DAT-02.2: Storage volumes for compute use the default encryption made available by the cloud provider using default keys. This is typically sufficient for compliance and likely protects snapshots from being inadvertently shared or made public.
  • Control automation: Automated
  • AWS control specification: Default EBS Volume encryption is enabled in all regions with instances
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: Default EBS Volume encryption is enabled in all regions with instances
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none