More Info:

Ensure Dataflow jobs are encrypted with customer managed kyes

Risk Level

Low

Address

Reliability, Security

Compliance Standards

SOC2, GDPR, ISO27001, HIPAA, HITRUST, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the “Dataflow Job CMK Keys Should Be Set” misconfiguration in GCP using the GCP console, please follow these steps:

  1. Open the Google Cloud Console and go to the Dataflow page.
  2. Select the Dataflow job that is affected by the misconfiguration.
  3. Click on the “Edit” button to edit the job configuration.
  4. Scroll down to the “Security” section of the configuration page.
  5. Under the “Encryption” section, select “Customer-managed key” from the “Key source” dropdown menu.
  6. Choose the appropriate Cloud KMS key that you want to use to encrypt your data.
  7. Click on the “Save” button to save the changes.

After following these steps, your Dataflow job will be configured to use customer-managed keys for encryption.