Professional Cloud Security EngineerEnsuring data protectionMedium

A healthcare organization uses Google Cloud SQL for PostgreSQL to store patient health information (PHI). Regulatory compliance requires that all encryption keys used for PHI data must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM) and managed outside of Google's direct control. Which Google Cloud service should be used to meet this specific key management requirement?

  1. ACustomer-Supplied Encryption Keys (CSEK)
  2. BCloud Key Management Service (KMS) with software keys
  3. CCloud External Key Manager (EKM)
  4. DCloud KMS with Cloud HSM keys
Show answer & explanation

Correct answer: C. Cloud External Key Manager (EKM)

Cloud External Key Manager (EKM) allows customers to use encryption keys stored in a third-party key management system outside of Google Cloud, which can be configured to use FIPS 140-2 Level 3 validated HSMs and remain under the customer's direct control, meeting the specific regulatory requirement.

Why the other options are wrong

  • A. CSEK allows customers to provide a key for each object, but it's not a full key management service for Cloud SQL and doesn't explicitly guarantee FIPS 140-2 Level 3 HSM or external management for Cloud SQL's disk encryption.
  • B. Cloud KMS with software keys does not meet the FIPS 140-2 Level 3 HSM or 'outside of Google's direct control' requirements.
  • D. Cloud KMS with Cloud HSM keys uses Google's FIPS 140-2 Level 3 validated HSMs, but the keys are still within Google's infrastructure, not 'outside of Google's direct control'.

Cloud External Key Manager (EKM)

A Google Cloud service that allows you to use encryption keys stored and managed in a supported external key management system outside of Google's infrastructure.

  • Provides complete control over key lifecycle.
  • Supports various external KMS providers.
  • Ideal for strong sovereignty and regulatory compliance requirements.

Memory trick: For ultimate key independence, look outside the cloud.

More Ensuring data protection questions