ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityHard

An organization is migrating its on-premises data center to a public cloud environment. They have classified their data into four categories: Public, Internal Use Only, Confidential, and Highly Confidential. The legal department has mandated that 'Highly Confidential' data, which includes trade secrets and unpatented inventions, must always reside within the organization's legal jurisdiction and should not be accessible by the cloud provider's staff, even for maintenance. Which of the following approaches BEST satisfies these requirements?

  1. AUtilizing a multi-region cloud storage solution with data replication across different geographic zones.
  2. BStoring 'Highly Confidential' data in a dedicated virtual private cloud (VPC) with strong network access controls.
  3. CImplementing client-side encryption for 'Highly Confidential' data before uploading it to the cloud, with keys managed on-premises.
  4. DContracting with a cloud provider that offers a 'zero-knowledge' architecture, ensuring data is never decrypted on their servers.
Show answer & explanation

Correct answer: C. Implementing client-side encryption for 'Highly Confidential' data before uploading it to the cloud, with keys managed on-premises.

Client-side encryption with on-premises key management ensures that the data is encrypted before it ever leaves the organization's control, and the cloud provider never has access to the decryption keys. This uniquely addresses both the 'not accessible by cloud provider staff' and the implication of data jurisdiction (since the plaintext never leaves). While 'zero-knowledge' architecture is good, it's typically a property of specific applications/services, not general storage, and client-side encryption is the direct control for the data itself.

Why the other options are wrong

  • A. Multi-region replication improves availability and disaster recovery but doesn't address confidentiality from the CSP or ensure data stays within a single jurisdiction.
  • B. A VPC provides network isolation but doesn't prevent access by CSP staff if they have administrative privileges or if the data is unencrypted on their systems.
  • D. While 'zero-knowledge' architecture is a strong concept, it's often specific to certain applications or services. Client-side encryption is a direct, data-centric control that achieves the core requirement of preventing CSP access to plaintext, which is the most robust answer for 'highly confidential' data in general storage.

Client-Side Encryption (Cloud)

The process of encrypting data on the client's local system before it is transmitted to and stored in the cloud, with encryption keys managed by the client.

  • Cloud provider never has access to plaintext data or decryption keys.
  • Ensures maximum data confidentiality and control.
  • Mitigates risks from cloud provider breaches or insider threats.

Memory trick: Keep the keys at home to keep data truly private in the cloud.

More Asset Security questions