Optional Readonlydeployment(OPTIONAL) Deployment targets for EBS default volume encryption
You can limit the OUs, accounts, and regions that EBS default volume encryption is deployed to. Please
only specify one of the deploymentTargets or excludeRegions properties. deploymentTargets allows you
to be more granular about where default EBS volume encryption is enabled across your environment.
DeploymentTargets
ReadonlyenableIndicates whether AWS EBS volume have default encryption enabled.
Optional Readonlyexclude(OPTIONAL) List of AWS Region names to be excluded from configuring AWS EBS volume default encryption
Optional Readonlykms(OPTIONAL) KMS key to encrypt EBS volume.
SecurityConfig / CentralSecurityServicesConfig / EbsDefaultVolumeEncryptionConfig
AWS EBS default encryption configuration.
Description
Use this configuration to enable enforced encryption of new EBS volumes and snapshots created in an AWS environment.
Example
Deployment targets:
Excluded regions: