Professional Cloud ArchitectDesign for security and complianceEasy
A global e-commerce company is deploying a new customer portal on Google Cloud. The company needs to ensure that all customer data at rest in Cloud Storage buckets is encrypted using keys that they control and manage outside of Google Cloud's infrastructure, while still leveraging Google Cloud Storage for object storage. Which encryption key management approach should they choose?
- ACustomer-managed encryption keys (CMEK)
- BCloud Key Management Service (KMS)
- CCustomer-supplied encryption keys (CSEK)
- DGoogle-managed encryption keys
Show answer & explanationAnswer & explanation
Correct answer: C. Customer-supplied encryption keys (CSEK)
Customer-supplied encryption keys (CSEK) allow customers to provide their own encryption keys for data at rest in Cloud Storage, giving them complete control over key management outside of Google Cloud. This directly addresses the requirement for keys controlled and managed externally.
Why the other options are wrong
- A. CMEK uses keys generated and stored in Cloud KMS, which is a Google-managed service, even though the customer controls key usage policies.
- B. Cloud KMS is a managed key management service within Google Cloud, which doesn't meet the requirement of managing keys *outside* Google Cloud's infrastructure.
- D. Google-managed encryption keys are controlled by Google, not the customer.
Customer-Supplied Encryption Keys (CSEK)
CSEK allows users to provide their own encryption keys for data stored in Google Cloud Storage. Google Cloud does not store these keys.
- Keys are generated and managed by the customer outside of Google Cloud.
- The key is supplied with each request to encrypt/decrypt data.
- Provides ultimate control over encryption keys.
Memory trick: Google-Managed, Customer-Managed, Customer-Supplied: Each offers a different level of key control.