We're starting to use some SaaS providers, including Office365 Exchange Online, that allow bring-your-own-key or hold-your-own-key for encrypting data at rest. These are, to my understanding, simply one key per provider, not something per-user or per-item.
What are the things I need to consider for deciding how to manage the keys? If it's under 6 services, can I just print 2 copies of the keys and store them in different locations, plus a copy in our password management system? At what point does an organization start to consider a key management solution?
0 Answers