More Info:

Ensures Customer Supplied Encryption Key is enabled on disks. Google encrypts all disks at rest by default. By using CSEK only authorized team members with the keys can access the disk. Anyone else, including Google, cannot access the disk data.

Risk Level

High

Address

Security

Compliance Standards

CISGCP, CBP, HITRUST, SOC2, GDPR, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Customer Supplied Encryption Key Should Be Enabled For Disks” for GCP using GCP console, please follow the below steps:

  1. Open the GCP Console and select the project for which you want to enable Customer Supplied Encryption Key.
  2. In the left navigation menu, select “Compute Engine” and then select “Disks”.
  3. Select the disk for which you want to enable Customer Supplied Encryption Key.
  4. Click on “Edit” at the top of the page.
  5. In the Encryption section, select “Customer-supplied encryption key”.
  6. Enter the 256-bit encryption key in the “Key” field.
  7. Click on “Save” to save the changes.

Once you have completed the above steps, the disk will be encrypted using the customer-supplied encryption key. It is recommended to create a backup of the encryption key and store it in a secure location, as it will be required to access the data on the disk.

Additional Reading: