EBS encryption monitoring needs review

Use the AWS Config ENCRYPTED_VOLUMES managed rule to check encryption of attached EBS volumes and respond to noncompliant results.

Description

The AWS Config ENCRYPTED_VOLUMES managed rule evaluates encryption of attached EBS volumes and can optionally check for a specified KMS key. Without this monitoring or an equivalent control, encryption gaps introduced during operation can go unnoticed.

The rule evaluates configuration changes. It does not encrypt volumes automatically or prevent creation of unencrypted volumes. Encryption configuration and monitoring are separate controls.

Potential impact

  • Attached unencrypted volumes or volumes using an unsuitable key may not be identified promptly.
  • Configurations that fail data-protection requirements can remain if noncompliant results are not reviewed and addressed.

Remediation

  • Verify that AWS Config records EBS volumes in the required accounts and Regions, then add ENCRYPTED_VOLUMES. Retain other required checks.
  • Where required, specify the key through the supported kmsId parameter and route noncompliant results to responsible owners and a response process.
  • Check actual evaluations and recording status. Plan encryption migration for unencrypted volumes and management of detached volumes separately.

Examples

An AWS Config recorder and required service permissions must already be configured. These examples keep two distinct security checks together.

Access-key age check only

yaml
Resources:
  ConfigRule:
    Type: AWS::Config::ConfigRule
    Properties:
      ConfigRuleName: access-keys-rotated
      InputParameters:
        maxAccessKeyAge: 100
      Source:
        Owner: AWS
        SourceIdentifier: ACCESS_KEYS_ROTATED
      MaximumExecutionFrequency: TwentyFour_Hours

This evaluates access-key age and includes no EBS encryption rule. Also review checks configured elsewhere.

Add EBS encryption monitoring

yaml
Resources:
  ConfigRule:
    Type: AWS::Config::ConfigRule
    Properties:
      ConfigRuleName: access-keys-rotated
      InputParameters:
        maxAccessKeyAge: 100
      Source:
        Owner: AWS
        SourceIdentifier: ACCESS_KEYS_ROTATED
      MaximumExecutionFrequency: TwentyFour_Hours
  EncryptedVolumesRule:
    Type: AWS::Config::ConfigRule
    Properties:
      ConfigRuleName: encrypted-volumes
      Scope:
        ComplianceResourceTypes:
          - AWS::EC2::Volume
      Source:
        Owner: AWS
        SourceIdentifier: ENCRYPTED_VOLUMES

A separate EBS encryption rule is added while retaining the access-key check. The example does not automatically remediate findings or encrypt volumes.

References