Amazon EFS file-system inventory

Track EFS file-system purpose and access scope.

Description

AWS::EFS::FileSystem declares shared file storage. Its presence belongs in an asset inventory and does not itself indicate a vulnerability.

Potential impact

An overlooked file system can be missed when reviewing access policies, backups, and operational ownership.

Remediation

Add the file system to the inventory and check encryption, file-system policies, network access, and backup requirements.

Examples

The examples retain backups and tags while explicitly requesting encryption for a new file system. Replacing an existing unencrypted file system requires creating a new one and migrating its data.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  FileSystemResource:
    Type: AWS::EFS::FileSystem
    Properties:
      BackupPolicy:
        Status: ENABLED
      FileSystemTags:
        - Key: Name
          Value: TestFileSystem

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  FileSystemResource:
    Type: AWS::EFS::FileSystem
    Properties:
      BackupPolicy:
        Status: ENABLED
      Encrypted: true
      FileSystemTags:
        - Key: Name
          Value: TestFileSystem

References