疑似Oday
Ensure that the disks attached to your production Google Compute Engine instances are encrypted with Customer-Supplied Encryption Keys (CSEKs) in order to have complete control over the data-at-rest encryption and decryption process. CSEKs allow you to provide your own encryption keys that Google Compute Engine uses to protect the Google-generated keys used to encrypt and decrypt your instance data.
id: gcloud-vm-disk-csek-not-enabled
info:
name: Virtual Machine Disk Encryption with Customer-Sup
...