A recent security review at Global Dynamics identified unencrypted EBS volumes, and the cloud infrastructure team needs to ensure all newly created volumes are encrypted by default. A solutions architect must implement a solution to encrypt all new EBS volumes at rest. Which solution will meet this requirement with the LEAST effort?