Create and obtaining a CMEK key
If you use customer-managed encryption keys (CMEK) to encrypt your Assured Workloads resources, this page shows you how to create and obtain those keys. Learn more about Assured Workloads encryption options.
Before you begin
Choose an encryption strategy.
Create an Assured Workloads folder for a control package that supports your requirements.
Select the project ID for the project that contains your Assured Workloads CMEK keys. If you chose IL4 or CJIS as a control package, then, by default, this project is created for you.
Create the key
To create the CMEK key, do the following:
In the Google Cloud console, go to the Key management page:
Select the Assured Workloads CMEK project. By default, this project ID starts with
cmek-
.Click your key ring.
Click Create Key.
From the What type of key do you want to create? list, select Generated key.
In Key name enter the key name.
From the Protection level list, select Software.
From the Purpose list, select Symmetric encryption/decryption.
From the Rotation period list, select 90 days.
Optional: To add a label, do the following:
- Click Add a label.
- Enter a key in the Key text field.
- Enter a value in the Value text field.
Click Create.
Obtain your CMEK key resource ID
- In Google Cloud console, in the Project Selector, select the project ID
for the project that contains your CMEK keys. By default, if
Assured Workloads creates this project, it prepends the project ID
cmek-
. In Security, go to the Key management page:
Under Key rings, click the key ring name.
In Key ring details, in the Keys tab, click the name of the key.
Click the more_vertMore icon to the right of the key name.
Click Copy Resource Name.
The resource string is formatted as follows:
projects/SECURITY_PROJECT_ID/locations/LOCATION/keyRings/KEY_RING_NAME/cryptoKeys/KEY_NAME
What's next
- Learn about supporting compliance with key management.
- Learn about data encryption and encryption keys.