AWS New Checks

Ensure Kafka Cluster Encryption in Transit Is Enabled
Profile Applicability Level 2 Description Encryption in transit ensures that all communication between Kafka clients, brokers, and ZooKeeper nodes is p...
Tue, 9 Sep, 2025 at 12:23 AM
Ensure Mutual TLS Authentication Is Enabled for Kafka Clusters
Profile Applicability Level 2 Description  Mutual TLS (mTLS) authentication ensures that both the client and the server authenticate each other during ...
Wed, 10 Sep, 2025 at 6:16 AM
Ensure Kafka Clusters Are Not Exposed to the Public
Profile Applicability Level 2 Description Exposing Kafka clusters to the public internet can lead to unauthorized access, data breaches, and potential ...
Wed, 10 Sep, 2025 at 6:22 AM
Ensure Directory Service LDAP Certificates Expiration Is Monitored and Managed
Profile Applicability: Level 1 Description: Amazon Directory Service enables you to use managed Active Directory (AD) on AWS, and for some directory ...
Wed, 26 Mar, 2025 at 3:03 AM
Ensure MSK Connect Connectors Are Encrypted in Transit
Profile Applicability Level 2 Description Encryption in transit ensures that data exchanged between MSK Connect connectors and Kafka clusters is protec...
Tue, 9 Sep, 2025 at 12:14 AM
Ensure Unused Network Access Control Lists (NACLs) Are Removed
Profile Applicability:  Level 2 Description Network Access Control Lists (NACLs) are used to control inbound and outbound traffic at the subnet level in ...
Thu, 11 Sep, 2025 at 4:48 AM
Ensure Kafka Cluster Encryption at Rest Uses Customer Managed Keys (CMK)
Profile Applicability Level 2 Description Encryption at rest protects sensitive data stored in Kafka clusters by encrypting it on disk. Using Customer ...
Wed, 10 Sep, 2025 at 6:05 AM
Ensure Enhanced Monitoring is Enabled for MSK (Kafka) Brokers
Profile Applicability Level 2 Description Enhanced Monitoring for Amazon MSK brokers provides additional insights into the operations of your Kafka clu...
Wed, 10 Sep, 2025 at 6:03 AM
Ensure MSK Clusters Use the Latest Version
Profile Applicability Level 2 Description Amazon MSK supports multiple versions of Apache Kafka, and using the latest version ensures that your cluster...
Wed, 10 Sep, 2025 at 6:03 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Ports 20 or 21 (FTP)
Profile Applicability:  Level 2 Description TCP ports 20 and 21 are used for FTP (File Transfer Protocol) to transfer files over a network. Allowing unre...
Thu, 11 Sep, 2025 at 4:51 AM