More Info:

Ensure that Bigtable clusters are encrypted with CMKs

Risk Level

High

Address

Security

Compliance Standards

SOC2, NIST, GDPR, ISO27001, HIPAA, HITRUST

Triage and Remediation

Remediation

To remediate the misconfiguration “Bigtable Cluster Should Be Encrypted With Customer Managed Keys” for GCP using GCP Console, please follow the below steps:

  1. Log in to your GCP Console.
  2. Go to the Bigtable instances page by clicking on “Navigation Menu > Bigtable” or by searching for “Bigtable” in the search bar.
  3. Select the Bigtable instance that you want to remediate.
  4. Click on the “Encryption” tab.
  5. Under the “Encryption at rest” section, select “Customer-managed key”.
  6. Click on “Create a key”.
  7. Choose the location for the key.
  8. Choose the key ring for the key.
  9. Enter a name for the key.
  10. Click on “Create”.
  11. Select the newly created key from the dropdown menu.
  12. Click on “Save” to save the changes.

After following these steps, your Bigtable cluster will be encrypted with customer-managed keys and the misconfiguration will be remediated.

Additional Reading: