More Info:

Encrypting the IaaS VMs OS disk (boot volume) ensures that its entire content is fully unrecoverable without a key and thus protects the volume from unwarranted reads.

Risk Level

High

Address

Security

Compliance Standards

HIPAA, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

Here are the steps to remediate the OS Disks Lacking Encryption misconfiguration in AZURE using the AZURE console:

  1. Log in to the AZURE portal.
  2. Navigate to the Virtual Machines blade.
  3. Select the virtual machine that has the OS Disks Lacking Encryption misconfiguration.
  4. Click on the “Disks” option under the Settings section.
  5. Select the OS disk that you want to encrypt.
  6. Click on the “Disk Encryption” option under the “Settings” section.
  7. Click on the “Enable” button to enable the disk encryption.
  8. Choose the encryption type and the encryption key.
  9. Click on the “Save” button to save the changes.

Once the encryption is enabled, the OS disk will be encrypted, and the misconfiguration will be remediated. It is important to note that the encryption process may take some time to complete, depending on the size of the disk.

Additional Reading: