Elastic Compute Cloud (EC2) supports account-level encryption for Elastic Block Store (EBS) service, which uses Key Management Service (KMS) keys. Disabled encryption requires you to build, secure and maintain your own key management infrastructure. You can encrypt volumes and snapshots manually only at creation time - it is impossible to encrypt an existing unencrypted volume or snapshot. While enabled by default, new EBS volumes and snapshot copies are encrypted at rest, which provides an additional layer of data protection.