Ensure that Server-Side Encryption (SSE) with the service-managed key is enabled for your Object Storage Service (OSS) buckets in order to protect your data at rest and meet regulatory requirements. Object Storage Service (OSS) provides a service-managed key identified by the alias "alias/acs/oss".
In Object Storage Service, Server-Side Encryption (SSE) automatically encrypts data you upload to your buckets. OSS handles the encryption and decryption process, keeping your data secure even if someone gains access to the underlying storage. SSE represents an extra layer of security that can prevent unauthorized users from accessing sensitive or mission-critical information.
Audit
To determine if Server-Side Encryption with the service-managed key is enabled for your OSS buckets, perform the following operations:
Remediation / Resolution
To ensure that Server-Side Encryption (SSE) with the service-managed key is enabled for your OSS buckets, perform the following operations:
References
- Alibaba Cloud Documentation
- Overview
- Integration with KMS
- Server-side encryption