Skip to main content
Guidance

Cloud security guidance

How to choose, configure and use cloud services securely.

Page 7 of 29

Choosing and configuring a KMS for secure key management in the cloud

Identifying secure cloud key management service (KMS), and how to use them to encrypt data securely.

Key management services (KMSs) are a common component in cloud services. These are typically used to generate, store, use and destroy cryptographic key material. When designed, operated and used well, a cloud KMS provides functionality for secure storage of encryption keys and use of encryption and digital signature algorithms.

A KMS will typically be a foundational component of the cloud service itself. In cloud platforms, where customers deploy their own applications, the KMS is often made available to customers to secure the services they have built on the cloud platform. For example, you might use the KMS to encrypt database passwords or virtual machine disk images. This is covered in more detail below.

Effective data encryption relies on secure key management, so you should make full use of a cloud provider’s KMS if it meets your needs and meets the requirements for a secure KMS given below.

If you are not satisfied that your service’s KMS offers adequate protection, you should look for a service that is better suited to your security needs.

Public key infrastructure (PKI)

This guidance explains how to identify a secure cloud KMS and how to use it to encrypt data securely. If you need a public key infrastructure (PKI) in the cloud, you should use a managed PKI service, assessed against the NCSC’s PKI guidance. The PKI should use the KMS to store and protect private keys. You should avoid building a PKI yourself. As described in the guidance, you should also be certain that a PKI is the best solution to the problem. In a cloud service, using keys protected and managed by a KMS, alongside robust identity and access management procedures, will often be a better alternative.




Published

Reviewed

Version

2.1