Skip to content

Files

Latest commit

 

History

History
31 lines (22 loc) · 706 Bytes

AWS048.md

File metadata and controls

31 lines (22 loc) · 706 Bytes

Pattern: EFS Encryption has not been enabled

Issue: -

Description

If your organization is subject to corporate or regulatory policies that require encryption of data and metadata at rest, we recommend creating a file system that is encrypted at rest, and mounting your file system using encryption of data in transit.

Resolution: Enable encryption for EFS.

Examples

Example of incorrect code:

resource "aws_efs_file_system" "bad_example" {
  name       = "bar"
  encrypted  = false
  kms_key_id = ""
}

Example of correct code:

resource "aws_efs_file_system" "good_example" {
  name       = "bar"
  encrypted  = true
  kms_key_id = "my_kms_key"
}