Professional Cloud ArchitectDesign and plan a cloud solution architectureMedium

A multinational corporation is migrating its sensitive human resources (HR) application to Google Cloud. The application stores highly confidential employee data. The company's compliance requirements mandate that all data at rest must be encrypted with customer-managed encryption keys (CMEK) and regularly rotated. Additionally, access to this data must be strictly controlled and audited. Which Google Cloud service combination should be used to store the application's data?

  1. ACloud SQL with customer-managed encryption keys (CMEK) and Cloud Audit Logs
  2. BBigQuery with default encryption and Identity and Access Management (IAM)
  3. CCloud Storage with customer-supplied encryption keys (CSEK)
  4. DFirestore with Google-managed encryption keys and VPC Service Controls
Show answer & explanation

Correct answer: A. Cloud SQL with customer-managed encryption keys (CMEK) and Cloud Audit Logs

Cloud SQL supports CMEK for data at rest, allowing customer control over encryption keys and rotation. Cloud Audit Logs provide a comprehensive audit trail of access to the data, satisfying the strict control and auditing requirements for sensitive HR data.

Why the other options are wrong

  • B. BigQuery is a data warehouse, generally not suitable for transactional HR applications. While it has IAM, its default encryption doesn't fulfill the 'customer-managed encryption keys' requirement.
  • C. CSEK requires the customer to provide the encryption key with each request, which can be operationally complex for a database. CMEK is generally preferred for managed services.
  • D. Firestore is a NoSQL document database, which might not be the best fit for a traditional HR application. More importantly, Google-managed encryption keys do not meet the 'customer-managed encryption keys' requirement.

Customer-Managed Encryption Keys (CMEK)

An encryption option in Google Cloud where customers provide and manage their own encryption keys, which are then used by Google Cloud services to encrypt data at rest.

  • Provides greater control over encryption keys and key rotation.
  • Keys are managed in Cloud Key Management Service (KMS).
  • Used by many Google Cloud services for data at rest encryption.

Memory trick: Encrypt with your key, audit every step, for sensitive data's safe keep.

More Design and plan a cloud solution architecture questions