This product is not supported for your selected
Datadog site. (
).
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Id: 48207659-729f-4b5c-9402-f884257d794f
Cloud Provider: aws
Framework: Terraform
Severity: High
Category: Encryption
Learn More
Description
AWS Elastic File System (EFS) stores data in clear text by default, potentially exposing sensitive information if the storage system is compromised. When EFS is not encrypted, unauthorized users who gain access to the underlying storage could read file contents, leading to data breaches and compliance violations. To properly secure an EFS file system, set the encrypted
attribute to true
in your Terraform configuration, as shown below:
resource "aws_efs_file_system" "secure_example" {
creation_token = "my-product"
encrypted = true
tags = {
Name = "MyProduct"
}
}
Compliant Code Examples
resource "aws_efs_file_system" "negative1" {
creation_token = "my-product"
encrypted = true
tags = {
Name = "MyProduct"
}
}
Non-Compliant Code Examples
resource "aws_efs_file_system" "positive1" {
creation_token = "my-product"
tags = {
Name = "MyProduct"
}
}
resource "aws_efs_file_system" "positive2" {
creation_token = "my-product"
encrypted = false
tags = {
Name = "MyProduct"
}
}