ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

A cloud service provider (CSP) offers object storage for sensitive customer data. A client requires that cryptographic keys for their data stored in this service are generated, stored, and managed solely within their own on-premises Hardware Security Modules (HSMs). Which of the following key management models best describes this client's requirement?

  1. ACSP-Managed Keys
  2. BCSP-Controlled Keys with Client Access
  3. CClient-Managed Keys (BYOK)
  4. DClient-Side Encryption with CSP Key Escrow
Show answer & explanation

Correct answer: C. Client-Managed Keys (BYOK)

Client-Managed Keys, often referred to as Bring Your Own Key (BYOK), means the client generates, stores, and manages their own cryptographic keys, typically in their on-premises HSMs, and then provides them to the CSP for use with their data. This provides the highest level of client control over encryption keys.

Why the other options are wrong

  • A. CSP-Managed Keys mean the CSP handles all aspects of key management.
  • B. CSP-Controlled Keys with Client Access implies the CSP manages keys but allows client interaction, not full client control.
  • D. Key escrow involves a third party holding keys, and client-side encryption is separate from how keys are managed by the CSP.

Client-Managed Keys (BYOK)

A cloud key management model where the client generates, stores, and manages their own cryptographic keys, typically using on-premises HSMs, and provides them to the CSP for data encryption.

  • Client retains full control over keys.
  • Keys often generated and stored in client's HSMs.
  • Enhances data sovereignty and security posture.

Memory trick: Client's Keys, Client's Control; CSP's Keys, CSP's Role.

More Asset Security questions