Description
A Persistent Disk inventory helps identify block-storage assets and data locations, then review encryption keys, backups and attachments. The presence of a disk is not itself a security vulnerability.
Persistent Disk encrypts stored data by default. Customer-managed encryption keys (CMEK) add control over key management; omitting them does not mean data is stored in plaintext.
Potential impact
- Missing assets can escape backup and snapshot-policy reviews.
- Data locations, costs and operational ownership can become harder to manage.
Remediation
Include disks in the asset inventory and review attachments, permissions and recovery policies. If CMEK is required, manage key permissions and availability, including the effect of disabling or deleting keys on data access.
Examples
These excerpts use the historical Deployment Manager format, whose support has ended. Both examples use encrypted storage; the after example specifies a different key-management approach. Replace the illustrative key with an actual usable key.
Before
resources:
- type: compute.v1.disk
name: disk-1-data
properties:
sizeGb: 10
zone: us-east1-c
After
resources:
- type: compute.v1.disk
name: disk-1-data
properties:
sizeGb: 10
zone: us-east1-c
diskEncryptionKey:
kmsKeyName: projects/example/locations/global/keyRings/ring/cryptoKeys/key
Explanation:
- Before: The disk uses Google-managed keys.
- After: CMEK is specified. The Compute Engine service agent needs permission to use the key. This setting alone does not convert an existing disk or create backups.