A security architect is designing a multi-account AWS environment for a new highly regulated application. The primary requirement is to ensure that all Amazon EBS volumes created in any account within the organization are always encrypted by default, and that unencrypted volume creation is explicitly prevented. Additionally, administrators should not be able to bypass this encryption requirement. Which AWS Organizations feature, combined with a specific policy, can enforce this across all accounts?
- AAWS Organizations Service Control Policies (SCPs) with a deny statement for unencrypted EBS volume creation.
- BAWS CloudFormation StackSets to deploy encrypted EBS volumes.
- CAWS Key Management Service (KMS) key policies to restrict EBS encryption.
- DAWS Config rules with automated remediation via AWS Lambda.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Organizations Service Control Policies (SCPs) with a deny statement for unencrypted EBS volume creation.
AWS Organizations Service Control Policies (SCPs) are preventative guardrails that can explicitly deny actions across all accounts in an organization. An SCP with a deny statement that prevents the creation of unencrypted EBS volumes (e.g., `ec2:RunInstances` or `ec2:CreateVolume` without encryption parameters) will enforce the encryption requirement and prevent administrators from bypassing it, as SCPs override IAM permissions.
Why the other options are wrong
- B. CloudFormation StackSets can deploy resources consistently, but they do not prevent users from manually creating unencrypted EBS volumes outside of StackSets, nor do they override explicit deny actions.
- C. KMS key policies control access to KMS keys, but they don't directly prevent the creation of unencrypted EBS volumes if no key is specified or if an unencrypted option is chosen.
- D. AWS Config rules detect non-compliance and can remediate, but they are reactive. SCPs are proactive and prevent the action from happening in the first place, and cannot be overridden by IAM permissions.
EBS Encryption Enforcement with SCPs
Uses AWS Organizations Service Control Policies (SCPs) to proactively prevent the creation of unencrypted Amazon EBS volumes across all accounts in an organization.
- SCPs are preventative guardrails that apply to all accounts in an OU or organization.
- They cannot be overridden by IAM policies, ensuring strong enforcement.
- A deny statement can prevent actions like `ec2:RunInstances` or `ec2:CreateVolume` if encryption is not specified.
- Ensures mandatory encryption for EBS volumes at creation time.
Memory trick: SCPs stop unencrypted EBS, no admin bypass, organization-wide.