Configuration without an ENCRYPTED_VOLUMES AWS Config rule

Evaluate encryption of attached EBS volumes with AWS Config and connect results to operational review.

Description

Secure initial configuration should be backed by controls that identify mistakes later. The AWS Config managed rule ENCRYPTED_VOLUMES evaluates encryption of EBS volumes attached to EC2 instances.

Without the rule or functioning evaluations, unencrypted volumes may go unnoticed. The rule does not itself encrypt volumes or automatically notify users.

Potential impact

Unencrypted volumes may remain in use, and ongoing compliance with encryption requirements becomes harder to verify. This rule should not be treated as coverage of every unattached volume.

Remediation

  • Add an aws_config_config_rule with source_identifier = "ENCRYPTED_VOLUMES".
  • Verify AWS Config recording and rule evaluation in the account and Region, and connect results to notification or review procedures.
  • Address noncompliant volumes through a separate data-preservation and encrypted-migration process. Review unattached volumes separately.

Examples

These are Config rule excerpts. Configure the required recorder and permissions separately. Add the EBS rule without removing the password-policy rule.

Before

hcl
resource "aws_config_config_rule" "password_policy_rule" {
  name = "some_rule"

  source {
    owner             = "AWS"
    source_identifier = "IAM_PASSWORD_POLICY"
  }
}

This rule evaluates IAM password policy, not EBS encryption.

After

hcl
resource "aws_config_config_rule" "encrypted_volumes_rule" {
  name = "encrypted_vols_rule"

  source {
    owner             = "AWS"
    source_identifier = "ENCRYPTED_VOLUMES"
  }
}

This adds a rule for attached EBS volumes. Verify evaluation results and the handling of noncompliant volumes after deployment.

References