Medium Protect Regional

MSK clusters should be encrypted in transit among broker nodes

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA

Description

Confirms that Amazon MSK clusters encrypt data in transit between broker nodes using TLS, with no plain-text connections permitted.


Remediation

Enable TLS encryption for in-cluster broker node communication.

Steps

  1. Navigate to the Amazon MSK console
  2. Select the MSK cluster
  3. Enable 'Encryption in transit' with 'In-cluster encryption' on
  4. Verify encryption is enabled

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA