EBS volume without a specified KMS key

Check that the KMS key used for volume encryption meets policy.

Description

An encrypted EBS volume without KmsKeyId uses the default EBS KMS key configured in that Region. That default can also be a customer managed key; omitting the property does not mean plaintext storage.

Potential impact

If the default key does not meet the volume’s access-control or audit requirements, it may fail the organization’s key-management policy.

Remediation

When a specific key is required, set Encrypted: true and specify a KmsKeyId in the same Region, then check permissions. Changing an existing volume’s key requires creating a new volume through a snapshot.

Examples

The examples compare the default key with an explicitly selected key at volume creation. MyKmsKey must refer to an actual key defined separately.

Before

yaml
Resources:
  DataVolume:
    Type: AWS::EC2::Volume
    Properties:
      Size: 100
      Encrypted: true
      AvailabilityZone: us-west-1a

After

yaml
Resources:
  DataVolume:
    Type: AWS::EC2::Volume
    Properties:
      Size: 100
      Encrypted: true
      AvailabilityZone: us-west-1a
      KmsKeyId: !Ref MyKmsKey

References