{"id":3555,"date":"2024-05-14T15:07:04","date_gmt":"2024-05-14T20:07:04","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/a-cost-effective-encryption-strategy-starts-with-key-management"},"modified":"2024-05-14T15:07:04","modified_gmt":"2024-05-14T20:07:04","slug":"a-cost-effective-encryption-strategy-starts-with-key-management","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/14\/a-cost-effective-encryption-strategy-starts-with-key-management\/","title":{"rendered":"A Cost-Effective Encryption Strategy Starts With Key Management"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0e0016b5ca0459e4\/663e8ef57f4b2a7f8fce70e5\/NicoElNino-digital-lock-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies have a problem with encryption: While many businesses duly encrypt sensitive data, there is no standard strategy for deploying and managing an key-management infrastructure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Every organization needs to make a large number of decisions in designing a key-management policy that works for their business, Karen Reinhardt, principal engineer for cryptographic services at Home Depot, told attendees at the RSA Conference in San Francisco last week. &#8220;One size does not fit all.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some cloud-native startups can manage much, if not all, of their encryption keys in the cloud, while large enterprises with legacy technology likely need a locally hosted system and hybrid infrastructure. Some groups, such as developers, may be able to manage their own infrastructure, while general employees need their keys managed for them. Finally, every company needs to take into account the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/why-the-us-needs-quantum-safe-cryptography-deployed-now\" rel=\"noopener\">post-quantum future<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Reinhardt said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Encryption is a necessary technology for securing data and systems, but there is more to data security than just encrypting the data. Perhaps the most complex part of any encryption infrastructure is managing the keys needed to decrypt data. If the attackers has access to the keys, they have access to the encrypted data; defenders who lose access to the keys lose access to data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Reinhardt outlined five things enterprise security teams should consider to &#8220;keep everybody from putting their <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/database-encryption-depends-on-effective-key-management\" rel=\"noopener\">proverbial key under their doormat<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which is a problem I see all the time.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Data Availability Requires Decryption\">1. Data Availability Requires Decryption<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first lesson for companies is that encryption keys are critical \u2014 perhaps more critical than proper encryption. Data is unusable if you can&#8217;t decrypt it, so knowing where the decryption keys are is often much more important than knowing the location of the encryption keys, said Reinhardt.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations should always have a controlled archive of decryption keys, she said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The thing about identity is you can always replace it \u2014&nbsp;okay, you lost your driver&#8217;s license, let me get you a new one,&#8221; Reinhardt said. &#8220;But if you have data that&#8217;s encrypted with something, you can only decrypt it one way.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"2. 'Encrypt Everything' Might Not Be Worth It\">2. &#8216;Encrypt Everything&#8217; Might Not Be Worth It<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security controls continue to be expensive to implement, and encryption is no exception. Companies need to measure the cost of creating and managing encryption infrastructure against the cost of a breach to find their &#8220;optimum security at minimum cost,&#8221; Reinhardt said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Security does you no good if you bankrupt your company,&#8221; she said. &#8220;Stronger controls almost always equals more money, so [while I&#8217;m] not actually against &#8216;encrypt everything,&#8217; it&#8217;s a lot of money, a lot of processing, a lot of extra memory \u2014&nbsp;so &#8216;m more of a fan of focus on what really needs to be kept secret.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Cloud Changes Everything, But Gives You Options\">3. Cloud Changes Everything, But Gives You Options<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies moving more of their infrastructure to cloud services and platform are already trying to control data sprawl \u2014&nbsp;cloud-native <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/drive-pervasive-encryption-boosts-key-management\" rel=\"noopener\">key management<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> adding key sprawl to the equation as well. Companies need to take stock of not only their critical data \u2014 what needs to be encrypted \u2014 but also how each cloud service manages its keys and other secrets and whether the company can centralize management to increase control.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Where are the keys? Well, a lot of times, they&#8217;re in a local key store sitting on a system, and in other cases, they can be in a remote store,&#8221; she said. &#8220;They could be anywhere these days \u2014 on-prem, in the cloud, [hosted by] a vendor, or in your own managed cloud.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"4. Legacy Integration Remains a Headache\">4. Legacy Integration Remains a Headache<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Smaller companies with just starting with key management can create greenfield key management and take advantage of the latest technologies to simplifying their infrastructure and strengthen control over their data. Yet, large companies who already have a variety of key management technologies in place will have to support legacy applications and databases.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If you&#8217;re a fairly new company with a greenfield implementation, you might not have the same integration requirements of a company that&#8217;s been around for 100 years,&#8221; she said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet, cloud-based encryption infrastructure, such as hardware security modules \u2014&nbsp;secure storage for key data and operations \u2014 can help make implementation simpler and make integration with legacy technology easier.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"5. Post Quantum Means Every Asymmetric Key Must Be Replaced\">5. Post Quantum Means Every Asymmetric Key Must Be Replaced<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, every company needs to consider the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/are-you-planning-for-the-quantum-transhumanist-threat-\" rel=\"noopener\">post-quantum future<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and make sure that their key infrastructure can generate quantum-safe keys. As <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-boards-prepare-quantum-computers\" rel=\"noopener\">quantum-computing technology<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> advances, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/nist-publishes-first-draft-standards-for-post-quantum-cryptography\" rel=\"noopener\">public-key encryption will need to evolve<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and use stronger keys generated by more modern algorithms.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Post-quantum means every asymmetric key has to be replaced, so you need to know where they are,&#8221; she said. &#8220;And that is the big advantage of a key management system \u2014 or any sort of centralized management system \u2014&nbsp;it will make finding your keys, and rotating them, much easier.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/a-cost-effective-encryption-strategy-starts-with-key-management\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Companies have a problem with encryption: While many businesses duly<\/p>\n","protected":false},"author":12,"featured_media":3556,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=1600%2C900&ssl=1",1600,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=1600%2C900&ssl=1",1600,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/a-cost-effective-encryption-strategy-starts-with-key-management.jpg?fit=1600%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3555"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3555\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3556"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}