A financial services firm requires that encryption keys used for Cloud Storage buckets are rotated every 90 days and never leave their HSM. Which solution satisfies this?
-
A
Google-managed encryption keys with automatic rotation
-
B
Customer-managed encryption keys (CMEK) via Cloud KMS with rotation schedule
-
C
Customer-supplied encryption keys (CSEK) stored in Cloud HSM
-
D
Cloud External Key Manager (EKM) with keys hosted in their on-premises HSM