Medium
EC2
Regional
EC2 Spot Fleet requests with launch parameters should enable encryption for attached EBS volumes
FSBP
Description
Confirms that EC2 Spot Fleet requests with launch parameters have encryption enabled on all attached EBS volumes.
Remediation
To enable EBS encryption for Spot Fleet requests, you need to configure the EBS block device mappings with encryption enabled.
Steps
- Open the Amazon EC2 console
- Navigate to Spot Requests
- Select the Spot Fleet request you want to modify
- Click 'Actions' and select 'Modify Spot Fleet request'
- In the launch configuration, update the EBS block device mappings
- Set 'Encrypted' to 'true' for all EBS volumes
- Specify a KMS key if needed for encryption
- Save the changes to enable EBS encryption
Compliance
FSBP