Description
EFS encryption at rest protects files and metadata stored in a shared file system. An unencrypted file system lacks this layer of protection for stored data. Encryption does not restrict users or applications already authorized to read files, so file permissions and network controls are also necessary.
Potential impact
Unauthorized acquisition of stored data can expose operational files or sensitive information shared by multiple workloads. It can also leave organizational data-protection requirements unmet.
Remediation
Set Encrypted: true for new file systems. Specify an appropriate KMS key and permissions when a separate key is required; otherwise EFS uses its default key. Configure encryption in transit and access permissions separately.
An existing file system’s encryption setting cannot be changed. Changing Encrypted in CloudFormation replaces the file system and does not copy its data. Preserve the source and backups, migrate data to an encrypted destination, and verify mounts and application behavior.
Examples
These examples compare file-system creation settings. Mount targets and access controls require separate configuration. Both examples retain data on deletion or replacement, but neither performs data migration.
Before
Resources:
EFSFileSystem01:
Type: AWS::EFS::FileSystem
DeletionPolicy: Retain
UpdateReplacePolicy: Retain
Properties:
BackupPolicy:
Status: ENABLED
Encrypted: false
LifecyclePolicies:
- TransitionToIA: AFTER_60_DAYS
PerformanceMode: generalPurpose
ThroughputMode: bursting
After
Resources:
EFSFileSystem01:
Type: AWS::EFS::FileSystem
DeletionPolicy: Retain
UpdateReplacePolicy: Retain
Properties:
BackupPolicy:
Status: ENABLED
Encrypted: true
LifecyclePolicies:
- TransitionToIA: AFTER_60_DAYS
PerformanceMode: generalPurpose
ThroughputMode: bursting