AWS snapshot created from an unencrypted EBS volume

Verify actual EBS volume and snapshot encryption and protect unencrypted backups.

Description

Backups are recovery assets and copies of sensitive data. A snapshot created from an EBS volume inherits the actual source volume’s encryption state. An unencrypted snapshot lacks encryption-at-rest protection.

Regional encryption defaults can affect the source volume’s actual state. Check both the volume and snapshot rather than rely on the template alone.

Potential impact

Unauthorized acquisition or inappropriate sharing of unencrypted backups can expose application data and sensitive information. Encrypted snapshots also require restricted sharing and KMS permissions.

Remediation

  • Explicitly set encrypted = true for new source EBS volumes and verify actual volume and snapshot encryption.
  • Create encrypted copies of existing unencrypted snapshots. The original snapshot cannot be encrypted directly.
  • Test recovery and data consistency, retaining originals until verified. Plan replacement and attachment changes separately when migrating existing volumes.

Examples

These examples create a new volume and snapshot. For backups of active volumes, also ensure application-data consistency.

Before

hcl
resource "aws_ebs_volume" "source_volume" {
  availability_zone = "us-west-2a"
  size              = 40
  encrypted         = false
}

resource "aws_ebs_snapshot" "snapshot" {
  volume_id = aws_ebs_volume.source_volume.id
}

The source volume does not explicitly request encryption. If it is actually unencrypted, this snapshot is also unencrypted.

After

hcl
resource "aws_ebs_volume" "source_volume" {
  availability_zone = "us-west-2a"
  size              = 40
  encrypted         = true
}

resource "aws_ebs_snapshot" "snapshot" {
  volume_id = aws_ebs_volume.source_volume.id
}

This creates an encrypted snapshot from a new encrypted volume. It does not encrypt an existing snapshot.

References