ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

A cloud service provider (CSP) offers various data storage options to its clients. A client needs to store highly confidential intellectual property data that requires the highest level of assurance regarding data confidentiality and integrity, even if the underlying storage infrastructure is compromised. Which data security control, if implemented by the CSP, would best address this client's concern?

  1. ARegular vulnerability scanning of the storage infrastructure.
  2. BStrong access control lists (ACLs) on storage buckets.
  3. CEnd-to-end encryption with client-managed keys.
  4. DGeographic dispersion of data replicas.
Show answer & explanation

Correct answer: C. End-to-end encryption with client-managed keys.

End-to-end encryption with client-managed keys ensures that the data remains encrypted both in transit and at rest, and only the client can decrypt it. This protects the data even if the CSP's infrastructure is breached, as the CSP would not have access to the decryption keys, thus providing the highest confidentiality and integrity assurance.

Why the other options are wrong

  • A. Vulnerability scanning improves security but doesn't protect data if the infrastructure itself is compromised and keys are with the CSP.
  • B. ACLs are crucial but protect against unauthorized access, not against a compromised underlying storage system where the CSP could still access unencrypted data.
  • D. Geographic dispersion improves availability and resilience but does not directly enhance confidentiality if the data itself is compromised at any location.

Client-Managed Encryption Keys

A security model where the customer, not the cloud service provider, controls the encryption keys used to protect their data in the cloud.

  • Enhances data confidentiality and integrity in the cloud.
  • Mitigates risks from CSP breaches or insider threats.
  • Increases customer control over data security.

Memory trick: Key control is king for cloud confidentiality.

More Asset Security questions