Description
AWS::EFS::FileSystem declares shared file storage. Its presence belongs in an asset inventory and does not itself indicate a vulnerability.
Potential impact
An overlooked file system can be missed when reviewing access policies, backups, and operational ownership.
Remediation
Add the file system to the inventory and check encryption, file-system policies, network access, and backup requirements.
Examples
The examples retain backups and tags while explicitly requesting encryption for a new file system. Replacing an existing unencrypted file system requires creating a new one and migrating its data.
Before
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
FileSystemResource:
Type: AWS::EFS::FileSystem
Properties:
BackupPolicy:
Status: ENABLED
FileSystemTags:
- Key: Name
Value: TestFileSystem
After
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
FileSystemResource:
Type: AWS::EFS::FileSystem
Properties:
BackupPolicy:
Status: ENABLED
Encrypted: true
FileSystemTags:
- Key: Name
Value: TestFileSystem