A pharmaceutical company is moving its research data to Amazon S3. The data is highly sensitive and subject to strict regulatory compliance, requiring all data to be encrypted at rest and in transit, with encryption keys fully managed by the customer for maximum control. Which S3 encryption option, combined with appropriate key management, would meet these stringent requirements?
- AServer-Side Encryption with Customer-Provided Keys (SSE-C)
- BServer-Side Encryption with KMS Customer Master Keys (CMKs) – customer managed (SSE-KMS)
- CServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
- DClient-Side Encryption with AWS Key Management Service (KMS)
Show answer & explanationAnswer & explanation
Correct answer: D. Client-Side Encryption with AWS Key Management Service (KMS)
Client-Side Encryption (CSE) ensures that data is encrypted before it leaves the customer's environment, providing the highest level of customer control over the encryption process and keys. Using AWS KMS with CSE allows for management of the encryption keys within a FIPS 140-2 validated service, meeting the 'customer managed keys' and 'maximum control' requirements for both data at rest and in transit (as it's encrypted before transit).
Why the other options are wrong
- A. SSE-C requires the customer to provide and manage their own encryption keys, but the encryption happens server-side, and the key is sent to AWS with each request, which might not meet 'maximum control' and 'customer managed' for transit for some interpretations.
- B. SSE-KMS with CMKs allows customer control over CMKs, but the encryption happens server-side, meaning data is in transit to S3 unencrypted before S3 encrypts it.
- C. SSE-S3 uses AWS-managed keys, which does not provide customer full control over the keys.
Client-Side Encryption with KMS
Encrypts data before it is sent to AWS, using keys managed by AWS KMS, providing maximum customer control over encryption for data in transit and at rest.
- Data is encrypted on the client-side before upload to AWS.
- Encryption keys are managed within AWS KMS, offering strong security and auditability.
- Provides the highest level of control and assurance for data encryption.
- Ensures data is encrypted both in transit and at rest from the customer's perspective.
Memory trick: Client-Side Keys give ultimate control over data's journey and rest.