High EC2 Regional

Block public access settings should be enabled for Amazon EBS snapshots

Description

Flags accounts/regions where EBS snapshot block public access is set to 'unblocked'. Without BPA, any snapshot can be made public (intentionally or by mistake) and would immediately be accessible to every AWS principal.


Remediation

Enable EBS snapshot block public access at the account level.

Steps

  1. Open the Amazon EC2 console and choose EBS encryption / snapshot settings.
  2. Enable Block public access for snapshots (block-all or block-new-sharing).
  3. Apply the change to every region.