Description
Secure initial configuration should be backed by controls that identify mistakes later. The AWS Config managed rule ENCRYPTED_VOLUMES evaluates encryption of EBS volumes attached to EC2 instances.
Without the rule or functioning evaluations, unencrypted volumes may go unnoticed. The rule does not itself encrypt volumes or automatically notify users.
Potential impact
Unencrypted volumes may remain in use, and ongoing compliance with encryption requirements becomes harder to verify. This rule should not be treated as coverage of every unattached volume.
Remediation
- Add an
aws_config_config_rulewithsource_identifier = "ENCRYPTED_VOLUMES". - Verify AWS Config recording and rule evaluation in the account and Region, and connect results to notification or review procedures.
- Address noncompliant volumes through a separate data-preservation and encrypted-migration process. Review unattached volumes separately.
Examples
These are Config rule excerpts. Configure the required recorder and permissions separately. Add the EBS rule without removing the password-policy rule.
Before
resource "aws_config_config_rule" "password_policy_rule" {
name = "some_rule"
source {
owner = "AWS"
source_identifier = "IAM_PASSWORD_POLICY"
}
}
This rule evaluates IAM password policy, not EBS encryption.
After
resource "aws_config_config_rule" "encrypted_volumes_rule" {
name = "encrypted_vols_rule"
source {
owner = "AWS"
source_identifier = "ENCRYPTED_VOLUMES"
}
}
This adds a rule for attached EBS volumes. Verify evaluation results and the handling of noncompliant volumes after deployment.