Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityHard
A cloud architect is designing a highly sensitive data analytics platform that requires FIPS 140-2 Level 3 validated cryptographic modules for all data encryption at rest and in transit. The organization also needs full control over the encryption key lifecycle, including key generation, storage, and destruction, without the cloud provider having access to the unencrypted keys. Which cloud service model BEST meets these stringent cryptographic and key management requirements?
- APaaS with cloud provider-managed encryption keys
- BSaaS with customer-managed encryption keys (CMEK)
- CHSM as a Service (HSMaaS) offering
- DIaaS with customer-provisioned Hardware Security Modules (HSMs)
Show answer & explanationAnswer & explanation
Correct answer: C. HSM as a Service (HSMaaS) offering
HSM as a Service (HSMaaS) directly provides FIPS 140-2 Level 3 validated hardware for cryptographic operations and key storage. Crucially, it allows the customer to maintain sole control over the encryption keys, meaning the cloud provider never has access to the unencrypted keys, fulfilling the stringent 'full control' and 'provider no access' requirements.
Why the other options are wrong
- A. PaaS with cloud provider-managed keys explicitly states the provider manages keys, which violates the requirement for the 'customer having full control' and 'provider not having access'.
- B. SaaS typically offers limited control over underlying infrastructure and key management, even with CMEK, the FIPS level and full key lifecycle control might not be met.
- D. IaaS with customer-provisioned HSMs would meet the technical requirements, but 'HSM as a Service' is a more direct and often simpler cloud offering specifically designed for this need, abstracting the infrastructure management.
HSM as a Service
A cloud service that provides dedicated, FIPS-validated Hardware Security Modules (HSMs) for cryptographic operations and secure key storage, allowing customers exclusive control over their encryption keys.
- Meets stringent compliance requirements (e.g., FIPS 140-2 Level 3).
- Customer retains sole control of encryption keys (Bring Your Own Key).
- Offloads management of physical HSMs to the cloud provider.
Memory trick: Only your key, only your control, FIPS-level security goal.