MEDIUM
Source
CloudSploit
ID
disable-default-encryption-creation

Disable Default Encryption Creation

Determine if “Restrict Default Google-Managed Encryption for Cloud SQL Instances” is enforced on the GCP organization level.

Google-managed encryption keys for Cloud SQL database instances to enforce the use of Customer-Managed Keys (CMKs) in order to have complete control over database encryption/decryption process.

Ensure that “Restrict Default Google-Managed Encryption for Cloud SQL Instances” constraint is enforced at the organization level.