MSK clusters should use IAM authentication between clients and brokers

Description

MSK clusters should use IAM authentication between clients and brokers, and other authentication methods should be disabled. IAM auth provides centralized access control and eliminates the need to distribute static credentials.

Remediation

Enable IAM client authentication for the cluster and disable unauthenticated, SCRAM, and mutual TLS access. For guidance, refer to IAM access control for Amazon MSK.