Medium
Protect
Regional
MSK clusters should be encrypted in transit among broker nodes
NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA
Description
Confirms that Amazon MSK clusters encrypt data in transit between broker nodes using TLS, with no plain-text connections permitted.
Remediation
Enable TLS encryption for in-cluster broker node communication.
Steps
- Navigate to the Amazon MSK console
- Select the MSK cluster
- Enable 'Encryption in transit' with 'In-cluster encryption' on
- Verify encryption is enabled
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1ISO 27001HIPAA