nerdexam
CSA

CCSK · Question #158

ENISA: Because it is practically impossible to process data in encrypted form, customers should have the following expectation of cloud providers:

The correct answer is C. Provider must be highly trustworthy and have compensating controls to protect customer data. Encrypting data at rest is not difficult, but despite recent advances in homomorphic encryption (27), there is little prospect of any commercial system being able to maintain this encryption during processing. In one article, Bruce Schneier estimates that performing a web…

Cloud Data Security

Question

ENISA: Because it is practically impossible to process data in encrypted form, customers should have the following expectation of cloud providers:

Options

  • AProvider should be PCI compliant
  • BProvider should immediately notify customer whenever data is in plaintext form
  • CProvider must be highly trustworthy and have compensating controls to protect customer data
  • DProvider should always manage customer encryption keys with hardware security module (HSM)
  • EHomomorphic encryption should be implemented where necessary

How the community answered

(29 responses)
  • A
    3% (1)
  • C
    79% (23)
  • D
    7% (2)
  • E
    10% (3)

Explanation

Encrypting data at rest is not difficult, but despite recent advances in homomorphic encryption (27), there is little prospect of any commercial system being able to maintain this encryption during processing. In one article, Bruce Schneier estimates that performing a web search with encrypted keywords -- a perfectly reasonable simple application of this algorithm -- would increase the amount of computing time by about a trillion (28). This means that for a long time to come, cloud customers doing anything other than storing data in the cloud must trust the cloud

Topics

#data encryption#plaintext exposure#cloud trust#compensating controls

Community Discussion

No community discussion yet for this question.

Full CCSK Practice