Professional Cloud ArchitectAnalyze and optimize technical and business processesMedium
A multinational company is migrating its enterprise resource planning (ERP) system to Google Cloud. The ERP system contains sensitive financial and customer data that requires strong encryption at rest and in transit. The company has strict compliance requirements that mandate they maintain control over the encryption keys. Which Google Cloud encryption option should they choose for their data stored in Cloud Storage and databases like Cloud SQL?
- AGoogle-managed encryption keys (by default).
- BClient-side encryption before uploading data to Google Cloud.
- CCustomer-managed encryption keys (CMEK) using Cloud Key Management Service (Cloud KMS).
- DCustomer-supplied encryption keys (CSEK) for all services.
Show answer & explanationAnswer & explanation
Correct answer: C. Customer-managed encryption keys (CMEK) using Cloud Key Management Service (Cloud KMS).
Customer-managed encryption keys (CMEK) via Cloud KMS allow the customer to generate, store, and manage their encryption keys while Google Cloud handles the encryption and decryption process. This provides the required control over encryption keys for compliance while leveraging Google's robust encryption infrastructure for data at rest.
Why the other options are wrong
- A. Google-managed encryption keys are the default, but they do not provide the customer with control over the encryption keys, failing to meet the compliance requirement.
- B. Client-side encryption requires the customer to manage all encryption and decryption processes and key management outside of Google Cloud, which can be complex and may not fully integrate with Google Cloud's native services for databases.
- D. Customer-supplied encryption keys (CSEK) are an option for Cloud Storage but are not available for all Google Cloud database services like Cloud SQL, making it an incomplete solution for the entire ERP system.
Google Cloud Encryption Options
Google Cloud offers various encryption options for data at rest and in transit, allowing customers to choose the level of key management control that best suits their security and compliance needs.
- Google-managed encryption keys (default): Google manages keys.
- Customer-managed encryption keys (CMEK): Customer controls keys via Cloud KMS.
- Customer-supplied encryption keys (CSEK): Customer provides and manages keys for Cloud Storage.
- Encryption in transit: Data is encrypted as it moves between services.
Memory trick: Google, Customer-Managed, Customer-Supplied: Key Choices.