A healthcare provider must store patient records in Cloud Storage. Regulatory requirements mandate that the encryption keys protecting the data must reside exclusively within the company's on-premises Hardware Security Module (HSM) and never be stored inside Google Cloud, while allowing Google Cloud Storage to perform automated encryption and decryption operations. Which key management solution should you select?
- Customer-Managed Encryption Keys (CMEK) integrated with Cloud External Key Manager (Cloud EKM)Answer
- BCustomer-Supplied Encryption Keys (CSEK) managed via primitive Owner IAM roles
- CGoogle-default encryption guarded by VPC Service Controls
- DCustomer-Supplied Encryption Keys (CSEK) with automated key rotation configured in Cloud KMS
Answer
Customer-Managed Encryption Keys (CMEK) integrated with Cloud External Key Manager (Cloud EKM)
Cloud External Key Manager (Cloud EKM) enables GCP services to use Customer-Managed Encryption Keys (CMEK) where the actual key material resides outside Google Cloud in an on-premises or external Key Management Service / HSM.
Step-by-Step Solution
Key Concept
Data Encryption at Rest, in Transit, and Key Management (KMS/CMEK/CSEK)