Description
The AWS Config ENCRYPTED_VOLUMES managed rule evaluates encryption of attached EBS volumes and can optionally check for a specified KMS key. Without this monitoring or an equivalent control, encryption gaps introduced during operation can go unnoticed.
The rule evaluates configuration changes. It does not encrypt volumes automatically or prevent creation of unencrypted volumes. Encryption configuration and monitoring are separate controls.
Potential impact
- Attached unencrypted volumes or volumes using an unsuitable key may not be identified promptly.
- Configurations that fail data-protection requirements can remain if noncompliant results are not reviewed and addressed.
Remediation
- Verify that AWS Config records EBS volumes in the required accounts and Regions, then add
ENCRYPTED_VOLUMES. Retain other required checks. - Where required, specify the key through the supported
kmsIdparameter and route noncompliant results to responsible owners and a response process. - Check actual evaluations and recording status. Plan encryption migration for unencrypted volumes and management of detached volumes separately.
Examples
An AWS Config recorder and required service permissions must already be configured. These examples keep two distinct security checks together.
Access-key age check only
Resources:
ConfigRule:
Type: AWS::Config::ConfigRule
Properties:
ConfigRuleName: access-keys-rotated
InputParameters:
maxAccessKeyAge: 100
Source:
Owner: AWS
SourceIdentifier: ACCESS_KEYS_ROTATED
MaximumExecutionFrequency: TwentyFour_Hours
This evaluates access-key age and includes no EBS encryption rule. Also review checks configured elsewhere.
Add EBS encryption monitoring
Resources:
ConfigRule:
Type: AWS::Config::ConfigRule
Properties:
ConfigRuleName: access-keys-rotated
InputParameters:
maxAccessKeyAge: 100
Source:
Owner: AWS
SourceIdentifier: ACCESS_KEYS_ROTATED
MaximumExecutionFrequency: TwentyFour_Hours
EncryptedVolumesRule:
Type: AWS::Config::ConfigRule
Properties:
ConfigRuleName: encrypted-volumes
Scope:
ComplianceResourceTypes:
- AWS::EC2::Volume
Source:
Owner: AWS
SourceIdentifier: ENCRYPTED_VOLUMES
A separate EBS encryption rule is added while retaining the access-key check. The example does not automatically remediate findings or encrypt volumes.