Low Identify Regional

Amazon MQ brokers should have automatic minor version upgrade enabled

NIST 800-53PCI DSS v4.0.1PCI DSS v6.3.3

Description

This control checks whether an Amazon MQ broker has automatic minor version upgrade enabled. The control fails if the broker doesn't have automatic minor version upgrade enabled. As Amazon MQ releases and supports new broker engine versions, the changes are backward-compatible with an existing application and don't deprecate existing functionality. Automatic broker engine version updates protect you against security risks, help fix bugs, and improve functionality.


Remediation

To remediate Amazon MQ brokers without automatic minor version upgrade enabled, you need to enable automatic minor version upgrade for the broker.

Steps

  1. Navigate to the Amazon MQ console
  2. Select the MQ broker that needs remediation
  3. Click on 'Edit' or 'Modify' broker
  4. Go to 'Configuration' settings
  5. Enable 'Automatic minor version upgrade'
  6. Review the upgrade settings
  7. Configure maintenance window if needed
  8. Review the configuration changes
  9. Apply the changes to the broker
  10. Verify automatic minor version upgrade is enabled

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v6.3.3