ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A company is implementing a new cloud-based application that processes sensitive customer data. To ensure data at rest is protected, they decide to use full disk encryption on the virtual machines. Which key management practice is crucial for maintaining the security of these encrypted disks, especially during operational changes or disaster recovery scenarios?
- AStoring all encryption keys directly on the encrypted virtual machines.
- BSharing encryption keys with all system administrators via email for easy access.
- CUsing a Hardware Security Module (HSM) for key generation, storage, and management.
- DHardcoding encryption keys within the application's source code.
Show answer & explanationAnswer & explanation
Correct answer: C. Using a Hardware Security Module (HSM) for key generation, storage, and management.
A Hardware Security Module (HSM) provides a highly secure, tamper-resistant environment for generating, storing, and managing cryptographic keys. This offloads key management from less secure software layers and ensures keys are protected even if the underlying virtual machine or host is compromised.
Why the other options are wrong
- A. Storing keys on the encrypted VM defeats the purpose of encryption if the VM is compromised.
- B. Sharing keys via email is highly insecure and introduces significant risk of compromise.
- D. Hardcoding keys exposes them directly in the application code, making them easily discoverable and unmanageable.
Hardware Security Module (HSM)
A physical computing device that safeguards and manages digital keys for strong authentication and provides cryptoprocessing.
- Provides a tamper-resistant environment for cryptographic operations.
- Generates, stores, and protects cryptographic keys.
- Used in highly secure environments for critical key management.
Memory trick: HSM Hides Keys Securely.