Skip to main content

More Info:

Ensure that your Amazon EFS file systems are encrypted in order to meet security and compliance requirements. Your data is transparently encrypted while being written and transparently decrypted while being read from your file system, therefore the encryption process does not require any additional action from you or your application. Encryption keys are managed by AWS KMS service, eliminating the need to build and maintain a secure key management infrastructure.

Risk Level

High

Address

Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS AWS
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • Cloudanix Best Practice
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • GDPR
  • HIPAA
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • Reserve Bank of India (RBI) Cyber Security Framework
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • Securities and Exchange Board of India (SEBI) - Cloud Security Adoption Framework
  • StateRAMP
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Using Console

To remediate the EFS Encryption Enabled misconfiguration in AWS, you can follow the below steps:
  1. Open the AWS Management Console and navigate to the Amazon Elastic File System (EFS) service.
  2. Select the EFS file system that needs to be remediated.
  3. Click on the “Actions” button and select “Modify file system”.
  4. In the “Modify file system” window, scroll down to the “Encryption” section.
  5. Disable the encryption by selecting “No” for the “Encrypt file system” option.
  6. Click on the “Modify” button to save the changes.
  7. Once the changes are saved, the EFS file system will be unencrypted.
Note: If you need to encrypt the EFS file system, you can follow the same steps and select “Yes” for the “Encrypt file system” option in step 5.

To remediate the misconfiguration of EFS Encryption Enabled in AWS using AWS CLI, follow these steps:
  1. Open the AWS CLI on your local machine.
  2. Run the following command to get a list of all the EFS file systems in your AWS account:
  1. Identify the EFS file system that has encryption disabled.
  2. Run the following command to enable encryption for the identified EFS file system:
Replace <file-system-id> with the ID of the EFS file system that you want to enable encryption for.
  1. Verify that encryption is enabled for the EFS file system by running the following command:
Replace <file-system-id> with the ID of the EFS file system that you enabled encryption for.
  1. Repeat the above steps for all the EFS file systems in your AWS account that have encryption disabled.
By following these steps, you can remediate the misconfiguration of EFS Encryption Enabled in AWS using AWS CLI.
To remediate the EFS Encryption Enabled misconfiguration in AWS using Python, follow these steps:
  1. Open the AWS console and navigate to the EFS service.
  2. Select the EFS file system that has encryption enabled.
  3. Click on the “Modify” button in the top menu bar.
  4. Scroll down to the “Encryption” section and select “No” in the “Encryption” dropdown menu.
  5. Click on the “Save” button to disable encryption for the EFS file system.
To do this programmatically using Python, you can use the AWS SDK for Python (Boto3) to modify the encryption setting for the EFS file system. Here’s an example code snippet to disable encryption for an EFS file system:
Make sure to replace fs-12345678 with the actual ID of the EFS file system that you want to remediate.
Enabling or changing encrypted/kms_key_id on an existing aws_efs_file_system forces replacement of the file system, which deletes the old one and its data; plan carefully to avoid outage and data loss.To verify, terraform plan should show either:
  • creating a new aws_efs_file_system with encrypted: "true" and the desired kms_key_id, or
  • replacing the existing file system where the diff includes encrypted: "false" => "true" (and/or a change to kms_key_id) with -/+ on the resource.

Additional Reading: