A digital art platform stores high-resolution images in an Amazon S3 bucket. The platform's compliance team requires all stored images to be encrypted at rest. The platform wants a fully managed solution where AWS handles the maintenance, clustering, and scaling of the underlying hardware security modules (HSMs), while the customer manages access policies for the encryption keys. Which AWS service should the platform use to meet this requirement?
- AAWS CloudHSM
- BAWS Secrets Manager
- AWS Key Management Service (AWS KMS)Answer
- DAWS Artifact
Answer
AWS Key Management Service (AWS KMS)
AWS Key Management Service (AWS KMS) is a fully managed service that allows customers to create, manage, and control cryptographic keys. With AWS KMS, AWS manages the underlying hardware security modules (HSMs) for operations such as maintenance, clustering, and scaling, while the customer remains responsible for key access policies and key usage, satisfying the requirement for a fully managed key storage solution.
Step-by-Step Solution
Key Concept
AWS Key Management Service (AWS KMS) vs AWS CloudHSM and Shared Responsibility for Data Protection