Medium EC2 Regional

EC2 Spot Fleet requests with launch parameters should enable encryption for attached EBS volumes

FSBP

Description

Confirms that EC2 Spot Fleet requests with launch parameters have encryption enabled on all attached EBS volumes.


Remediation

To enable EBS encryption for Spot Fleet requests, you need to configure the EBS block device mappings with encryption enabled.

Steps

  1. Open the Amazon EC2 console
  2. Navigate to Spot Requests
  3. Select the Spot Fleet request you want to modify
  4. Click 'Actions' and select 'Modify Spot Fleet request'
  5. In the launch configuration, update the EBS block device mappings
  6. Set 'Encrypted' to 'true' for all EBS volumes
  7. Specify a KMS key if needed for encryption
  8. Save the changes to enable EBS encryption

Compliance

FSBP