Skip to main content

Remediation

Enable EBS Volume Encryption​

Amazon WorkSpaces does not support enabling encryption on existing WorkSpaces. To remediate this finding, you must recreate the affected WorkSpace with EBS volume encryption enabled.

From Console​

  1. Open the Amazon WorkSpaces console.

  2. Choose Create WorkSpaces and complete the first three setup steps.

  3. On the Customization step:

    • Select Encrypt root volume and Encrypt user volume.

    • For Encryption Key, select a customer-managed KMS key that you created

      Note: The selected KMS key must be symmetric, as Amazon WorkSpaces does not support asymmetric KMS keys.

  4. Choose Create WOrkSpace to finish the WorkSpaces creation process.