Posted On: Jun 25, 2019

We are excited to announce the availability of Encryption by Default for all new EBS volumes created in an account within a region in Amazon Web Services China (Beijing) Region operated by Sinnet, and Amazon Web Services China (Ningxia) Region operated by NWCD. 

You can now enable Amazon Elastic Block Store (EBS) Encryption by Default, ensuring that all new EBS volumes created in your account are encrypted. Encryption by Default opt-in settings are specific to individual Amazon Web Services regions in your account. This feature makes it easier for you to encrypt data on EBS so that you achieve your compliance and security goals.  

Previously, you explicitly specified encryption for every new EBS volume that was created. In order to ensure that all new volumes were encrypted, you either wrote an IAM policy to terminate an instance launch when encryption was not specified or maintained custom scripts to detect unencrypted volumes and copied the data to encrypted volumes. Now you can enable EBS Encryption by Default with a single API call per region. Once you enable EBS Encryption by Default, all newly created volumes are encrypted without having to specify encryption for each volume. This simplifies your workflow to ensure that only encrypted volumes are created. Furthermore, you can set one of your customer-managed customer master keys (CMK) as the default CMK for EBS encryption instead of an Amazon Web Services-managed CMK. As a result, you can have more granular control over who can access data that is encrypted by default.  

To get started, see the technical documentation on enabling EBS Encryption by Default. This feature is now available through the Amazon Web Services Management Console, Amazon Command Line Interface (CLI) or Amazon SDKs at no extra charge in all commercial regions.