Description
EBS encryption protects data at rest on volumes and associated snapshots. A new volume's encryption depends on Encrypted, the Region's encryption-by-default setting and any source snapshot. An omitted or false setting alone does not prove that the deployed volume is unencrypted.
Explicitly request the required encryption and check the created volumes. Encryption at rest does not replace controls against excessive access inside an instance or data exposure through an application.
Potential impact
- Actually unencrypted volumes and snapshots may not meet data-protection requirements.
- Incorrect key permissions or unexpected instance replacement can affect data access and service availability.
Remediation
- Set
Encrypted: truefor new EBS volumes requiring encryption. Check the source image or snapshot, encryption defaults and KMS permissions. - Migrate existing unencrypted volumes through encrypted copies and new volumes. Changing this property on a running
AWS::EC2::Instancereplaces the instance, so review the change set and data preservation first. - Use launch templates for new Auto Scaling configurations, and verify all actual EBS volumes and relevant snapshots after applying the change.
Examples
Provide an AMI available in the Region and compatible with the instance type as ImageId. These examples create a new data volume; /dev/sdf must not conflict with the AMI's existing mappings. Review the root volume and networking separately.
Volume without an explicit encryption request
{
"AWSTemplateFormatVersion": "2010-09-09",
"Parameters": {
"ImageId": {
"Type": "AWS::EC2::Image::Id"
}
},
"Resources": {
"MyEC2Instance": {
"Type": "AWS::EC2::Instance",
"Properties": {
"ImageId": {
"Ref": "ImageId"
},
"InstanceType": "t2.micro",
"BlockDeviceMappings": [
{
"DeviceName": "/dev/sdf",
"Ebs": {
"VolumeSize": 8,
"VolumeType": "gp3",
"Encrypted": false
}
}
]
}
}
}
}
With encryption by default disabled, this new empty volume is unencrypted. Enabling the Region's default changes that outcome.
Volume with encryption requested
{
"AWSTemplateFormatVersion": "2010-09-09",
"Parameters": {
"ImageId": {
"Type": "AWS::EC2::Image::Id"
}
},
"Resources": {
"MyEC2Instance": {
"Type": "AWS::EC2::Instance",
"Properties": {
"ImageId": {
"Ref": "ImageId"
},
"InstanceType": "t2.micro",
"BlockDeviceMappings": [
{
"DeviceName": "/dev/sdf",
"Ebs": {
"VolumeSize": 8,
"VolumeType": "gp3",
"Encrypted": true
}
}
]
}
}
}
}
This requests encryption for the new data volume. It does not encrypt an existing volume in place or change the settings of every other volume.