Question 1
Q1A financial services firm is migrating its on-premises data warehouse to a hybrid cloud model. To comply with industry regulations, the firm must ensure that data encryption keys are never accessible to the cloud provider. The security team has mandated a solution where key generation, storage, and management remain entirely within the firm's on-premises hardware security module (HSM). Which security control mechanism meets this stringent requirement?
Show answer & explanation
Correct answer: C
Hold Your Own Key (HYOK) is the correct model for this scenario. It allows an organization to use its on-premises key management infrastructure, such as an HSM, to generate and manage encryption keys. The cloud service uses these keys to encrypt and decrypt data but never has access to the keys themselves, fulfilling the strict compliance requirement. Cloud provider-managed keys and keys in a cloud vault both involve the provider having some level of access or control, which is forbidden by the requirements. Encryption in use protects data during processing, which is different from key management.