Introduction

The federal government and regulated industries customers require the same performance and enterprise-grade services that private industry does. But they also have many extra security and compliance requirements, especially from a data storage, access, and sovereignty perspective. These extra security and compliance needs make it more difficult for the public sector and regulated industries customers to operate in Azure’s public cloud services.
Why Azure NetApp Files?
Azure NetApp Files is a high-performance, enterprise-class file storage service that is natively integrated with Azure Government. Azure NetApp Files is a high-performance, scalable, and secure storage service for running mission-critical applications and workloads in Azure.
Azure NetApp Files integration with Azure services makes the migration process easy, enabling users to move their workloads from their premises to the cloud with minimal effort. It meets all critical compliance and regulatory requirements for public sector and regulated industry customers, thanks to its advanced security and compliance features.
Azure NetApp Files saves time and money by enhancing cloud application deployment and operation with added security and compliance, enabling your organization to focus on innovation rather than administration, delivering greater value.
https://www.youtube.com/watch?v=dDnVssBTNv4
Volume encryption with customer-managed keys in Azure Government
With the release of customer-managed keys for Azure NetApp Files volume encryption in Azure Government, public sector and regulated industries customers who require DoD IL5 support can now benefit from enhanced volume encryption. This advance enables customers to securely move mission-critical workloads, such as databases, Azure virtual desktops, and high-performance computing (HPC), to Azure NetApp Files.
Customer-managed keys (CMK) is a security feature that allows organizations to take control of their keys and manage them independently from the cloud service provider. In the context of Azure NetApp Files, customer-managed keys enable customers to encrypt and decrypt their data stored in Azure NetApp Files by using their own keys, so that they have exclusive access control.
Customer-managed keys in Azure NetApp Files enhances data protection in the following ways.
- Enhanced data security - By using customer-managed keys, organizations can strengthen the security of their data stored in Azure NetApp Files. With customer-managed keys, the keys are generated, managed, and stored within the organization’s own infrastructure, reducing the risk of unauthorized access to sensitive information. This approach offers an additional layer of protection against data breaches and insider threats.
- Compliance and regulatory requirements - Many industries and regions have stringent data protection regulations that require organizations to maintain control over their keys. Customer-managed keys in Azure NetApp Files allows businesses to meet these compliance requirements by keeping the keys in their possession, providing an auditable trail of key management, which is essential for regulatory compliance audits.
- Protection against unauthorized access - Customer-managed keys offers organizations protection against unauthorized access to their data. Even if a breach or unauthorized access occurs in the cloud environment, the encrypted data remains inaccessible without the corresponding keys. This protection minimizes the risk of data exposure and helps organizations maintain the confidentiality of their sensitive information.
- Trust and confidence - Customer-managed keys gives organizations a sense of trust and confidence in the security of their data. By having exclusive control over the keys, organizations can keep their data protected, fostering trust with their customers, partners, and stakeholders.
Volume encryption with customer-managed keys with managed Hardware Security Module (HSM)
Azure NetApp Files volume encryption with customer-managed keys with the managed Hardware Security Module (HSM) is an extension to customer-managed keys for the Azure NetApp Files volumes encryption feature. Customer-managed keys with managed HSM allows encryption keys to be stored in a more secure FIPS 140-2 Level 3 HSM instead of the FIPS 140-2 Level 1 or Level 2 service used by Azure Key Vault (AKV). For more information, see Configure customer-managed keys with managed Hardware Security Module for Azure NetApp Files volume encryption.
An Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant, standards-compliant cloud service that enables customers to safeguard cryptographic keys for cloud applications, using FIPS 140-2 Level 3 validated HSM. For more information, see What is Azure Key Vault Managed HSM.
This option is especially crucial for public sector and regulated industries customers with highly sensitive data. Using an Azure Key Vault Managed HSM along with an Azure NetApp Files volume ensures the protection of sensitive information and compliance with all security requirements. These HSMs are tamper-resistant, provide isolated access control, enhance data protection and compliance, and are dedicated to a single customer.
Conclusion
With the latest security and compliance feature releases, Azure NetApp Files has achieved feature parity between Azure Government and Azure Commercial. Additionally, Azure NetApp Files now offers a comprehensive set of security and compliance features, ensuring the secure storage of sensitive information for all customers.
The release of customer-managed keys in Azure Government enables public sector and regulated industries customers who require IL5 compliance to use Azure NetApp Files for their mission-critical workloads. With its ease of use, cost efficiency, and robust support, Azure NetApp Files is an essential service for public sector and regulated industry customers, enabling them to leverage the cloud while meeting their unique requirements.
Additional Information
- Solution architectures using Azure NetApp Files | Microsoft Learn
- Azure NetApp Files for Azure Government | Microsoft Learn
- Azure NetApp Files double encryption at rest | Microsoft Learn
- Configure customer-managed keys for Azure NetApp Files volume encryption | Microsoft Learn
- Configure customer-managed keys with managed Hardware Security Module for Azure NetApp Files volume encryption | Microsoft Learn
- Quick Bytes: What is Azure NetApp Files
- How-to: Configure customer-managed keys for Azure NetApp Files volume encryption