EFS file system with encryption disabled

Encrypt EFS data at rest and preserve existing data when migrating a file system.

Description

EFS encryption at rest protects files and metadata stored in a shared file system. An unencrypted file system lacks this layer of protection for stored data. Encryption does not restrict users or applications already authorized to read files, so file permissions and network controls are also necessary.

Potential impact

Unauthorized acquisition of stored data can expose operational files or sensitive information shared by multiple workloads. It can also leave organizational data-protection requirements unmet.

Remediation

Set Encrypted: true for new file systems. Specify an appropriate KMS key and permissions when a separate key is required; otherwise EFS uses its default key. Configure encryption in transit and access permissions separately.

An existing file system’s encryption setting cannot be changed. Changing Encrypted in CloudFormation replaces the file system and does not copy its data. Preserve the source and backups, migrate data to an encrypted destination, and verify mounts and application behavior.

Examples

These examples compare file-system creation settings. Mount targets and access controls require separate configuration. Both examples retain data on deletion or replacement, but neither performs data migration.

Before

yaml
Resources:
  EFSFileSystem01:
    Type: AWS::EFS::FileSystem
    DeletionPolicy: Retain
    UpdateReplacePolicy: Retain
    Properties:
      BackupPolicy:
        Status: ENABLED
      Encrypted: false
      LifecyclePolicies:
        - TransitionToIA: AFTER_60_DAYS
      PerformanceMode: generalPurpose
      ThroughputMode: bursting

After

yaml
Resources:
  EFSFileSystem01:
    Type: AWS::EFS::FileSystem
    DeletionPolicy: Retain
    UpdateReplacePolicy: Retain
    Properties:
      BackupPolicy:
        Status: ENABLED
      Encrypted: true
      LifecyclePolicies:
        - TransitionToIA: AFTER_60_DAYS
      PerformanceMode: generalPurpose
      ThroughputMode: bursting

References