Amazon EBS volume inventory

Include EBS volumes and their data in the asset inventory.

Description

AWS::EC2::Volume declares an EBS block-storage volume for EC2. This is inventory information about a volume’s presence, not a vulnerability by itself.

Potential impact

An unmanaged volume can be missed during encryption, snapshot, and deletion-policy reviews.

Remediation

Record the volume’s owner, attachment, and data purpose, and check encryption, snapshot retention, and deletion policies.

Examples

The examples create a 100 GiB volume in us-east-1a; the second explicitly requests encryption. When omitted, account and Region EBS encryption defaults also matter. Encrypting an existing volume requires considering snapshot copying and migration to a new volume.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  NewVolume:
    Type: AWS::EC2::Volume
    Properties:
      Size: 100
      AvailabilityZone: us-east-1a

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  NewVolume:
    Type: AWS::EC2::Volume
    Properties:
      Size: 100
      AvailabilityZone: us-east-1a
      Encrypted: true

References