More Info:

Ensure that infrastructure double encryption is enabled for your Azure PostgreSQL database servers in order to add a second layer of encryption for your PostgreSQL databases using a different encryption algorithm which provides enhanced data protection.

Risk Level

Medium

Address

Security

Compliance Standards

CISAZURE, CBP, HITRUST, GDPR, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Enable Infrastructure Double Encryption” in Azure using Azure Console, follow the below steps:

  1. Login to the Azure Portal (https://portal.azure.com/)
  2. Click on the “Virtual machines” option from the left-hand menu.
  3. Select the virtual machine that you want to remediate.
  4. Click on the “Disks” option from the left-hand menu.
  5. Select the disk that you want to remediate.
  6. Click on the “Disk Encryption” option from the left-hand menu.
  7. Click on the “Enable encryption” button.
  8. Select the key vault that you want to use for encryption.
  9. Click on the “Save” button to enable encryption.

By following these steps, you can remediate the misconfiguration “Enable Infrastructure Double Encryption” in Azure using Azure Console.