Encryption

The 14 checks in the “Encryption” category of a SQL Server audit: what each one verifies, its severity and the versions covered.

Checks in this category
14
Weight in the score
16
Breakdown by severity
1 critical · 5 high · 1 medium · 7 info

Checks in this category

  • ENC002

    TDE Certificates Backup

    Critical

    Checks if TDE certificates have been backed up recently

    Versions : 2012-2025

  • ENC003

    Certificates Expiring Soon

    High

    Detects database certificates expiring within the next 90 days

    Versions : 2012-2025

  • ENC005

    Database Master Key protected by password only (not by the Service Master Key)

    High

    Detects databases that own a Database Master Key (##MS_DatabaseMasterKey##) whose encryption by the Service Master Key has been dropped, leaving it protected by password only. Such a DMK does not open automatically, applications must OPEN MASTER KEY manually, and if the password is lost with no key backup, everything under the DMK (certificates, symmetric keys, credentials) becomes unrecoverable.

    Versions : 2012-2025

  • TLS007

    DEK uses AES (not RC4/DES)

    High

    Checks that Database Encryption Keys (TDE) use AES rather than the deprecated RC4 or DES algorithms.

    Versions : 2012-2025

  • TLS008

    Certificates >= 2048 bits

    High

    Checks that certificate key length is at least 2048 bits.

    Versions : 2016-2025

  • TLS009

    Asymmetric keys >= 2048 bits

    High

    Checks that asymmetric key length is at least 2048 bits.

    Versions : 2012-2025

  • TLS003

    Encryption certificate valid

    Medium

    Checks that instance certificates are neither expired nor self-signed, a prerequisite for trustworthy server identity in TLS.

    Versions : 2012-2025

  • DATA006

    Always Encrypted columns

    Info

    Inventories columns protected by Always Encrypted (client-side crypto, plaintext never exposed to the engine).

    Versions : 2016-2025

  • DATA007

    Always Encrypted enclave/attestation

    Info

    Checks Always Encrypted secure enclave configuration, which enables rich queries over encrypted data and requires an attestation service.

    Versions : 2019-2025

  • DATA010

    Cell-Level Encryption keys

    Info

    Inventories user symmetric keys used for cell-level encryption (EncryptByKey) of individual secrets.

    Versions : 2012-2025

  • DATA011

    TDE certificate backed up off-box

    Info

    Checks that the TDE protector certificate and its private key have been backed up; without a backup, encrypted databases are unrecoverable if the certificate is lost.

    Versions : 2012-2025

  • ENC001

    TDE Status Details

    Info

    Displays the detailed TDE encryption status per database

    Versions : 2012-2025

  • ENC004

    Encryption Coverage

    Info

    Calculates the percentage of user databases protected by TDE

    Versions : 2012-2025

  • TLS010

    EKM/HSM providers baselined

    Info

    Inventories registered external key management (EKM/HSM) providers to confirm they are all authorized.

    Versions : 2012-2025

Other categories

All checks