A security architect is designing a multi-account AWS environment for a new highly regulated application. They need to ensure that all data stored in Amazon EBS volumes attached to EC2 instances is encrypted by default. This encryption must use customer-managed keys (CMKs) from AWS Key Management Service (KMS), and the policy must be enforced at an organizational level to prevent any non-compliant EBS volumes from being created. How can this be achieved?
- AUse IAM policies on EC2 roles to enforce EBS encryption with a CMK when instances are launched.
- BApply an AWS Organizations Service Control Policy (SCP) that denies the 'ec2:RunInstances' and 'ec2:CreateVolume' actions if the encryption parameters do not specify a CMK.
- CImplement an AWS Config rule to detect unencrypted EBS volumes and trigger a Lambda function for remediation.
- DConfigure default encryption for EBS in each region for every account, using a specified CMK.
Show answer & explanationAnswer & explanation
Correct answer: B. Apply an AWS Organizations Service Control Policy (SCP) that denies the 'ec2:RunInstances' and 'ec2:CreateVolume' actions if the encryption parameters do not specify a CMK.
To enforce preventive controls at an organizational level, an AWS Organizations Service Control Policy (SCP) is the most effective solution. An SCP can explicitly deny actions like 'ec2:RunInstances' or 'ec2:CreateVolume' if the request parameters do not include the necessary encryption configuration (e.g., KmsKeyId for a CMK or 'Encrypted': 'true' with a default CMK), ensuring that only compliant EBS volumes are created.
Why the other options are wrong
- A. IAM policies control what specific users/roles can do. While useful, they can be bypassed by root users or administrators in child accounts, or simply misconfigured. An SCP provides a higher, unoverridable level of control across the organization.
- C. AWS Config with Lambda is a detective and reactive control. It detects non-compliance after it occurs and then remediates, which is not a preventive measure to stop non-compliant volumes from being created.
- D. While configuring default encryption for EBS in each account/region is good practice, it relies on manual configuration per account and doesn't prevent an override or misconfiguration. It's not a strong organizational-level enforcement.
EBS Encryption Enforcement with SCPs
AWS Organizations Service Control Policies (SCPs) can be used to prevent the creation of unencrypted EBS volumes or volumes not using a specified KMS CMK, enforcing encryption at rest as a preventive control across an entire organization.
- SCPs are preventive, organization-wide guardrails.
- Denies specific EC2 actions if encryption conditions are not met.
- Ensures compliance with encryption-at-rest policies.
Memory trick: SCP's Iron Rule: Encrypted EBS, or No Creation at All.