You can create a key manager provider of type Hardware-Based. The Hardware Based Key Manager Provider enables the server to access the private key information through a generic hardware-based key store. This standard interface is used by cryptographic accelerators and hardware security modules.
The C-suite refers to a company's top management positions, where the "C" stands for "chief." Various chief officers (e.g., CEO, CIO, CFO, etc.) are the occupants of the C-suite. These individuals, while highly paid and influential managers, are still employees of the firm. The number of C-level positions varies by firm, depending on variables such as a company's size, mission, and sector.
An external key store is a custom key store backed by an external key management infrastructure that you own and manage outside of AWS. All encryption or decryption operations that use a KMS key in an external key store are performed in your key manager with cryptographic keys and operations that are under your control and are physically inaccessible to AWS.
Note: The above examples are appropriate for persistent storage of cardholder data. The minimum cryptography requirements for transaction-based operations, as defined in PCI PIN and PTS, are more flexible as there are additional controls in place to reduce the level of exposure.
It is recommended that all new implementations use a minimum of 128-bits of effective key strength.