More Info:

Ensure Spanner Database Backups are encrypted with Customer Managed Keys

Risk Level

Medium

Address

Reliability, Security

Compliance Standards

SOC2, GDPR, ISO27001, HIPAA, HITRUST, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration of Spanner Database Backup not being encrypted with customer-managed keys in GCP, follow these steps:

  1. Go to the GCP Console and navigate to the Spanner instance whose backup you want to encrypt.

  2. Click on the “Backups” tab in the left-hand menu.

  3. Find the backup that needs to be encrypted and click on its name.

  4. Click on the “Encryption” tab in the top menu.

  5. Click on the “Edit” button.

  6. Select “Customer-managed key” from the “Encryption type” dropdown.

  7. Choose the appropriate key from the “Key name” dropdown.

  8. Click on the “Save” button to save the changes.

  9. Verify that the backup is now encrypted with the customer-managed key by checking the “Encryption” tab.

  10. Repeat these steps for any other Spanner backups that need to be encrypted with customer-managed keys.

By following these steps, you can remediate the misconfiguration of Spanner Database Backup not being encrypted with customer-managed keys in GCP.