← Back to list

Google-managed encryption keys (KMS) and Customer-managed encryption keys (CMEK)

Google-managed encryption keys (KMS):

Harsh Kumar · 2023-12-31 06:56 · 4 claps · 1.9 min read
#gcp #encryption #encryption-key #managed-services
Open on Medium ↗
Wiki topics: ☁️ · DevOps & Cloud 🔒 · Cybersecurity

Google-managed encryption keys (KMS) and Customer-managed encryption keys (CMEK)

Photo by Mika Baumeister on Unsplash

Photo by Mika Baumeister on Unsplash

Google-managed encryption keys (KMS):

  • Definition: Encryption keys that are created, managed, and stored entirely by Google within its infrastructure.
  • Control: Google has full control over key management operations, including creation, rotation, access, and deletion.
  • User involvement: No setup or configuration required by users. Enabled by default for most GCP services that support encryption.
  • Visibility: Users cannot directly view or manage these keys.
  • Compliance: May not meet the strictest compliance requirements where full key control is mandated.

Customer-managed encryption keys (CMEK):

  • Definition: Encryption keys that are created and managed by customers using Google Cloud Key Management Service (Cloud KMS).
  • Control: Customers have full control over key management, including creation, rotation, access, storage location, and deletion.
  • User involvement: Requires setup and configuration within Cloud KMS.
  • Visibility: Customers have full visibility and control over their keys.
  • Compliance: Can meet stricter compliance requirements due to customer control over keys.

Here’s a comprehensive comparison of Google-managed encryption keys (KMS) and customer-managed encryption keys (CMEK) within Google Cloud Platform (GCP):

Key Management:

Control and Compliance:

Ease of Use and Cost:

Best Practices for Choosing:

Use Google-managed keys (KMS):

  • When you need a simple and cost-effective encryption solution.
  • When you trust Google to manage your keys securely.
  • When you don’t have strict compliance requirements that mandate full control over keys.

Use customer-managed keys (CMEK):

  • When you need more control over key management and access.
  • When you have strict compliance requirements that necessitate full key control.
  • When you need to meet data residency or locality requirements.
  • When you want to restrict Google’s access to your data.

Additional Considerations:

  • CMEK is not available for all GCP services. Check the list of supported services.
  • Using CMEK can add complexity to your key management processes.
  • It’s essential to have a robust key management strategy in place, regardless of the key type you choose.

메타데이터
post_id
5d38f482fbd5
slug
google-managed-encryption-keys-kms-and-customer-managed-encryption-keys-cmek-5d38f482fbd5
url
https://medium.com/@h369kr/google-managed-encryption-keys-kms-and-customer-managed-encryption-keys-cmek-5d38f482fbd5
canonical_url
https://medium.com/@h369kr/google-managed-encryption-keys-kms-and-customer-managed-encryption-keys-cmek-5d38f482fbd5
author_url
https://medium.com/@h369kr
status
ok
fetched_at
2026-06-28 10:39:35