Data protection

Storage bucket is not encrypted with Customer-Managed key (CMK)

Description

Google Cloud Storage service allows you to store and retrieve data in a bucket. It was found that the {GcpStorageBucket} bucket is encrypted by default with Google-Managed key instead of using Customer-Managed key (CMK), which provides an extra strong layer of protection and control over your encrypted data.
  • Recommended Mitigation

    It is recommended that you encrypt your bucket data using a Customer Management Key (CMK). For further information, visit: <a href="https://cloud.google.com/storage/docs/encryption" target="_blank" rel="noopener noreferrer">https://cloud.google.com/storage/docs/encryption</a>