Description
AWS::EC2::Volume declares an EBS block-storage volume for EC2. This is inventory information about a volume’s presence, not a vulnerability by itself.
Potential impact
An unmanaged volume can be missed during encryption, snapshot, and deletion-policy reviews.
Remediation
Record the volume’s owner, attachment, and data purpose, and check encryption, snapshot retention, and deletion policies.
Examples
The examples create a 100 GiB volume in us-east-1a; the second explicitly requests encryption. When omitted, account and Region EBS encryption defaults also matter. Encrypting an existing volume requires considering snapshot copying and migration to a new volume.
Before
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
NewVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
AvailabilityZone: us-east-1a
After
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
NewVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
AvailabilityZone: us-east-1a
Encrypted: true