Skip to content

Encryption and identity

Source: Storage & Data Standards, sys_kb_id=fdc09a4d93548f908037f8bd1dba10ed.


Control Requirement
Primary identity Entra ID / AD wherever supported
SQL authentication Still needed for some Azure SQL — permitted where required
Shared keys Disabled unless approved
SAS tokens Expiry required + least privilege
Public network access Disabled unless approved
Private endpoints Required for production sensitive workloads

[TBD: the standard does not state a maximum SAS token lifetime, nor whether user-delegation SAS is preferred over account SAS.]

Control Requirement
At rest Mandatory
In transit TLS 1.2 minimum, 1.3+ where supported
High-sensitivity data CMK, stored in Key Vault
Key rotation At least annually

“High-sensitivity” maps to Restricted, and to Confidential where required. The standard’s phrasing for Restricted/Confidential is “Key Vault managed keys where required”, so CMK is not unconditional for Confidential.

[TBD: the standard does not define "high-sensitivity" beyond the classification levels, nor does it state who determines when Key Vault managed keys are "required".]

resource "azurerm_storage_account" "data" {
min_tls_version = "TLS1_2"
https_traffic_only_enabled = true
shared_access_key_enabled = false
public_network_access_enabled = false
customer_managed_key {
key_vault_key_id = azurerm_key_vault_key.data.id
}
tags = { data_classification = "Restricted" }
}
resource "azurerm_private_endpoint" "data" { /* required for Restricted/Confidential */ }

Source of truth: plugins/patterson-engineering/skills/storage-data-standards/references/encryption-and-identity.md in the patterson-corp repository.