More Info:

Ensure EBS volumes are encrypted

Risk Level

High

Address

Security

Compliance Standards

HITRUST, AWSWAF, CISAWS, CBP, SOC2, GDPR, PCIDSS

Triage and Remediation

Remediation

  1. Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.

  2. From the navigation bar, select the Region.

  3. From the navigation pane, select EC2 Dashboard.

  4. In the upper-right corner of the page, choose Account Attributes, Data protection and security.

  5. Choose Manage.

  6. Select Enable. You keep the AWS managed key with the alias alias/aws/ebs created on your behalf as the default encryption key, or choose a symmetric customer managed encryption key.

  7. Choose Update EBS encryption.

.