Not all data stored in the EBS snapshot is securely encrypted
Description
EBS snapshots must be encrypted, as they often include sensitive information, customer PII or CPNI. Amazon EBS encryption uses AWS Key Management Service (AWS KMS) customer master keys (CMK) when creating encrypted volumes and snapshots. With EBS encryption enabled, you no longer have to build, maintain, and secure your own key management infrastructure.
Fix - Runtime
AWS Console
To change the policy using the AWS Console, follow these steps: