Storage.
- CCustomer-Managed Encryption Keys (CMEK) with Cloud KMS using software keys.
- DCustomer-Managed Encryption Keys (CMEK) with Cloud KMS using an External Key Manager (EKM).
Show answer & explanationAnswer & explanation
Correct answer: D. Customer-Managed Encryption Keys (CMEK) with Cloud KMS using an External Key Manager (EKM).
The requirement for physically isolated FIPS 140-2 Level 3 certified HSMs that are on-premises points directly to using an External Key Manager (EKM). Cloud KMS's EKM integration allows Google Cloud services like Cloud Storage to use encryption keys that are managed in the customer's external, on-premises HSMs, meeting the stringent compliance requirements.
Why the other options are wrong
- A. GMEK does not allow the customer to manage their own keys, failing the compliance requirement.
- B. CSEK requires the customer to supply the key with each request, but doesn't provide a centralized key management solution leveraging an HSM for Cloud Storage directly in the way CMEK/EKM does.
- C. Software keys in Cloud KMS do not meet the FIPS 140-2 Level 3 HSM requirement for physical isolation.
Cloud KMS External Key Manager (EKM)
Cloud KMS EKM allows customers to use encryption keys that are managed outside Google Cloud, in their own external key management systems (like on-premises HSMs), while still leveraging Google Cloud services for data storage and processing. Cloud KMS acts as a proxy to these external keys.
- Integrates Google Cloud with customer's external key management systems.
- Keys remain outside Google's infrastructure, managed by the customer.
- Supports high-security requirements like FIPS 140-2 Level 3 HSMs.
- Data encrypted in Google Cloud is protected by keys never directly accessible by Google.
Memory trick: External Key Manager: Your keys, your house, Google accesses them (safely).