Skip to content

Latest commit

 

History

History
35 lines (31 loc) · 3.51 KB

ebs-encrypted-snapshots.md

File metadata and controls

35 lines (31 loc) · 3.51 KB

CloudSploit

AWS / EC2 / EBS Encrypted Snapshots

Quick Info

Plugin Title EBS Encrypted Snapshots
Cloud AWS
Category EC2
Description Ensures EBS snapshots are encrypted at rest
More Info EBS snapshots should have at-rest encryption enabled through AWS using KMS. If the volume was not encrypted and a snapshot was taken the snapshot will be unencrypted.
AWS Link https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSSnapshots.html#encryption-support
Recommended Action Configure volume encryption and delete unencrypted EBS snapshots.

Detailed Remediation Steps

  1. Log in to the AWS Management Console.
  2. Select the "Services" option and search for EC2.
  3. Scroll down the left navigation panel and choose "Snapshots".
  4. Select the "Snapshot" that needs to be verified and click on its name from the "Name" column.
  5. Scroll down the page and under "Details" check for "Encrypted". If the "Encrypted" option is showing "Not Encrypted" then the selected the "EBS Snapshot" is not encrypted.
  6. Repeat the steps number 2 - 5 to check other "EBS Snapshot" in the AWS region.
  7. Select the unencrypted "EBS Snapshot" that needs to be encrypted and click on the "Actions" button at the top panel and click on the "Copy snapshot" option.
  8. In the "Copy Snapshot" dialog box select the box "Encrypt this snapshot" next to "Encryption" and choose the "KMS key" from the dropdown menu.
  9. Click on the "Copy snapshot" button to copy the selected "EBS Snapshot".
  10. Select the new EBS snapshot and click on the "Actions" button at the top panel and click on the "Create Volume from snapshot" option.
  11. In the "Create Volume" dialog box verify the "Encryption" option is enabled.
  12. Click on the "Create Volume" button to create the new "EBS Encrypted Volume".
  13. Scroll down the left navigation panel and click on the "Volumes".
  14. Select the volume that is not encrypted and click on the "Action" button at the top and click on the "Detach Volume".
  15. In the "Detach Volume" dialog box click on the "Detach" button.
  16. Select the newly encrypted EBS volume and click on the "Action" button at the top and click on the "Attach Volume".
  17. In the "Attach Volume" dialog box select the EC2 instance and device name for the attachment.
  18. Repeat steps number 7 - 17 to ensure "EBS snapshots" are encrypted at rest.