A global technology company is developing a new serverless application that processes highly sensitive personal data. The data will be stored in an Amazon RDS PostgreSQL database. Due to data residency regulations, all data must remain within the EU. The company also requires that the encryption keys for the database are customer-managed and automatically rotated annually. Which solution meets these requirements?
- ADeploy the RDS PostgreSQL instance in an EU region and enable encryption at rest with a customer-managed AWS KMS CMK, performing manual key rotation annually.
- BDeploy the RDS PostgreSQL instance in an EU region and use client-side encryption for all data before storing it in the database.
- CDeploy the RDS PostgreSQL instance in an EU region (e.g., eu-central-1) and enable encryption at rest with a customer-managed AWS KMS CMK with automatic key rotation enabled.
- DDeploy the RDS PostgreSQL instance in a non-EU region and enable encryption at rest with an AWS-managed key.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy the RDS PostgreSQL instance in an EU region (e.g., eu-central-1) and enable encryption at rest with a customer-managed AWS KMS CMK with automatic key rotation enabled.
Deploying the RDS instance in an EU region ensures data residency. Enabling encryption at rest with a customer-managed AWS KMS CMK (Customer Master Key) means the customer controls the encryption key. Enabling automatic key rotation for this CMK in KMS fulfills the annual rotation requirement, making this the most comprehensive and efficient solution.
Why the other options are wrong
- A. While this option meets residency and customer-managed key requirements, it fails the 'automatically rotated annually' requirement due to manual rotation.
- B. Client-side encryption for an RDS database is complex and generally not recommended for 'at rest' encryption where native RDS encryption with KMS is available, as it adds significant application overhead and potential for errors.
- D. Deploying in a non-EU region violates data residency requirements and AWS-managed keys do not meet the 'customer-managed' key requirement.
RDS Data Residency with KMS
Ensuring an Amazon RDS database and its encryption keys comply with data residency requirements by provisioning the database in a specific AWS region and using customer-managed AWS KMS CMKs with automatic key rotation.
- Region selection dictates data residency.
- KMS CMKs provide customer control over encryption keys.
- Automatic key rotation enhances security without manual intervention.
Memory trick: EU for data, KMS for keys, auto-rotate for security's ease.