Google Cloud プロジェクト内の保存データの暗号化に使用する鍵を、 Google Cloudのデフォルトの暗号化で行われるよりも詳細に制御する必要がある場合は、 Google Cloud サービスで、Cloud KMS 内でお客様によって管理されている暗号鍵を使用してデータを保護するための機能を使用できます。こうした暗号鍵は「顧客管理の暗号鍵(CMEK)」と呼ばれます。
[[["わかりやすい","easyToUnderstand","thumb-up"],["問題の解決に役立った","solvedMyProblem","thumb-up"],["その他","otherUp","thumb-up"]],[["わかりにくい","hardToUnderstand","thumb-down"],["情報またはサンプルコードが不正確","incorrectInformationOrSampleCode","thumb-down"],["必要な情報 / サンプルがない","missingTheInformationSamplesINeed","thumb-down"],["翻訳に関する問題","translationIssue","thumb-down"],["その他","otherDown","thumb-down"]],["最終更新日 2025-03-06 UTC。"],[[["Google Cloud employs default encryption for data both in transit, using TLS, and at rest, ensuring data protection."],["Customers can utilize Cloud Key Management Service (Cloud KMS) to create, manage, rotate, and destroy their own encryption keys, known as customer-managed encryption keys (CMEK), for enhanced control over data at rest."],["Assured Workloads offers the option to deploy a CMEK project alongside a resources project for specific control packages, allowing customers more control over data encryption."],["Google-owned and managed encryption keys, which are FIPS-140-2 compliant, are available as a default option and can support most control packages, but it is recommended that you choose between them or CMEK keys before creating your Assured Workloads folder."],["Cloud KMS provides detailed information and guides on managing CMEK, including tutorials and quickstarts for users seeking to implement customer-managed encryption."]]],[]]