Data protection

Managed disk is not encrypted with CMK.

Risk Level

Informational (4)

Platform(s)
Compliance Frameworks

Description

{AzureDisk} is not encrypted with customer managed key (CMK). Encrypting managed disks ensures that the entire content is fully unrecoverable without a key and thus protects the volume from unwarranted reads. Encryption with customer managed key (CMK) is superior encryption although requires additional planning. Using customer managed keys may provide an additional level of security or meet an organization's regulatory requirements. Even if the disk is not attached to any of the VMs, there is always a risk where a compromised user account with administrative access to VM service can mount/attach these data disks which may lead to sensitive information disclosure and tampering. By default, Azure disks are encrypted using SSE with PMK.
  • Recommended Mitigation

    It is recommended to encrypt disks with customer managed keys.