October 2019
Intermediate to advanced
520 pages
13h 5m
English
The key that's used to encrypt a piece of data is known as a Data Encryption Key (DEK). These keys are then wrapped by a Key Encryption Key (KEK). KEKs are stored and managed within Google Cloud's KMS, allowing Google to track and control access from a central point. It isn't possible to export your KEK from KMS, and all of the encryption and decryption of keys must be within KMS. In addition to this, KMS-held keys are backed up for disaster recovery purposes. KEKs are also rotated over a period of time, meaning that a new key is created. This allows GCP to comply with certain regulations, such as Payment Card Industry Data Security Standard (PCI DSS), and is considered a security best practice. ...
Read now
Unlock full access