Terminology Index
Glossary
1801 terms
Showing 481-512 of 1801 terms
Customer Managed Keys
Encryption keys that the customer controls within a cloud key-management service, rather than relying on provider-managed default keys, giving the customer authority over key rotation, access, and revocation for their encrypted data.
By default, cloud providers can manage encryption keys transparently, but customer-managed keys hand control to the customer: they decide rotation, who can use the key, and can revoke it to render data inaccessible. This offers stronger assurance and supports compliance and data-sovereignty needs, at the cost of more responsibility for key lifecycle. It is a step beyond provider defaults and a foundation for stricter models like BYOK and HYOK.
Introduced in: Cloud Security Engineer Fundamentals
Examples
- Encrypting cloud data with a key the customer controls and can rotate.
- Revoking a customer-managed key to cut off access to encrypted data.
- Choosing customer-managed keys to satisfy a compliance requirement.
No related terms linked yet.
