EBS block-device encryption needs review

Check actual encryption and defaults for EBS volumes created with EC2, and specify required encryption and key permissions.

Description

EBS encryption protects data at rest on volumes and associated snapshots. A new volume's encryption depends on Encrypted, the Region's encryption-by-default setting and any source snapshot. An omitted or false setting alone does not prove that the deployed volume is unencrypted.

Explicitly request the required encryption and check the created volumes. Encryption at rest does not replace controls against excessive access inside an instance or data exposure through an application.

Potential impact

  • Actually unencrypted volumes and snapshots may not meet data-protection requirements.
  • Incorrect key permissions or unexpected instance replacement can affect data access and service availability.

Remediation

  • Set Encrypted: true for new EBS volumes requiring encryption. Check the source image or snapshot, encryption defaults and KMS permissions.
  • Migrate existing unencrypted volumes through encrypted copies and new volumes. Changing this property on a running AWS::EC2::Instance replaces the instance, so review the change set and data preservation first.
  • Use launch templates for new Auto Scaling configurations, and verify all actual EBS volumes and relevant snapshots after applying the change.

Examples

Provide an AMI available in the Region and compatible with the instance type as ImageId. These examples create a new data volume; /dev/sdf must not conflict with the AMI's existing mappings. Review the root volume and networking separately.

Volume without an explicit encryption request

json
{
  "AWSTemplateFormatVersion": "2010-09-09",
  "Parameters": {
    "ImageId": {
      "Type": "AWS::EC2::Image::Id"
    }
  },
  "Resources": {
    "MyEC2Instance": {
      "Type": "AWS::EC2::Instance",
      "Properties": {
        "ImageId": {
          "Ref": "ImageId"
        },
        "InstanceType": "t2.micro",
        "BlockDeviceMappings": [
          {
            "DeviceName": "/dev/sdf",
            "Ebs": {
              "VolumeSize": 8,
              "VolumeType": "gp3",
              "Encrypted": false
            }
          }
        ]
      }
    }
  }
}

With encryption by default disabled, this new empty volume is unencrypted. Enabling the Region's default changes that outcome.

Volume with encryption requested

json
{
  "AWSTemplateFormatVersion": "2010-09-09",
  "Parameters": {
    "ImageId": {
      "Type": "AWS::EC2::Image::Id"
    }
  },
  "Resources": {
    "MyEC2Instance": {
      "Type": "AWS::EC2::Instance",
      "Properties": {
        "ImageId": {
          "Ref": "ImageId"
        },
        "InstanceType": "t2.micro",
        "BlockDeviceMappings": [
          {
            "DeviceName": "/dev/sdf",
            "Ebs": {
              "VolumeSize": 8,
              "VolumeType": "gp3",
              "Encrypted": true
            }
          }
        ]
      }
    }
  }
}

This requests encryption for the new data volume. It does not encrypt an existing volume in place or change the settings of every other volume.

References