MSK clusters should use ZooKeeper TLS and security groups

Description

ZooKeeper nodes for MSK clusters should use TLS and be protected by security groups. TLS protects ZooKeeper traffic in transit, and security groups restrict access to approved network paths.

Remediation

Enable ZooKeeper TLS and associate security groups with the broker node group. For guidance, refer to MSK cluster security settings.