Skip to main content

Mythbusting cloud key management services

Why trying to avoid trusting the KMS doesn't make sense (and other common misconceptions).

The NCSC’s recently-updated cloud security guidance includes a new section on how to configure and use a KMS for secure key management in the cloud. It covers how data should be encrypted at rest, and what you should expect from a key management service (KMS).

While we were writing the guidance, we identified some common myths about key management in the cloud. This blog explores some of these myths, and explains how a KMS can help secure the data you store in the cloud.






Written by

Jamie H Principal Security Researcher