ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

A global e-commerce company is migrating its customer database to a public cloud environment. The company's policy dictates that all Personally Identifiable Information (PII) must be protected at rest and in transit. To meet regulatory compliance, the company wants to ensure that the cloud provider does not have access to the encryption keys for their most sensitive customer data. Which encryption key management approach should the company implement?

  1. AClient-Side Encryption (CSE) with client-managed keys
  2. BTransparent Data Encryption (TDE) provided by the CSP
  3. CCloud Provider Managed Keys
  4. DHardware Security Modules (HSMs) provided by the CSP
Show answer & explanation

Correct answer: A. Client-Side Encryption (CSE) with client-managed keys

Client-Side Encryption (CSE) with client-managed keys ensures that the encryption and decryption occur before data leaves the client's control, and the keys remain exclusively with the client, preventing the cloud provider from accessing the unencrypted data.

Why the other options are wrong

  • B. Transparent Data Encryption (TDE) is typically managed by the database or CSP, meaning the CSP would have access to the keys.
  • C. Cloud Provider Managed Keys mean the CSP generates and manages the keys, giving them potential access to the data.
  • D. While HSMs enhance key security, if they are CSP-provided and managed, the CSP still has control over the environment and potentially the keys.

Client-Side Encryption (CSE)

Encryption performed by the client before data is sent to a cloud service or stored, with the encryption keys retained solely by the client.

  • Data encrypted before leaving client control
  • Client holds all encryption keys
  • Cloud provider cannot access plaintext data

Memory trick: Client-Side Keys mean the Cloud Can't See.

More Asset Security questions