Control: 4.2 Ensure that 'Virtual Machine’s disk' are encrypted
Description
Ensure that disk are encrypted when it is created with the creation of VM instance.
Remediation
From Console
Encrypt a system disk when copying an image in the ECS console by following the below steps:
- Logon to ECS Console.
- In the left-side navigation pane, choose
Instances & Images > Instances
. - In the top navigation bar, select a region.
- On the
Images
page, click theCustom Image
tab. - Select the target image and click
Copy Image
in theActions
column. - In the
Copy Image
dialog box, check theEncrypt
box and then select a key from the drop-down list. - Click OK.
You can encrypt a data disk when creating an instance by following the below steps:
- Logon to ECS Console.
- In the left-side navigation pane, choose
Instances & Images > Instances
. - On the
Instances
page, clickCreate Instance
. - On the
Basic Configurations
page, find theStorage
section and perform the following steps- Click
Add Disk
. - Specify the disk category and capacity of data disk.
- Select
Disk Encryption
and then select a key from the drop-down list.
- Click
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_4_2
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_4_2 --share
SQL
This control uses a named query:
ecs_disk_encryption_enabled