STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Microsoft Azure SQL Managed Instance Security Technical Implementation Guide

V-276251

CAT I (High)

Azure SQL Managed Instance must protect the confidentiality and integrity of all information at rest.

Rule ID

SV-276251r1149662_rule

STIG

Microsoft Azure SQL Managed Instance Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-001199

Discussion

This control is intended to address the confidentiality and integrity of information at rest in nonmobile devices and covers user information and system information. Information at rest refers to the state of information when it is located on a secondary storage device (e.g., disk drive, tape drive) within an organizational information system. Applications and application users generate information throughout the course of their application use. User data generated, as well as application-specific configuration data, must be protected. Organizations may choose to employ different mechanisms to achieve confidentiality and integrity protections, as appropriate. If the confidentiality and integrity of application data is not protected, the data will be open to compromise and unauthorized modification.

Check Content

Run the following TSQL to determine database encryption status: 

SELECT db.name AS DatabaseName, db.is_encrypted AS IsEncrypted,  
CASE 
WHEN dm.encryption_state = 0 THEN 'No database encryption key present, no encryption' 
WHEN dm.encryption_state = 1 THEN 'Unencrypted' 
WHEN dm.encryption_state = 2 THEN 'Encryption in progress' 
WHEN dm.encryption_state = 3 THEN 'Encrypted' 
WHEN dm.encryption_state = 4 THEN 'Key change in progress' 
WHEN dm.encryption_state = 5 THEN 'Decryption in progress' 
WHEN dm.encryption_state = 6 THEN 'Protection change in progress' 
END AS EncryptionState, 
dm.encryption_state AS EncryptionState,  
dm.key_algorithm AS KeyAlgorithm,  
dm.key_length AS KeyLength 
FROM sys.databases db 
LEFT OUTER JOIN sys.dm_database_encryption_keys dm ON db.database_id = dm.database_id 
WHERE db.database_id NOT IN (1,2,3,4) 

If the application owner and authorizing official have determined that encryption of data at rest is required and the EncryptionState column returns "UNENCRYPTED" or "DECRYPTION_IN_PROGRESS", this is a finding.

Fix Text

For each database indicating "UNENCRYPTED" or "DECRYPTION_IN_PROGRESS", execute the TSQL command below to enable encryption: 
  
ALTER DATABASE [<database name between brackets>] SET ENCRYPTION ON