AWS New Checks

Ensure Kafka Cluster Encryption in Transit Is Enabled
Profile Applicability Level 2 Description Encryption in transit ensures that all communication between Kafka clients, brokers, and ZooKeeper nodes is p...
Wed, 26 Mar, 2025 at 2:53 AM
Ensure Mutual TLS Authentication Is Enabled for Kafka Clusters
Profile Applicability Level 2 Description  Mutual TLS (mTLS) authentication ensures that both the client and the server authenticate each other during ...
Wed, 26 Mar, 2025 at 2:58 AM
Ensure Kafka Clusters Are Not Exposed to the Public
Profile Applicability Level 2 Description Exposing Kafka clusters to the public internet can lead to unauthorized access, data breaches, and potential ...
Wed, 26 Mar, 2025 at 3:03 AM
Ensure Directory Service LDAP Certificates Expiration Is Monitored and Managed
Profile Applicability: Level 1 Description: Amazon Directory Service enables you to use managed Active Directory (AD) on AWS, and for some directory ...
Wed, 26 Mar, 2025 at 3:03 AM
Ensure MSK Connect Connectors Are Encrypted in Transit
Profile Applicability Level 2 Description Encryption in transit ensures that data exchanged between MSK Connect connectors and Kafka clusters is protec...
Wed, 26 Mar, 2025 at 3:09 AM
Ensure Unused Network Access Control Lists (NACLs) Are Removed
Profile Applicability:  Level 2 Description Network Access Control Lists (NACLs) are used to control inbound and outbound traffic at the subnet level in ...
Wed, 26 Mar, 2025 at 3:14 AM
Ensure Kafka Cluster Encryption at Rest Uses Customer Managed Keys (CMK)
Profile Applicability Level 2 Description Encryption at rest protects sensitive data stored in Kafka clusters by encrypting it on disk. Using Customer ...
Wed, 26 Mar, 2025 at 3:16 AM
Ensure Enhanced Monitoring is Enabled for MSK (Kafka) Brokers
Profile Applicability Level 2 Description Enhanced Monitoring for Amazon MSK brokers provides additional insights into the operations of your Kafka clu...
Wed, 26 Mar, 2025 at 3:22 AM
Ensure MSK Clusters Use the Latest Version
Profile Applicability Level 2 Description Amazon MSK supports multiple versions of Apache Kafka, and using the latest version ensures that your cluster...
Wed, 26 Mar, 2025 at 3:28 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Ports 20 or 21 (FTP)
Profile Applicability:  Level 2 Description TCP ports 20 and 21 are used for FTP (File Transfer Protocol) to transfer files over a network. Allowing unre...
Wed, 26 Mar, 2025 at 3:40 AM