Trending...
- Phinge Exposes Massive AI Security Risks, Claiming Its Patented Hardware-Verified Architecture Is The Only Safeguard Against Surveillance Capitalism
- On the Boards: Proform Builds Announce New Construction in Alki, Seattle
- Phinge's Netverse: Reclaiming the Digital Frontier For Everyone Through CEO Robert DeMaio's Vision of a True App-less, User Data Sovereign World
SEATTLE--(BUSINESS WIRE)--The Cloud Security Alliance (CSA), the world's leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released Cloud Key Management System with External Origin Key. Written by the Cloud Key Management Working Group to help organizations optimize such business outcomes as security, agility, cost, and compliance, the paper provides general guidance for choosing, planning, and deploying cloud-native key management systems (KMS) in cases where organizations either want to or must import key material (e.g., keys, vaults, secrets, policies) from an external source.
"A cloud service provider's KMS often has strong ties to its other cloud services, and this same cloud-native KMS using EKO can be used with a customer's on-premises technologies and cloud services from other providers. Unsurprisingly, integrating a cloud KMS with an organization's assets spanning traditional private data centers, as well as private and public cloud services in various geographic locations presents a host of challenges," said Paul Rich, co-chair of the Cloud Key Management Working Group and one of the paper's authors. "It's our hope that after reading this document, program and project managers who have been tasked with leading their organization through the selection, planning, and deployment stages of cloud-native KMS using EKO will be able map considerations to their organization."
More on Washingtoner
The guidance addresses the technical, operational, legal, regulatory, and financial aspects of leveraging a cloud-native KMS using external key origin (EKO) for each of the three stages of the lifecycle (choosing, planning, and deploying). Each aspect is broken down into further considerations and their accompanying justifications. Because cloud-native key management systems using EKO are relatively new, there isn't a large repository of best practices from which to draw. This guidance, therefore, combines best practices drawn from experience with traditional key management systems, cloud services in general, and cloud-native key management systems.
For further reading, Key Management in Cloud Services: Understanding Encryption's Desired Outcomes and Limitations provides the foundation for the choice of cloud KMS pattern and general guidance for using KMS whether the KMS is native to a cloud platform, external, self-operated, or yet another cloud service. Additionally, Recommendations for Adopting a Cloud-Native Key Management System provides more specific guidance for choosing, planning, and deploying cloud-native key management systems.
The Cloud Key Management Working Group aims to facilitate the standards for seamless integration between cloud service providers and key broker services. Those interested in participating in future research and initiatives involving cloud key management are invited to join the working group.
More on Washingtoner
Download Cloud Key Management System with External Origin Key now.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
Contacts
Media Contacts
Kristina Rundquist for the CSA
kristina@zagcommunications.com
"A cloud service provider's KMS often has strong ties to its other cloud services, and this same cloud-native KMS using EKO can be used with a customer's on-premises technologies and cloud services from other providers. Unsurprisingly, integrating a cloud KMS with an organization's assets spanning traditional private data centers, as well as private and public cloud services in various geographic locations presents a host of challenges," said Paul Rich, co-chair of the Cloud Key Management Working Group and one of the paper's authors. "It's our hope that after reading this document, program and project managers who have been tasked with leading their organization through the selection, planning, and deployment stages of cloud-native KMS using EKO will be able map considerations to their organization."
More on Washingtoner
- Gravity Payments and Suno Software Partner to Simplify Payments for Independent Hearing Clinics
- Where Do Missouri Plane Crashes Really Happen? Not Where You'd Think
- Spokane: Female Arrested After Homeowners Caught Her on Property of Burned Home
- SPD Detectives are Investigating a Suspicious Death in West Spokane
- LCC Asia Pacific Sponsors CubeSatPlus 2026 at UNSW Sydney
The guidance addresses the technical, operational, legal, regulatory, and financial aspects of leveraging a cloud-native KMS using external key origin (EKO) for each of the three stages of the lifecycle (choosing, planning, and deploying). Each aspect is broken down into further considerations and their accompanying justifications. Because cloud-native key management systems using EKO are relatively new, there isn't a large repository of best practices from which to draw. This guidance, therefore, combines best practices drawn from experience with traditional key management systems, cloud services in general, and cloud-native key management systems.
For further reading, Key Management in Cloud Services: Understanding Encryption's Desired Outcomes and Limitations provides the foundation for the choice of cloud KMS pattern and general guidance for using KMS whether the KMS is native to a cloud platform, external, self-operated, or yet another cloud service. Additionally, Recommendations for Adopting a Cloud-Native Key Management System provides more specific guidance for choosing, planning, and deploying cloud-native key management systems.
The Cloud Key Management Working Group aims to facilitate the standards for seamless integration between cloud service providers and key broker services. Those interested in participating in future research and initiatives involving cloud key management are invited to join the working group.
More on Washingtoner
- Spokane: City Council Approves Mayor's Orders for Declaration of Emergency
- Real Estate Syndication Attorney Tilden Moschetti Releases The Real Estate Private Equity Blueprint
- 5X Gross Margin Improvement to Beat EPS Consensus; $54.6 Million 10-Year Contract Award Puts Cybersecurity Leader on Path to a $30 Million Run Rate
- Independent Colbert Packaging Thrives Amid Industrywide Consolidation
- Free Commercial Glass Estimating and Code Compliance Tools Launched by Landmark Construction - The Leading Glass Company in Los Angeles
Download Cloud Key Management System with External Origin Key now.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
Contacts
Media Contacts
Kristina Rundquist for the CSA
kristina@zagcommunications.com
0 Comments
Latest on Washingtoner
- Space Ambitions Expanding as New Testing Builds on NASA Results and Targets MEO, GEO and Next-Generation Orbital Markets: Ascent Solar Technologies
- FDA Path Clears, Manufacturing Ramps Up + $22.3 Million Strengthens the Balance Sheet; Inflection Point for NRx Pharmaceuticals (N A S D A Q: NRXP)
- Buy Retatrutide Research Peptide: Why Reta Is Getting So Much Attention
- Stage 2 Burn Ban Order in Effect Across Tacoma
- San Diego Attorney Anthony Z. Vargas Narrows Practice to Employment Law, Representing Employees Only
- Spokane: Additional PPE Kits Available Tuesday and Thursday
- Solid Earth Introduces RealtyID, a Universal Identity Spine for the Real Estate Industry
- BlazeHive's AI SEO Agent Outranks Human Writers on 500+ Google Top-3 Results in 5 Months, on Autopilot
- Cracking the Immortality Code: A Human / AI Long-Term Collaboration Working to Achieve Immortality
- On the Boards: Proform Builds Announce New Construction in Alki, Seattle
- On the Boards: Proform Builds Announce New Construction in Gig Harbor
- Phinge Exposes Massive AI Security Risks, Claiming Its Patented Hardware-Verified Architecture Is The Only Safeguard Against Surveillance Capitalism
- Phinge & CEO Robert DeMaio Publicly Declare Cash Settlements or Judgments Alone Cannot & Will Not Remedy the Deep Public Harm of Infringing Its IP
- Dana Flanagan Expands the Authority Architect, Bringing a Nontraditional Approach to Executive Authority, Strategic Access and Business Growth
- Phinge's Netverse: Reclaiming the Digital Frontier For Everyone Through CEO Robert DeMaio's Vision of a True App-less, User Data Sovereign World
- DuraFast Label Company Launches Seiko SLP850 2" Thermal Printer with Free Label Promotion
- Scientific Figure Releases Free Layout Template Libraries for Graphical Abstracts and Research Posters
- Permian Museum announces the addition of an Ancient Alien Artifacts photo gallery
- VISION 2050 Award for Historic Tideflats Subarea Plan Presented by Puget Sound Regional Council at Tacoma City Council Meeting
- The Golden Jazz Fest Shuttle Returns for 2026