Skip to main content
compliance · aws

EBS volumes created without encryption at rest

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags an Amazon EBS volume whose `Encrypted` attribute from `ec2:DescribeVolumes` is false. AWS cannot encrypt an existing volume in place; the fix is to snapshot it, create an encrypted copy, and swap it in. The finding is high severity with no saving, since unencrypted data at rest usually fails security baselines and audit controls.

Signal and threshold

How ZopNight evaluates EBS volumes created without encryption at rest.
Field Value
Rule IDsRC-172
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdEncrypted = false
SourceZopNight
Permissions usedec2:DescribeVolumes · ec2:GetEbsEncryptionByDefault

Why an unencrypted volume is a finding on its own

Encrypted EBS volumes protect data at rest, the snapshots taken from them and the volumes restored from those snapshots. The EBS encryption guide states that you cannot remove encryption from a volume, and equally that you cannot directly encrypt an existing unencrypted one. Once a volume is created unencrypted it stays that way, and every snapshot of it inherits the gap. Security baselines and audit frameworks commonly require encryption at rest, so each such volume is an exception someone has to explain.

Listing unencrypted volumes and the account default

Terminal window
aws ec2 describe-volumes --filters Name=encrypted,Values=false \
--query 'Volumes[].[VolumeId,Size,State,Attachments[0].InstanceId]' --output table
aws ec2 get-ebs-encryption-by-default --query EbsEncryptionByDefault

If the second command prints false, new volumes in that Region will keep being created unencrypted unless a launch template asks otherwise.

What triggers the finding

ZopNight reads the encryption flag AWS reports for each volume. The rule fires only when the flag is present and false. Attached and detached volumes are treated alike.

When the volume is left out

If the encryption flag was not collected for a volume, no finding is raised. A tag on the volume that claims it is encrypted has no effect; only the value AWS reports counts. The broader Resource Not Encrypted At Rest rule can also report the same volume.

Compliance exposure, no saving

The estimate is fixed at $0 per month. The risk is audit and data exposure: a detached unencrypted volume, or a snapshot shared by mistake, exposes readable data to anyone who can attach it.

Replacing a volume with an encrypted copy

  1. Create a snapshot: aws ec2 create-snapshot --volume-id vol-0abc.
  2. Create an encrypted volume from it in the same Availability Zone: aws ec2 create-volume --snapshot-id snap-0abc --availability-zone us-east-1a --encrypted (add --kms-key-id for a customer managed key).
  3. Stop the instance, detach the old volume, attach the new one on the same device name, and start the instance.
  4. Turn on encryption by default for the Region so this does not recur: aws ec2 enable-ebs-encryption-by-default.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·