More Info:

Cloud services offer the ability to protect data related to those services using encryption keys managed by the customer within Cloud KMS. These encryption keys are called customer-managed encryption keys (CMEK). When you protect data in Google Cloud services with CMEK, the CMEK key is within your control.

Risk Level

Medium

Address

Security, Reliability

Compliance Standards

CISGCP, CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “Ensure Dataproc Clusters Encrypted Using CMEK” for GCP using GCP console, you can follow the below steps:

  1. Login to your GCP console.
  2. Navigate to the Dataproc Clusters page.
  3. Select the cluster for which you want to enable encryption.
  4. Click on the “Edit” button at the top of the page.
  5. Scroll down to the “Security” section.
  6. Under “Encryption”, select “Customer-managed key”.
  7. Choose the Cloud KMS key that you want to use for encryption.
  8. Click on the “Save” button at the bottom of the page.

Once you have completed these steps, your Dataproc cluster will be encrypted using the specified Cloud KMS key. This will ensure that your data is secure and protected from unauthorized access.

Additional Reading: