Key management covers key generation, secure storage typically in a hardware security module or key management service, access control, rotation schedules, and destruction. Customer-managed keys give the customer control while vendor-managed keys do not.
Encryption provides no protection where keys are accessible alongside the data.
Alternative Names:
Encryption Key Management, Key Lifecycle Management
Why it Matters?
Who holds the keys determines whether a vendor can read customer data, which is the question behind every encryption discussion. Vendor-managed keys mean the vendor can decrypt, which matters for confidentiality analysis and for what the vendor could produce in response to legal process served on it. Customer-managed keys shift that control and are increasingly available, though they add operational responsibility.
Frequently Confused with
Related terms
Frequently asked questions
Why does key custody matter?
What are customer-managed keys?





