MSK clusters should be encrypted in transit among broker nodes

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This rule checks whether Amazon MSK clusters have encryption enabled for data in transit among broker nodes.

By default, Amazon MSK encrypts data in transit within the cluster. This setting can be modified during the cluster creation process.

Remediation

To configure encryption in transit for MSK clusters, adjust the encryption settings during cluster creation. For detailed steps on setting up encryption in transit, refer to Updating security settings of a cluster in the Amazon Managed Streaming for Apache Kafka Developer Guide.