Professional Cloud ArchitectDesign for security and complianceMedium

A healthcare provider is deploying a new patient records application on Google Cloud. The application will store highly sensitive protected health information (PHI) in BigQuery datasets and needs to ensure that only specific individuals from the 'Medical_Staff' group can decrypt and access this data. They also need to ensure that the keys used for encryption are automatically rotated every 90 days. Which Google Cloud service should be configured to manage these encryption keys and access policies?

  1. ACloud Key Management Service (KMS) with CMEK
  2. BCustomer-supplied encryption keys (CSEK)
  3. CCloud HSM
  4. DGoogle-managed encryption keys
Show answer & explanation

Correct answer: A. Cloud Key Management Service (KMS) with CMEK

Cloud KMS with Customer-Managed Encryption Keys (CMEK) allows the customer to control the encryption keys used for services like BigQuery. It integrates with IAM to restrict access to specific groups (Medical_Staff) and provides automated key rotation, directly fulfilling all requirements.

Why the other options are wrong

  • B. CSEK requires manual key management and doesn't offer automated rotation or direct IAM integration for key access within Google Cloud.
  • C. Cloud HSM provides FIPS 140-2 Level 3 hardware security but is typically overkill if the primary need is IAM integration, automated rotation, and customer control over keys, which CMEK already offers within Cloud KMS.
  • D. Google-managed keys are fully controlled by Google and do not allow the customer to define specific group access for key usage or control rotation schedules.

Customer-Managed Encryption Keys (CMEK)

CMEK allows customers to generate, use, and manage cryptographic keys within Cloud KMS for data encryption in supported Google Cloud services.

  • Keys are stored and managed in Cloud KMS.
  • Customer controls key access via IAM policies.
  • Supports automated key rotation.

Memory trick: CMEK uses KMS to let YOU manage keys, group access, and rotations.

More Design for security and compliance questions