---
title: EFS data should be encrypted at rest
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Datadog Security > OOTB Rules > EFS data should be encrypted at rest
---

# EFS data should be encrypted at rest
 
## Description{% #description %}

This control evaluates whether Amazon EFS is set up to encrypt file data at rest through AWS KMS.

It is recommended to utilize encrypted file systems. This is supported by Amazon EFS and can be enabled during the creation of a file system.

## Remediation{% #remediation %}

To learn how to enable encryption for a new Amazon EFS file system, consult the [Encrypting Data at Rest](https://docs.aws.amazon.com/efs/latest/ug/encryption-at-rest.html) section in the Amazon EFS User Guide.
