Professional Cloud ArchitectDesign for security and complianceMedium
A global media conglomerate is migrating its archival video content, including highly sensitive unreleased footage and proprietary intellectual property, to Google Cloud Storage. The company has a strict compliance requirement to demonstrate exclusive control over the encryption keys for this sensitive data. They also need to ensure that the data remains accessible to authorized internal teams for editing and distribution workflows. Which encryption key management solution should be implemented to meet these requirements?
- ACustomer-managed encryption keys (CMEK) stored in Cloud KMS for the sensitive data buckets.
- BCustomer-supplied encryption keys (CSEK) for the sensitive data buckets.
- CCloud HSM with keys generated and managed entirely within the HSM for all Cloud Storage buckets.
- DGoogle-managed encryption keys (GMEK) for all Cloud Storage buckets.
Show answer & explanationAnswer & explanation
Correct answer: B. Customer-supplied encryption keys (CSEK) for the sensitive data buckets.
Customer-supplied encryption keys (CSEK) allow the customer to generate and manage their own encryption keys entirely outside of Google Cloud, providing exclusive control. This meets the strict compliance requirement for demonstrating exclusive control over the encryption keys, while still allowing data to be stored in Cloud Storage.
Why the other options are wrong
- A. CMEK keys are managed by Cloud KMS within Google Cloud, which does not provide exclusive customer control over the keys outside of Google's infrastructure.
- C. Cloud HSM keys are managed within Google Cloud's HSM, which, while secure, does not provide the 'exclusive control' over keys generated and managed entirely outside Google Cloud as required by the scenario.
- D. GMEK provides no customer control over the keys, failing the compliance requirement.
Customer-Supplied Encryption Keys (CSEK)
CSEK is a Google Cloud feature that allows users to provide their own encryption keys to encrypt data at rest in services like Cloud Storage. The keys are managed entirely by the customer.
- Customer generates and manages the encryption key.
- Key is provided to Google Cloud during data operations (upload/download).
- Google Cloud never stores the key persistently.
- Provides the highest level of customer control over encryption keys.
Memory trick: Secure Your Data: Keys for Every Need!