Description
An EFS file-system inventory identifies shared storage, its users, and its owners. The existence of a file system is not itself a vulnerability.
Potential impact
Unlisted file systems may be missed in access-policy or backup reviews, and their storage costs can be harder to track.
Remediation
Record each file system’s owner and workloads, then check mount targets, security groups, encryption, and backups.
Examples
These excerpts add identification tags to a file system. Network access and data protection require separate configuration.
Before
hcl
resource "aws_efs_file_system" "shared" {
creation_token = "shared-storage"
}
After
hcl
resource "aws_efs_file_system" "shared" {
creation_token = "shared-storage"
tags = {
Service = "shared-storage"
Environment = "production"
}
}