Data protection

FileStore not encrypted using customer-managed encryption keys (CMEK)

Platform(s)
Compliance Frameworks
  • CCPA
  • ,
  • coppa
  • ,
  • CPRA
  • ,
  • iso_27001_2022
  • ,
  • iso_27002_2022
  • ,
  • Mitre ATT&CK
  • ,
  • mpa
  • ,
  • New Zealand Information Security Manual
  • ,
  • NIST 800-171
  • ,
  • PDPA
  • ,
  • pipeda

Description

Filestore instances are fully managed NFS file servers on Google Cloud for use with applications running on Compute Engine virtual machines (VMs) instances or Google Kubernetes Engine clusters. We identified a FileStore instance '{GcpFileStoreInstance}' which encrypted using default encryption keys managed by Google. is recommended that Google FileStore Instance is configured to encrypt file data using customer-managed encryption keys (CMEK)