EMR cluster has no security configuration attached

Attach an EMR security configuration with the required encryption and authentication settings.

Description

EMR uses SecurityConfiguration to apply settings such as encryption or Kerberos authentication to a cluster. Without the required security configuration attached, those settings are not applied to the cluster.

Potential impact

The workload may not meet its data protection or authentication requirements.

Remediation

Specify a reviewed security configuration’s name in SecurityConfiguration when creating the cluster. Check its settings and prerequisites, including keys and certificates.

Examples

The excerpts reference a separately defined EMRSecurityConfiguration. Attaching its name does not enable every security feature within it.

Before

yaml
Resources:
  EMRCluster:
    Type: AWS::EMR::Cluster
    Properties:
      Name: analytics-cluster
      ReleaseLabel: emr-6.14.0

After

yaml
Resources:
  EMRCluster:
    Type: AWS::EMR::Cluster
    Properties:
      Name: analytics-cluster
      ReleaseLabel: emr-6.14.0
      SecurityConfiguration: !Ref EMRSecurityConfiguration

References