Professional Cloud ArchitectDesign for security and complianceMedium

A global financial institution is migrating its on-premises data centers to Google Cloud. They handle highly sensitive customer financial data and are subject to strict regulatory compliance requirements, including GDPR, CCPA, and PCI DSS. The institution needs to ensure that all data at rest is encrypted with customer-managed encryption keys (CMEK) and that key access is tightly controlled, audited, and geographically restricted to specific regions. They also require the ability to revoke access to data by disabling the encryption keys. Which Google Cloud service should be used to meet these key management requirements?

  1. ACloud Storage
  2. BSecret Manager
  3. CCloud Key Management Service (KMS)
  4. DIdentity and Access Management (IAM)
Show answer & explanation

Correct answer: C. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) is specifically designed to manage cryptographic keys for cloud services, offering features like CMEK, key rotation, access control, and audit logging, which directly address the institution's requirements for sensitive data and compliance.

Why the other options are wrong

  • A. Cloud Storage is a data storage service and can use KMS for encryption, but it's not the key management service itself.
  • B. Secret Manager is for storing API keys, passwords, certificates, and other secrets, not for managing cryptographic encryption keys used for data at rest.
  • D. IAM manages permissions and access to resources, including KMS keys, but it is not the service that generates or stores the encryption keys themselves.

Cloud Key Management Service (KMS)

A Google Cloud service for managing cryptographic keys in a cloud-hosted environment, enabling strong encryption for data at rest and in transit.

  • Supports symmetric and asymmetric encryption keys.
  • Integrates with many Google Cloud services for CMEK.
  • Provides key rotation, access control, and audit logging.

Memory trick: Keys Keep My Secrets Secure, Every time.

More Design for security and compliance questions