Professional Cloud Security EngineerEnsuring data protectionMedium
A healthcare organization uses Google Cloud SQL for PostgreSQL to store patient health information (PHI). Regulatory compliance requires that all encryption keys used for PHI data must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM) and managed outside of Google's direct control. Which Google Cloud service should be used to meet this specific key management requirement?
- ACustomer-Supplied Encryption Keys (CSEK)
- BCloud Key Management Service (KMS) with software keys
- CCloud External Key Manager (EKM)
- DCloud KMS with Cloud HSM keys
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud External Key Manager (EKM)
Cloud External Key Manager (EKM) allows customers to use encryption keys stored in a third-party key management system outside of Google Cloud, which can be configured to use FIPS 140-2 Level 3 validated HSMs and remain under the customer's direct control, meeting the specific regulatory requirement.
Why the other options are wrong
- A. CSEK allows customers to provide a key for each object, but it's not a full key management service for Cloud SQL and doesn't explicitly guarantee FIPS 140-2 Level 3 HSM or external management for Cloud SQL's disk encryption.
- B. Cloud KMS with software keys does not meet the FIPS 140-2 Level 3 HSM or 'outside of Google's direct control' requirements.
- D. Cloud KMS with Cloud HSM keys uses Google's FIPS 140-2 Level 3 validated HSMs, but the keys are still within Google's infrastructure, not 'outside of Google's direct control'.
Cloud External Key Manager (EKM)
A Google Cloud service that allows you to use encryption keys stored and managed in a supported external key management system outside of Google's infrastructure.
- Provides complete control over key lifecycle.
- Supports various external KMS providers.
- Ideal for strong sovereignty and regulatory compliance requirements.
Memory trick: For ultimate key independence, look outside the cloud.