Professional Cloud ArchitectDesign for security and complianceMedium
A healthcare provider is building a new application on Google Cloud to store electronic health records (EHR). Due to strict regulatory requirements (e.g., HIPAA), they must ensure that all data at rest and in transit is encrypted, and that the encryption keys are managed in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Google Cloud service should be used to meet these key management requirements?
- ACloud KMS
- BCustomer-Supplied Encryption Keys (CSEK)
- CCloud HSM
- DSecret Manager
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud HSM
Cloud HSM is the only Google Cloud service that provides a FIPS 140-2 Level 3 validated hardware security module for cryptographic key management, directly addressing the strict regulatory requirement. Cloud KMS offers key management but doesn't guarantee FIPS 140-2 Level 3 HSMs for customer keys. Secret Manager is for secrets, not cryptographic keys. CSEK uses customer-provided keys, but Google doesn't manage their FIPS validation level.
Why the other options are wrong
- A. Cloud KMS provides key management but does not guarantee that customer-managed keys will reside in FIPS 140-2 Level 3 validated HSMs by default, which is a specific requirement here.
- B. Customer-Supplied Encryption Keys (CSEK) means the customer provides the key, but Google does not manage the FIPS validation level of the customer's key source or how it is used within Google Cloud to meet this specific requirement.
- D. Secret Manager is used for managing API keys, passwords, and other secrets, not for cryptographic keys that require FIPS 140-2 Level 3 validation.
Cloud HSM (Hardware Security Module)
A Google Cloud service that provides a fully managed cloud-hosted hardware security module (HSM) for generating and storing cryptographic keys.
- Offers FIPS 140-2 Level 3 validated HSMs.
- Provides enhanced security for sensitive cryptographic operations.
- Integrates with Cloud KMS for key management operations.
Memory trick: HSM for FIPS, Regulatory Trips, Secure Key Ships.