Amazon EMR security configurations should be encrypted in transit
Description
This control checks whether an Amazon EMR security configuration has encryption in transit enabled. The control fails if the security configuration doesn't enable encryption in transit. Data in transit refers to data that moves from one location to another, such as between nodes in your cluster or between your cluster and your application. Data may move across the internet or within a private network. Encrypting data in transit reduces the risk that an unauthorized user can eavesdrop on network traffic.
Remediation
To enable encryption in transit for your EMR security configuration, you need to update the encryption settings.
Steps
- Navigate to the Amazon EMR console
- Go to 'Security configurations' in the left navigation
- Select your security configuration
- Choose 'Edit' to modify the configuration
- In the 'Encryption' section, enable 'Encryption in transit'
- Configure the encryption settings (TLS, certificates, etc.)
- Save the configuration to apply encryption in transit