Glossary

    EFS Security

    Storage & Database

    Amazon EFS (Elastic File System) provides scalable NFS file storage. Security is managed through multiple layers.

    Network Security

    • EFS mount targets live in VPC subnets - accessible only from within the VPC
    • Security groups on mount targets control which EC2 instances or containers can connect
    • No public access possible - EFS is VPC-only by design

    Encryption

    • At Rest: AES-256 using KMS; must be enabled at creation
    • In Transit: TLS 1.2 encryption using the EFS mount helper

    Access Control

    • IAM Authorization: file system policies and IAM identity policies for mount/read/write
    • Access Points: enforce POSIX user/group identity and root directory per application
    • POSIX Permissions: standard Unix file permissions (owner, group, other)

    Related AWS Services

    Related Content

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.