π‘οΈ AWS Account EBS Volume Encryption Attribute is not enabled in all regionsπ’
- Contextual name: π‘οΈ EBS Volume Encryption Attribute is not enabled in all regionsπ’
- ID:
/ce/ca/aws/account/ebs-volume-encryption-attribute-in-all-regions - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicβ
- π§ prod.logic.yamlπ’
Similar Policiesβ
- Cloud Conformity: Enable Encryption by Default for EBS Volumes
- Internal:
dec-x-0bdcd276
Similar Internal Rulesβ
| Rule | Policies | Flags |
|---|---|---|
| βοΈ dec-x-0bdcd276 | 1 |
Descriptionβ
Descriptionβ
Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.
Rationaleβ
Encrypting data at rest reduces the likelihood that it is unintentionally exposed and can nullify the impact of disclosure if the encryption remains unbroken.
Impactβ
Losing access or removing the KMS key in use by the EBS volumes will result in no longer being able to access the volumes.
Auditβ
From Consoleβ
- Login to AWS Management Console and open the Amazon EC2 console using https://console.aws.amazon.com/ec2/.
- Under
Account attributes, clickEBS encryption.- Verify
Always encrypt new EBS volumesdisplaysEnabled.- Review every region in-use.
Note: EBS volume encryption is configured per region.
From Command Lineβ
- Run:
aws --region <region> ec2 get-ebs-encryption-by-default
- Verify that
"EbsEncryptionByDefault": trueis displayed.- Review every region in-use.
Note: EBS volume encryption is configured per region.
... see more
Remediationβ
Remediationβ
From Consoleβ
- Login to AWS Management Console and open the Amazon EC2 console using https://console.aws.amazon.com/ec2/
- Under
Account attributes, clickEBS encryption.- Click
Manage.- Click the
Enablecheckbox.- Click
Update EBS encryption- Repeat for every region requiring the change.
Note: EBS volume encryption is configured per region.
From Command Lineβ
- Run
aws --region <region> ec2 enable-ebs-encryption-by-default
- Verify that
"EbsEncryptionByDefault": trueis displayed.- Repeat every region requiring the change.
Note: EBS volume encryption is configured per region.