Items related to Cryptographic Key Management in Practice: Protect the...

Cryptographic Key Management in Practice: Protect the Full Lifecycle of Keys from Creation to Rotation and Revocation - Softcover

Frost, Rion

 
9798171322830: Cryptographic Key Management in Practice: Protect the Full Lifecycle of Keys from Creation to Rotation and Revocation

Synopsis

Your encryption can be strong and your system can still be vulnerable.

A database may be encrypted. A master secret may live inside an HSM. Automatic replacement may be enabled. Access may be logged. But none of those controls answers the questions that ultimately determine whether sensitive data remains secure:

Who can actually decrypt it? What happens when credentials are compromised? Can old data survive a replacement? What happens when a cloud provider is unavailable? Can an organization prove where its most important cryptographic assets are used?

Cryptographic Key Management in Practice is a practical guide to building the systems behind trustworthy encryption, signing, identity, cloud security, and modern digital infrastructure.

Rather than focusing on mathematical derivations, this book shows developers, security engineers, cloud professionals, DevOps and SRE teams, architects, and technical leaders how cryptographic controls work throughout real production environments.

You'll learn how to:

  • Build secure hierarchies using DEKs, KEKs, envelope encryption, KMS platforms, and HSMs
  • Choose appropriate boundaries for software, hardware-backed, cloud-hosted, and externally controlled assets
  • Separate possession from permission and enforce least privilege around sensitive operations
  • Replace active material without breaking applications or losing access to historical data
  • Prepare for compromise, emergency response, recovery, destruction, and cryptographic erasure
  • Use workload identities, separation of duties, policy automation, and audit evidence
  • Architect cloud-native environments across Kubernetes, CI/CD systems, multiple regions, and multiple providers
  • Evaluate BYOK, HYOK, external control, sovereignty, and vendor-exit requirements
  • Build inventories and governance systems that remain useful as infrastructure changes
  • Prepare applications for crypto agility and the transition toward post-quantum standards

Realistic case studies show how apparently secure systems fail through overprivileged identities, version pinning, untested recovery, weak signing workflows, excessive centralization, and incomplete dependency maps.

The book concludes with a professional review playbook and a practical learning path that turns the concepts into repeatable architecture, migration, incident-response, and assurance workflows.

"synopsis" may belong to another edition of this title.