Amazon MQ brokers should have automatic minor version upgrade enabled
Description
This control checks whether an Amazon MQ broker has automatic minor version upgrade enabled. The control fails if the broker doesn't have automatic minor version upgrade enabled. As Amazon MQ releases and supports new broker engine versions, the changes are backward-compatible with an existing application and don't deprecate existing functionality. Automatic broker engine version updates protect you against security risks, help fix bugs, and improve functionality.
Remediation
To remediate Amazon MQ brokers without automatic minor version upgrade enabled, you need to enable automatic minor version upgrade for the broker.
Steps
- Navigate to the Amazon MQ console
- Select the MQ broker that needs remediation
- Click on 'Edit' or 'Modify' broker
- Go to 'Configuration' settings
- Enable 'Automatic minor version upgrade'
- Review the upgrade settings
- Configure maintenance window if needed
- Review the configuration changes
- Apply the changes to the broker
- Verify automatic minor version upgrade is enabled