An enterprise financial institution is designing a storage architecture for high-throughput transaction databases hosted on a Storage Area Network (SAN). Security requirements specify that bulk data at rest must be encrypted at the drive hardware level to eliminate host CPU performance degradation, and all storage keys must be centrally managed using a standardized network protocol integrated with a Hardware Security Module (HSM). Which of the following storage security solutions best meets these requirements?
- Self-Encrypting Drives (SEDs) managed via Key Management Interoperability Protocol (KMIP) connected to an enterprise HSMCevap
- BHost-based software Full Disk Encryption (FDE) utilizing local Trusted Platform Modules (TPMs) for volume key storage
- CBulk volume encryption using asymmetric RSA-4096 keys generated natively on host operating systems
- DInline network Data Loss Prevention (DLP) appliances positioned between host bus adapters and SAN fabric switches
Cevap
Self-Encrypting Drives (SEDs) managed via Key Management Interoperability Protocol (KMIP) connected to an enterprise HSM
Self-Encrypting Drives (SEDs) utilize dedicated, on-board cryptoprocessors to encrypt and decrypt data at wire speed without burdening host system CPU cycles. Using the Key Management Interoperability Protocol (KMIP) enables seamless integration between storage hardware controllers and a dedicated enterprise Hardware Security Module (HSM) for automated key lifecycle management.
Adım Adım Çözüm
Anahtar Kavram
Hardware-based storage encryption with centralized key management protocols
Tahmini Süre:1m 30s