Glossary

    EBS Encryption

    Storage & Database

    EBS Encryption provides seamless encryption for Amazon Elastic Block Store volumes. When enabled, it encrypts data at rest, data in transit between EC2 and EBS, all snapshots, and all volumes created from encrypted snapshots.

    How It Works

    • Uses AES-256 encryption algorithm
    • Keys managed by AWS KMS: use the AWS managed key (aws/ebs) or a customer managed key
    • Encryption/decryption happens on the EC2 host -no performance impact on modern instances (Nitro-based)
    • Default Encryption: enable per-region to automatically encrypt all new volumes

    Best Practices

    • Enable default EBS encryption in every region you use
    • Use customer managed KMS keys for cross-account snapshot sharing and granular key policies
    • Copy unencrypted snapshots as encrypted to migrate existing data
    • Use SCPs to enforce encryption across all accounts in your organization

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.