Review the EFS customer managed KMS key

Review EFS encryption at rest and requirements for a customer managed KMS key.

Description

EFS stores application data and shared files, making encryption at rest and key management important. A customer managed KMS key gives your organization control over the key policy and lifecycle.

A file system with Encrypted: true can use an AWS managed key when KmsKeyId is omitted. Do not equate an unspecified customer key with unencrypted storage; verify the actual encryption state and key.

Potential impact

  • An actually unencrypted file system lacks protection from encryption at rest.
  • The default key may not meet organizational requirements for a customer managed key.

Remediation

Set Encrypted: true for new EFS storage and, where a customer key is required, specify its ARN in KmsKeyId in the same Region. Verify key policies and necessary permissions. Changing an existing file system’s encryption or key requires a new file system, so review CloudFormation replacement, data migration and mount cutover. Manage file permissions, TLS and backups separately.

Examples

These compare new file-system settings. Replace the key ARN with a key you can use.

Before

yaml
Resources:
  FileSystem:
    Type: AWS::EFS::FileSystem
    Properties:
      Encrypted: false

This explicitly disables encryption at rest.

After

yaml
Resources:
  FileSystem:
    Type: AWS::EFS::FileSystem
    Properties:
      Encrypted: true
      KmsKeyId: arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012

This encrypts a new file system with the specified key. It does not automatically encrypt or migrate existing data.

References