Checks whether the encryption feature is enabled for each ECS data disk that you want to mount. If the encryption feature is enabled for each ECS data disk that you want to mount, the configuration is considered compliant.

Scenarios

You can enable the encryption feature for each ECS data disk to improve data security. This helps you meet security and regulatory requirements.

Risk level

Default risk level: medium.

When you apply this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If the encryption feature is enabled for each ECS data disk that you want to mount, the configuration is considered compliant.
  • If the encryption feature is disabled for an ECS data disk that you want to mount, the configuration is considered compliant. For more information about how to remediate an incompliant configuration, see Incompliance remediation.

Rule details

Item Description
Rule name ecs-available-disk-encrypted
Rule identifier ecs-available-disk-encrypted
Tag ECS and Disk
Automatic remediation Not supported
Trigger type Configuration change
Supported resource type ECS disk
Input parameter None.

Incompliance remediation

ecs-disk-encrypted For more information, see Encrypt a data disk.