A software-as-a-service (SaaS) company is developing a new application that stores highly sensitive customer data. The company's compliance requirements mandate that all customer data must be encrypted using customer-controlled keys. Additionally, the application needs to perform cryptographic operations (encrypt, decrypt) on the data within a FIPS 140-2 Level 3 validated hardware security module (HSM) that is fully managed by AWS. Which AWS service should the security architect recommend to meet these stringent encryption and key management requirements?
- AAWS Key Management Service (KMS) with custom key stores backed by AWS CloudHSM
- BAWS Secrets Manager for storing and managing encryption keys
- CAWS Certificate Manager (ACM) for managing SSL/TLS certificates and keys
- DAWS CloudHSM directly provisioned and managed by the customer
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Key Management Service (KMS) with custom key stores backed by AWS CloudHSM
AWS KMS custom key stores backed by AWS CloudHSM allow customers to generate, store, and use their KMS keys within a FIPS 140-2 Level 3 validated CloudHSM cluster that they own and manage. This provides the full customer control over keys and the guaranteed hardware-backed security required, while leveraging KMS's integrated API for cryptographic operations and audit logging.
Why the other options are wrong
- B. AWS Secrets Manager is for storing and rotating secrets like database credentials or API keys, not for performing cryptographic operations within an HSM or for general data encryption keys.
- C. AWS Certificate Manager (ACM) is for provisioning, managing, and deploying SSL/TLS certificates for AWS services. It's not designed for general data encryption or custom key management within an HSM.
- D. While AWS CloudHSM provides FIPS 140-2 Level 3 validated HSMs, directly provisioning and managing it by the customer means the customer is responsible for much of the operational overhead (patching, backups, scaling), which contradicts the 'fully managed by AWS' aspect implied by seeking a service that integrates this capability securely and simply, as KMS custom key stores do.
KMS Custom Key Stores with CloudHSM
A KMS Custom Key Store backed by AWS CloudHSM allows you to create KMS keys whose cryptographic operations are performed within a dedicated, FIPS 140-2 Level 3 validated CloudHSM cluster that you own and control.
- Customer owns and manages the CloudHSM cluster.
- KMS provides a streamlined API for using these keys.
- Combines KMS ease of use with dedicated HSM security.
Memory trick: KMS + CloudHSM = 'Key Master' for your 'Hardware Safe Mode' data.