More Info:

Enable Encryption for Spanner Database Backups

Risk Level

High

Address

Reliability, Security

Compliance Standards

SOC2, GDPR, ISO27001, HIPAA, HITRUST, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Spanner Database Backup Encryption Should Be Enabled” for GCP using GCP console, you can follow the below steps:

  1. Login to the Google Cloud Console.
  2. Navigate to the Spanner database instance for which you want to enable the backup encryption.
  3. Click on the “Edit” button on the top of the page.
  4. Scroll down to the “Backup” section and click on it.
  5. In the “Backup Encryption” section, select the “Enabled” option.
  6. Choose a key version to encrypt the backups. You can either use a customer-managed encryption key or Google-managed encryption key.
  7. If you choose a customer-managed encryption key, select the key from the dropdown list. If you choose Google-managed encryption key, then select the key version from the dropdown list.
  8. Click on the “Save” button to save the changes.

Once you have enabled the backup encryption for the Spanner database instance, all the backups taken for that instance will be encrypted using the selected encryption key.