A financial firm requires that encryption keys used for payment data be generated and stored in tamper-resistant hardware. Which solution best satisfies this requirement?
-
A
Software-based key store in the cloud provider's KMS
-
B
Hardware Security Module (HSM)
-
C
Encrypted configuration file on a bastion host
-
D
TPM chip on a virtual machine