policy security_error ai_generated true

Security finding: encryption at rest not enabled

ID: policy/encryption-at-rest-disabled

Also available as: JSON · Markdown
85%Fix Rate
88%Confidence
3Evidence
2023-01-01First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
any active

Root Cause

Storage resource lacks encryption at rest.

generic

Workarounds

  1. 92% success Enable platform-managed encryption: AWS SSE-S3, GCP default encryption
  2. 88% success Use customer-managed keys (CMK) for sensitive data

Dead Ends

Common approaches that don't work:

  1. Enable encryption without key management plan 80% fail

    Key loss means data loss

  2. Encrypt at application layer only 72% fail

    Doesnt satisfy infrastructure compliance