AWS Config configuration lacks an ENCRYPTED_VOLUMES rule

Use the AWS Config ENCRYPTED_VOLUMES rule to monitor encryption on attached EBS volumes, and verify that evaluations and notifications work.

Description

Without EBS encryption monitoring, unencrypted volumes may remain unnoticed. The AWS managed ENCRYPTED_VOLUMES rule evaluates encryption on EBS volumes attached to EC2 instances when their configuration changes. Its optional kmsId parameter can also check that a particular KMS key is used.

The rule evaluates encryption; it does not encrypt volumes or prevent unencrypted volumes from being created. Review the monitoring already operating in the account and Region, and configure the evaluations you need.

Potential impact

  • It may take longer to identify volumes that violate encryption requirements and begin corrective work.
  • Stopped configuration recording or an incorrect evaluation scope can prevent the expected results and notifications.

Remediation

  • Where needed, add a separately named AWS Config rule with source.owner: AWS, source.identifier: ENCRYPTED_VOLUMES, and a scope appropriate for AWS::EC2::Volume. Retain other required rules.
  • Verify that the configuration recorder records changes to the relevant volumes. Set kmsId if a particular key is required.
  • Verify actual evaluations and notifications. Configure volume encryption and controls on volume creation separately.

Examples

Monitor public writes to S3

yaml
---
- name: foo
  community.aws.aws_config_rule:
    name: test_config_rule
    state: present
    description: "This AWS Config rule checks for public write access on S3 buckets"
    scope:
      compliance_types:
        - "AWS::S3::Bucket"
    source:
      owner: AWS
      identifier: "S3_BUCKET_PUBLIC_WRITE_PROHIBITED"

This rule evaluates public write access to S3. Retain the required S3 monitoring and add EBS encryption monitoring separately.

Add EBS encryption monitoring

yaml
- name: foo
  community.aws.aws_config_rule:
    name: encrypted-volumes
    state: present
    description: "This AWS Config rule checks encrypted EBS volumes"
    scope:
      compliance_types:
        - "AWS::EC2::Volume"
    source:
      owner: AWS
      identifier: ENCRYPTED_VOLUMES

The distinct name encrypted-volumes avoids replacing the S3 rule above. Use the EBS volume scope and verify that configuration recording and actual evaluations work.

References