Medium EFS Regional

EFS file systems should be encrypted at rest

CIS v5.0.0CIS v2.3.1HIPAA

Description

Confirms that EFS file systems encrypt stored data at rest with AWS KMS.


Remediation

To enable encryption for your EFS file system, you need to create a new encrypted file system and migrate your data, as encryption cannot be enabled on existing file systems.

Steps

  1. Navigate to the Amazon EFS console
  2. Create a new file system with encryption enabled
  3. Configure the encryption settings using AWS KMS
  4. Migrate your data from the unencrypted file system to the new encrypted one
  5. Update your applications to use the new encrypted file system
  6. Delete the old unencrypted file system once migration is complete

Compliance

CIS v5.0.0CIS v2.3.1HIPAA