Terminology Index

Glossary

1801 terms

Open concept maps

Showing 481-512 of 1801 terms

C
11

Customer Managed Keys

Encryption keys that the customer controls within a cloud key-management service, rather than relying on provider-managed default keys, giving the customer authority over key rotation, access, and revocation for their encrypted data.

By default, cloud providers can manage encryption keys transparently, but customer-managed keys hand control to the customer: they decide rotation, who can use the key, and can revoke it to render data inaccessible. This offers stronger assurance and supports compliance and data-sovereignty needs, at the cost of more responsibility for key lifecycle. It is a step beyond provider defaults and a foundation for stricter models like BYOK and HYOK.

Introduced in: Cloud Security Engineer Fundamentals

Examples

  • Encrypting cloud data with a key the customer controls and can rotate.
  • Revoking a customer-managed key to cut off access to encrypted data.
  • Choosing customer-managed keys to satisfy a compliance requirement.

No related terms linked yet.

D
21