Professional Cloud ArchitectDesign for security and complianceHard
A global financial institution is migrating its core banking applications to Google Cloud. They have a strict regulatory requirement to encrypt all data at rest using FIPS 140-2 Level 3 validated hardware security modules (HSMs). The solution must ensure that the encryption keys are never exposed outside of the HSMs. Which Google Cloud service should they use to meet this specific compliance requirement?
- ACustomer-supplied encryption keys (CSEK)
- BCloud Key Management Service (KMS)
- CCustomer-managed encryption keys (CMEK)
- DCloud HSM
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud HSM
Cloud HSM is a fully managed cloud-hosted hardware security module (HSM) service that allows customers to generate and store cryptographic keys in FIPS 140-2 Level 3 validated HSMs. This directly addresses the strict regulatory requirement for FIPS 140-2 Level 3 and ensures keys are never exposed outside the HSMs.
Why the other options are wrong
- A. CSEK involves the customer supplying keys, but Google Cloud does not store these keys in a FIPS 140-2 Level 3 HSM, nor does it manage the HSM for the customer-supplied key.
- B. Cloud KMS provides cryptographic operations but does not guarantee FIPS 140-2 Level 3 *hardware* validation for key storage by default, nor that keys are never exposed outside an HSM.
- C. CMEK uses Cloud KMS, inheriting its properties, and thus doesn't inherently meet the FIPS 140-2 Level 3 *hardware* requirement for key storage.
Cloud HSM
Cloud HSM is a fully managed hardware security module (HSM) service that allows you to host encryption keys and perform cryptographic operations in FIPS 140-2 Level 3 validated HSMs.
- Provides FIPS 140-2 Level 3 validated hardware.
- Keys are generated and stored exclusively within the HSM.
- Integrated with Cloud KMS for management and access control.
Memory trick: FIPS 140-2 Level 3 means a strong, verified hardware box for your keys, and that's Cloud HSM.