ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityHard
An organization is migrating sensitive customer data from on-premises servers to a public cloud storage service. To meet regulatory requirements, the data must remain encrypted at all times, including during transfer and when stored in the cloud. Furthermore, the organization wants to ensure that the CSP cannot access the plaintext data. Which encryption strategy should be implemented?
- AClient-side encryption before data leaves the on-premises network.
- BTransport Layer Security (TLS) for data in transit only.
- CServer-side encryption managed by the CSP.
- DCSP-managed encryption with customer-controlled keys.
Show answer & explanationAnswer & explanation
Correct answer: A. Client-side encryption before data leaves the on-premises network.
Client-side encryption, performed before the data leaves the client's control, ensures that the data is encrypted before it ever reaches the CSP. This strategy guarantees that the CSP only ever receives and stores encrypted data, thus preventing them from accessing the plaintext data, fulfilling the most stringent requirement.
Why the other options are wrong
- B. TLS protects data in transit but does not address data at rest or prevent the CSP from seeing plaintext upon arrival.
- C. Server-side encryption means the CSP encrypts the data once it receives it, meaning the CSP has access to plaintext prior to encryption.
- D. CSP-managed encryption, even with customer-controlled keys, means the CSP still performs the encryption/decryption, potentially exposing plaintext.
Client-Side Encryption
Encryption performed by the client application or system before data is transmitted to or stored by a third party (e.g., cloud provider).
- Ensures data is encrypted before leaving client control.
- Prevents cloud provider from accessing plaintext data.
- Provides highest level of data confidentiality in cloud.
Memory trick: Client First, Cloud Never Sees; Server Second, Cloud Can Please.