Customer-Managed Keys

Complete the full lesson to earn 25 points — 50 with Pro

Work through each section, then tap “Mark as Complete” on the last one.

Section 1 of 10

✦ Skip the page breaks, the wait, and see fewer ads — read each lesson on a single page with Pro

Lesson: Mastering Customer-Managed Keys (CMK)

Introduction: Taking Control of Your Data Security

In the modern landscape of cloud computing, security is no longer a "one-size-fits-all" proposition. For many years, organizations relied on provider-managed encryption, where the cloud service provider (CSP) handled the lifecycle of encryption keys. While convenient, this model leaves a critical gap in control: if the provider manages the keys, they technically have the capability to access your data, even if their policies prevent them from doing so. This is where Customer-Managed Keys (CMK) come into play.

Customer-Managed Keys represent a shift in the security paradigm, moving the responsibility and authority of key lifecycle management from the cloud provider to the data owner. By implementing CMK, you retain the ability to create, rotate, disable, and delete the keys used to encrypt your sensitive data. This level of control is essential for organizations operating in highly regulated industries—such as healthcare, finance, and government—where data sovereignty and strict compliance mandates are not just recommended, but legally required.

Understanding CMK is not merely about checking a compliance box; it is about building a defense-in-depth strategy that prevents unauthorized access. Even if a bad actor gains access to your storage environment, without the corresponding key—which you control and monitor—the data remains encrypted and useless to them. This lesson will guide you through the technical, operational, and strategic aspects of managing your own encryption keys in a cloud environment.


Section 1 of 10

Reach the last section to complete this lesson and earn points — you're on section 1 of 10.