Data protection

OSS buckets encryption without BYOK method


Alibaba Cloud OSS (Object Storage Service) provides storage service to your files and data in the account. The files are stored in containers called buckets. It was detected that the OSS bucket {AliCloudOssBucket} is not configured to use BYOK (Bring Your Own Key) method. BYOK helps you to better control encryption keys by choosing the key material yourself. When creating a KMS key you can select the Alibaba Cloud as the source of your material or you can select external key material.
  • Recommended Mitigation

    It is recommended to configure server-side encryption with KMS (SSE-KMS) by using BYOK method.