From the course: AWS Certified Security - Specialty (SCS-C03) Cert Prep
Unlock this course with a free trial
Join today to access over 25,600 courses taught by industry experts.
AWS CloudHSM - Amazon Web Services (AWS) Tutorial
From the course: AWS Certified Security - Specialty (SCS-C03) Cert Prep
AWS CloudHSM
AWS cloud HSM is another service you can use for creating and managing encryption keys. The big difference between this and KMS is that cloud HSM is a dedicated hardware device that you get access to. It's not just a multi tenant infrastructure like KMS, and actually runs in your VPC. So let's have a look at some key facts about cloud HSM. It's a cloud based hardware security module running in the cloud, you can generate and use your own encryption keys on the AWS cloud with cloud HSM, and it runs in your VPC. It uses what's known as FIPS 140 dash two level three validated hardware security modules. Now that just means that is extremely secure. It's validated as being a secure configuration. Now it's not that kms isn't secure. Of course it is. But it is a multi tenant infrastructure. So a hardware based security module will give you that additional level of security that you may need for your compliance or your security requirements in your organization. It's a managed service and it…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
-
-
-
(Locked)
Section 8 - Introduction1m
-
(Locked)
Encryption at Rest and in-Transit3m 45s
-
(Locked)
AWS Certificate Manager (ACM)3m 57s
-
(Locked)
[HOL] SSL/TLS Certificate in ACM7m 10s
-
(Locked)
AWS Key Management Service (KMS)10m 38s
-
(Locked)
[HOL] Create Custom KMS Keys6m 21s
-
(Locked)
AWS CloudHSM3m 37s
-
(Locked)
Protecting Data on S3, EBS, and EFS8m 42s
-
(Locked)
[HOL] Enforce KMS Encryption for S3 Bucket4m 15s
-
(Locked)
[HOL] Copy Encrypted Snapshot Across Accounts8m 42s
-
(Locked)
Database Protection - DynamoDB and RDS5m 32s
-
(Locked)
[HOL] Encryption Options for AWS Databases7m 55s
-
(Locked)
[HOL] Schedule Key Deletion2m 23s
-
(Locked)
Storing Secrets4m 12s
-
(Locked)
Security for Lambda Functions2m 27s
-
(Locked)
AWS Step Functions2m 33s
-
(Locked)
AWS Data Lifecycle Management Features6m 42s
-
(Locked)
AWS Data Integrity Features7m 21s
-
(Locked)
[HOL] Amazon Verified Permissions4m 34s
-
(Locked)
Data and Application Protection Exam Cram7m 48s
-
(Locked)
-
-
-