MEDIUM
Source
Trivy
ID
AVD-AZU-0061

Storage account should have infrastructure encryption enabled

Infrastructure encryption provides an additional layer of encryption at the infrastructure level. When infrastructure encryption is enabled, data in the storage account is encrypted twice - once at the service level and once at the infrastructure level with two different encryption algorithms. This provides double encryption for enhanced security.

Impact

Follow the appropriate remediation steps below to resolve the issue.

Enable infrastructure encryption for storage account

1
2
3
4
5
6
7
8
resource "azurerm_storage_account" "good_example" {
  name                              = "storageaccountname"
  resource_group_name               = azurerm_resource_group.example.name
  location                          = azurerm_resource_group.example.location
  account_tier                      = "Standard"
  account_replication_type          = "GRS"
  infrastructure_encryption_enabled = true
}