More Info:

Ensure that BigQuery Tables are encrypted with CMKs

Risk Level

Medium

Address

Security

Compliance Standards

CISGCP, CBP, HITRUST, SOC2, NISTCSF, PCIDSS, FedRAMP

Triage and Remediation

Remediation

To remediate the misconfiguration “GCP BigQuery Tables Should Be Encrypted With Customer Managed Keys”, you can follow the below steps:

  1. Log in to your GCP console.

  2. Navigate to the BigQuery section.

  3. Select the dataset that contains the tables you want to encrypt.

  4. Click on the “Show Info Panel” button (i) next to the dataset name.

  5. In the “Encryption” section, click on the “Edit” button.

  6. Select the “Customer-managed encryption keys” option.

  7. Click on the “Create or select a key” button.

  8. Choose an existing key or create a new one.

  9. Click on the “Save” button.

  10. Repeat the above steps for each table in the dataset.

By following these steps, you can remediate the misconfiguration “GCP BigQuery Tables Should Be Encrypted With Customer Managed Keys” and ensure that your BigQuery tables are encrypted with customer-managed keys.

Additional Reading: