CloudHSM
Special security mechanisms to make them more secure:
Some types of keys that might be stored on HSMs
keys used to encrypt file systems
keys used to encrypt databases
keys used to provide DRM
used with S3 encryption.
When to use CloudHSM instead of somethign like key management service?
- - not even AWS engineers have access to the keys in the cloudHSM applicance, only access to “manage” the appliance.