CCSK · Question #158
ENISA: Because it is practically impossible to process data in encrypted form, customers should have the following expectation of cloud providers:
The correct answer is C. Provider must be highly trustworthy and have compensating controls to protect customer data. Encrypting data at rest is not difficult, but despite recent advances in homomorphic encryption (27), there is little prospect of any commercial system being able to maintain this encryption during processing. In one article, Bruce Schneier estimates that performing a web…
Question
ENISA: Because it is practically impossible to process data in encrypted form, customers should have the following expectation of cloud providers:
Options
- AProvider should be PCI compliant
- BProvider should immediately notify customer whenever data is in plaintext form
- CProvider must be highly trustworthy and have compensating controls to protect customer data
- DProvider should always manage customer encryption keys with hardware security module (HSM)
- EHomomorphic encryption should be implemented where necessary
How the community answered
(29 responses)- A3% (1)
- C79% (23)
- D7% (2)
- E10% (3)
Explanation
Encrypting data at rest is not difficult, but despite recent advances in homomorphic encryption (27), there is little prospect of any commercial system being able to maintain this encryption during processing. In one article, Bruce Schneier estimates that performing a web search with encrypted keywords -- a perfectly reasonable simple application of this algorithm -- would increase the amount of computing time by about a trillion (28). This means that for a long time to come, cloud customers doing anything other than storing data in the cloud must trust the cloud
Topics
Community Discussion
No community discussion yet for this question.