KMS vs HSM Flashcards
1
Q
What is AWS KMS (Key Management System)?
A
It’s a regional service that is associated with the Amazon System manager that allows for key encryption and decryption.
It’s regional because a key generate for Virginia won’t work anywhere else.
2
Q
What is CMKs?
A
It’s the Customer Master Keys. I.E the keys that were used for encryption/decryption.
3
Q
What is CloudHSM?
A
It works the same way as KMS but it has a dedicated hardware security module. It can also provides for single tenant, or multi-AZ cluster,
4
Q
What is the Security accordance that CloudHSM provides?
A
FIPS 140-2 level 3