EBS volumes created without encryption at rest
What does ZopNight detect here?
ZopNight flags an Amazon EBS volume whose `Encrypted` attribute from `ec2:DescribeVolumes` is false. AWS cannot encrypt an existing volume in place; the fix is to snapshot it, create an encrypted copy, and swap it in. The finding is high severity with no saving, since unencrypted data at rest usually fails security baselines and audit controls.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-172 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | Encrypted = false |
| Source | ZopNight |
| Permissions used | ec2:DescribeVolumes · ec2:GetEbsEncryptionByDefault |
Where it applies
Why an unencrypted volume is a finding on its own
Encrypted EBS volumes protect data at rest, the snapshots taken from them and the volumes restored from those snapshots. The EBS encryption guide states that you cannot remove encryption from a volume, and equally that you cannot directly encrypt an existing unencrypted one. Once a volume is created unencrypted it stays that way, and every snapshot of it inherits the gap. Security baselines and audit frameworks commonly require encryption at rest, so each such volume is an exception someone has to explain.
Listing unencrypted volumes and the account default
aws ec2 describe-volumes --filters Name=encrypted,Values=false \ --query 'Volumes[].[VolumeId,Size,State,Attachments[0].InstanceId]' --output table
aws ec2 get-ebs-encryption-by-default --query EbsEncryptionByDefaultIf the second command prints false, new volumes in that Region will keep being created
unencrypted unless a launch template asks otherwise.
What triggers the finding
ZopNight reads the encryption flag AWS reports for each volume. The rule fires only when the flag is present and false. Attached and detached volumes are treated alike.
When the volume is left out
If the encryption flag was not collected for a volume, no finding is raised. A tag on the volume that claims it is encrypted has no effect; only the value AWS reports counts. The broader Resource Not Encrypted At Rest rule can also report the same volume.
Compliance exposure, no saving
The estimate is fixed at $0 per month. The risk is audit and data exposure: a detached unencrypted volume, or a snapshot shared by mistake, exposes readable data to anyone who can attach it.
Replacing a volume with an encrypted copy
- Create a snapshot:
aws ec2 create-snapshot --volume-id vol-0abc. - Create an encrypted volume from it in the same Availability Zone:
aws ec2 create-volume --snapshot-id snap-0abc --availability-zone us-east-1a --encrypted(add--kms-key-idfor a customer managed key). - Stop the instance, detach the old volume, attach the new one on the same device name, and start the instance.
- Turn on encryption by default for the Region so this does not recur:
aws ec2 enable-ebs-encryption-by-default.