4.9 Ensure that Tri-Secret Secure is enabled for the Snowflake account

Information

Tri-Secret Secure is the combination of a Snowflake-maintained key and a customer-managed key in the cloud provider platform that hosts your Snowflake account to create a composite master key to protect your Snowflake data. The composite master key acts as an account master key and wraps all of the keys in the hierarchy; however, the composite master key never encrypts raw data.

If the customer-managed key in the composite master key hierarchy is revoked, your data can no longer be decrypted by Snowflake, providing a level of security and control above Snowflake's standard encryption.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable Snowflake Tri-Secret Secure for your Business Critical (or higher) account, please contact Snowflake Support.

Impact:

This feature relies on the customer managing and providing an encryption key. There is a reliability risk associated with it: If the key is lost, all data encrypted within the Snowflake account will be lost.

See Also

https://workbench.cisecurity.org/benchmarks/14781

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|14.4, CSCv7|14.8

Plugin: Snowflake

Control ID: 81ad326dc5c9680899b91d4c1d4f6a4681de2503e8915a73212273ab58408768