EBS volume encryption needs review

Verify actual encryption on EBS volumes and snapshots and explicitly request it for new volumes. Existing unencrypted data needs a separate migration.

Description

EBS encryption protects volume data and associated snapshots. Request encryption with Encrypted: true for new volumes and select the required KMS key. Account and Region defaults and source snapshots also affect the result, so false or omission alone does not establish that a deployed volume is unencrypted.

Potential impact

  • Actually unencrypted volumes and snapshots lack this additional protection and may not meet data-protection requirements.
  • Removing required key permissions or replacing a volume without migrating its data can disrupt application access and recovery.

Remediation

  • Verify encryption and keys on actual volumes and snapshots. Explicitly request the required encryption for new volumes and review KMS permissions.
  • Migrate an existing unencrypted volume through a supported process, such as creating a new volume from an encrypted copy of a consistent snapshot. CloudFormation does not support updating an existing volume's Encrypted property.
  • Plan backups, attachment of the new volume, data verification and service interruption. Enabling encryption by default does not retroactively encrypt existing volumes or snapshots.

Examples

These alternatives create a new empty volume. Select the same Availability Zone as the instance that will use it. Data copying and volume attachment are not included.

Encryption not requested

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Volume
Parameters:
  VolumeAvailabilityZone:
    Type: AWS::EC2::AvailabilityZone::Name
Resources:
  NewVolume:
    Type: AWS::EC2::Volume
    Properties:
      Size: 100
      Encrypted: false
      AvailabilityZone: !Ref VolumeAvailabilityZone
      Tags:
        - Key: MyTag
          Value: TagValue
    DeletionPolicy: Snapshot

An unencrypted volume can be created if encryption by default is off. Verify the actual result.

Encryption requested

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: Volume
Parameters:
  VolumeAvailabilityZone:
    Type: AWS::EC2::AvailabilityZone::Name
Resources:
  NewVolume:
    Type: AWS::EC2::Volume
    Properties:
      Size: 100
      Encrypted: true
      AvailabilityZone: !Ref VolumeAvailabilityZone
      Tags:
        - Key: MyTag
          Value: TagValue
    DeletionPolicy: Snapshot

This encrypts the new volume with the default KMS key. Specify an approved KmsKeyId if a different key is required. DeletionPolicy: Snapshot retains a snapshot on stack deletion; it does not migrate data.

References