Breif
Investigating HSMs and Key Management Products
Context
Client is interested in understadning the commercial landscape for technologies that produce, manage and secure cryptographic keys. These technologies are frequently referred to as Hardware Security Modules (HSMs).
The client ask is to undertake a comparative analysis of the more commonly used and trusted technologies.
The focus should be on hardware based products, with one exception (Hashicorp Vault). Assessment should include (but not be limited to) products developed by:
- Thales
- Entrust
- IBM
- Utimaco
- Futurex
- Hashicorp Vault
Some of these vendors may have more than one product, the main interest is in general purpose capabilities rather than those developed for specific use cases (eg payment systems).
Undertake a comparative analysis of these products exploring elements such as but not limited to (if another one comes up feel free to include but label as new):
- Cost
- Form Factor
- Performance
- Deployment scenarios (on-prem; Cloud)
- Certifications/Security Standards compliance
- Capacity
- Algorithm support (eg do they support PQ algorithms)
- Monitoring
- Where vendor is based (ie which country)
Please include any further information you uncover on the products that could be of interest.
All research should be conducted from publicly available information supplemented with any PA internal and/or client provided insights (if feasible).
No more than 2 to 3 days of effort, provided pro-bono to NSB client
Output: Matrix of Products:Elements, findings to be presented in PA branded pack
Sufyaan Amnour started to look into this but has been diverted onto client work – he may have some useful information to share.
Avoid rabbit holes and dead-ends. Gaps in the matrix is fine.
Deadline is Friday 27th February for a 10am client call. Some review time with Toby would need to be factored in beforehand.