Description
EFS stores application data and shared files, making encryption at rest and key management important. A customer managed KMS key gives your organization control over the key policy and lifecycle.
A file system with Encrypted: true can use an AWS managed key when KmsKeyId is omitted. Do not equate an unspecified customer key with unencrypted storage; verify the actual encryption state and key.
Potential impact
- An actually unencrypted file system lacks protection from encryption at rest.
- The default key may not meet organizational requirements for a customer managed key.
Remediation
Set Encrypted: true for new EFS storage and, where a customer key is required, specify its ARN in KmsKeyId in the same Region. Verify key policies and necessary permissions. Changing an existing file system’s encryption or key requires a new file system, so review CloudFormation replacement, data migration and mount cutover. Manage file permissions, TLS and backups separately.
Examples
These compare new file-system settings. Replace the key ARN with a key you can use.
Before
Resources:
FileSystem:
Type: AWS::EFS::FileSystem
Properties:
Encrypted: false
This explicitly disables encryption at rest.
After
Resources:
FileSystem:
Type: AWS::EFS::FileSystem
Properties:
Encrypted: true
KmsKeyId: arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012
This encrypts a new file system with the specified key. It does not automatically encrypt or migrate existing data.