Professional Cloud ArchitectDesign for security and complianceHard

A large enterprise is migrating a highly regulated application to Google Cloud. This application processes sensitive personal data and requires strict controls over how data is processed, stored, and accessed. Due to compliance requirements, the customer must have explicit control and visibility over the encryption key lifecycle, including key generation, storage, and revocation, and must be able to prove that Google personnel cannot access the unencrypted data without explicit customer approval and audit trails. Which Google Cloud security feature best addresses these requirements for data in Google Cloud services?

  1. AConfidential Computing with Key Access Justifications and External Key Manager (EKM)
  2. BCustomer-Supplied Encryption Keys (CSEK) with VPC Service Controls
  3. CCloud HSM with Access Transparency and Data Loss Prevention (DLP)
  4. DCustomer-Managed Encryption Keys (CMEK) with Cloud Audit Logs
Show answer & explanation

Correct answer: A. Confidential Computing with Key Access Justifications and External Key Manager (EKM)

This scenario requires the highest level of control over encryption keys and proof of Google's inability to access unencrypted data without customer approval. Confidential Computing encrypts data in memory during processing. External Key Manager (EKM) allows customers to manage keys outside Google Cloud, giving them ultimate control over key lifecycle and revocation. Key Access Justifications provides explicit justification and approval for any Google access to keys, with audit trails. Combined, these provide the strongest guarantees. CMEK manages keys within Google KMS but doesn't give external control. CSEK provides the key but Google still processes it. Cloud HSM manages keys in Google's HSMs, but doesn't offer external management or the in-memory encryption of Confidential Computing.

Why the other options are wrong

  • B. CSEK means the customer provides the key, but Google still processes it within their infrastructure. VPC Service Controls creates perimeters but doesn't provide external key management or in-memory encryption, nor does it explicitly address Google personnel access to unencrypted data.
  • C. Cloud HSM provides FIPS 140-2 Level 3 validated key storage within Google Cloud. Access Transparency logs Google's administrative access. DLP protects sensitive data. However, this combination lacks external key management (EKM) for ultimate customer control over key revocation and the in-memory encryption provided by Confidential Computing, which are critical for the 'unencrypted data' requirement.
  • D. CMEK allows customers to manage keys within Google Cloud KMS. While it integrates with Cloud Audit Logs, it doesn't offer the external key management (EKM) or the in-memory encryption of Confidential Computing, nor the explicit approval mechanism of Key Access Justifications.

Ultimate Data Control Stack

A combination of Google Cloud services (Confidential Computing, EKM, Key Access Justifications) providing the highest level of customer control over encryption keys and assurance against unauthorized access to unencrypted data.

  • Confidential Computing encrypts data in-use (memory).
  • External Key Manager (EKM) puts key management fully under customer control.
  • Key Access Justifications provides audit and approval for Google personnel key access.

Memory trick: Confidential EKM, Justify My Key, Ultimate Control, Google Can't See.

More Design for security and compliance questions