Key management options
In this section, we will cover several aspects of key management that are either Google-managed or customer-managed. It is important to know which option is best suited to which scenario so that you can make the right decision for a given use case.
Google Cloud’s default encryption
Google Cloud stores all data encrypted at rest using a Google-managed default encryption key. The key is the AES-256 symmetric encryption key. There is no setup of keys or configuration required to turn on this option; all data by default uses this type of encryption. Google manages the keys and the rotation period of those keys. Google Cloud’s default encryption is best suited for those customers who do not have specific requirements related to compliance or regional requirements for cryptographic key material. It is simple to use and does not require additional configuration to create keys, hence there is no cost to use it.