Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium

A cloud development team is building a new application that will process sensitive customer data. They want to ensure that all data at rest within the cloud storage is encrypted using keys that they fully control and manage outside of the cloud provider's direct control. Which encryption strategy should they implement?

  1. AClient-Side Encryption with Customer-Provided Keys (CSE-C)
  2. BServer-Side Encryption with Customer-Provided Keys (SSE-C)
  3. CServer-Side Encryption with Cloud-Managed Keys (SSE-C)
  4. DServer-Side Encryption with KMS-Managed Keys (SSE-KMS)
Show answer & explanation

Correct answer: A. Client-Side Encryption with Customer-Provided Keys (CSE-C)

Client-Side Encryption with Customer-Provided Keys (CSE-C) ensures that encryption and decryption occur on the client side before data is sent to or after it is retrieved from cloud storage, with the keys fully managed by the customer. This gives the customer complete control over the encryption keys, satisfying the requirement.

Why the other options are wrong

  • B. SSE-C uses keys provided by the customer, but the encryption/decryption process happens server-side, meaning the cloud provider handles the cryptographic operations.
  • C. SSE-C uses keys provided by the customer, but the encryption/decryption process happens server-side, meaning the cloud provider handles the cryptographic operations.
  • D. SSE-KMS uses keys managed by the cloud provider's Key Management Service, which does not meet the requirement of keys being fully controlled and managed outside the cloud provider's direct control.

Client-Side Encryption (CSE)

Encryption performed by the client application before data is sent to the cloud, ensuring the cloud provider never sees unencrypted data or encryption keys. The client maintains full control over the keys.

  • Data encrypted before leaving client environment.
  • Client holds and manages the encryption keys.
  • Cloud provider stores encrypted data only.

Memory trick: To truly own your cloud data lock, keep the key in your hand, not in the cloud's.

More Cloud Application Security questions