Loading controls...

Control: 2.2.1 Ensure EBS volume encryption is enabled


Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store(EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.

Default EBS volume encryption only applies to newly created EBS volumes. Existing EBS volumes are not converted automatically.

Encrypting data at rest reduces the likelihood that it is unintentionally exposed and can nullify the impact of disclosure if the encryption remains unbroken.


From Console

  1. Open the Amazon EC2 console using EC2
  2. Under Account attributes, click EBS encryption.
  3. Click Manage.
  4. Click the Enable checkbox.
  5. Click Update EBS encryption
  6. Repeat for every region requiring the change.

From Command Line

  1. Run
aws --region <region> ec2 enable-ebs-encryption-by-default.
  1. Verify that EbsEncryptionByDefault: true is displayed.
  2. Review every region in-use.


Run the control in your terminal:

steampipe check aws_compliance.control.cis_v130_2_2_1

Snapshot and share results via Steampipe Cloud:

steampipe login
steampipe check --share aws_compliance.control.cis_v130_2_2_1


This control uses a named query: