Azure-StorageAccounts-Storage-Accounts-Encryption
Severity : High
Description: This control ensures that encryption of sensitive data at rest using Customer Managed Key. Data in Azure Monitor is encrypted with Microsoft-managed key or using Customer-managed keys. Using a customer-managed key to protect and control access to data is encrypted with your Azure Key Vault key. Customer-managed keys offer greater flexibility to manage access controls.
Remediation Steps:
Perform following to update encryption parameters:
Login to Azure Portal using https://portal.azure.com.
Go to Storage Account.
For each storage account, Click Encryption under Settings.
Set Customer Managed Keys.
Select the Encryption key and enter the appropriate setting value.
Click Save.
Important:
Reference:
CIS Microsoft Azure Foundations Benchmark v1.3.0 - 02-01-2021 : Recommendation #3.9
Data security and encryption best practices - Microsoft Azure
Blue Hexagon Proprietary