A company is migrating its existing data warehouse to Amazon Redshift. The security team has mandated that all data loaded into Redshift must be encrypted at rest, and the encryption keys must be managed by the company, not AWS. Additionally, an audit trail of all key usage must be maintained. Which encryption option for Amazon Redshift should the SysOps administrator choose?
- AClient-side encryption before data is loaded into Redshift.
- BAmazon Redshift native encryption with an AWS-managed key.
- CAWS Key Management Service (KMS) with customer-managed keys (CMK).
- DAWS Key Management Service (KMS) with AWS-managed keys (CMK).
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Key Management Service (KMS) with customer-managed keys (CMK).
The requirement states that encryption keys must be managed by the company, not AWS, and that an audit trail of key usage must be maintained. AWS KMS with customer-managed keys (CMKs) directly fulfills this by allowing the customer to create, own, and manage their encryption keys. KMS also integrates with AWS CloudTrail to provide an audit trail of all key usage, meeting both specified compliance requirements.
Why the other options are wrong
- A. Client-side encryption can be used, but it adds significant operational overhead and complexity compared to leveraging Redshift's built-in KMS integration, which is designed for this purpose, and it doesn't inherently provide a centralized audit trail of key usage for Redshift itself.
- B. Redshift native encryption with an AWS-managed key does not allow the company to manage the keys, conflicting with the requirement.
- D. AWS-managed keys (CMK) are managed by AWS on the customer's behalf and do not allow the company to manage the keys themselves.
KMS Customer-Managed Keys (CMK)
Customer-managed keys (CMKs) in AWS KMS are encryption keys that you create, own, and manage, providing greater control over key lifecycle and auditing.
- You control key creation, rotation, and access policies.
- Integrates with AWS services like Redshift.
- Key usage is auditable via AWS CloudTrail.
- Offers more control than AWS-managed keys.
Memory trick: Customer-Managed Keys means 'Custody Means Control' and 'CloudTrail records everything'.