Description
EMR uses SecurityConfiguration to apply settings such as encryption or Kerberos authentication to a cluster. Without the required security configuration attached, those settings are not applied to the cluster.
Potential impact
The workload may not meet its data protection or authentication requirements.
Remediation
Specify a reviewed security configuration’s name in SecurityConfiguration when creating the cluster. Check its settings and prerequisites, including keys and certificates.
Examples
The excerpts reference a separately defined EMRSecurityConfiguration. Attaching its name does not enable every security feature within it.
Before
yaml
Resources:
EMRCluster:
Type: AWS::EMR::Cluster
Properties:
Name: analytics-cluster
ReleaseLabel: emr-6.14.0
After
yaml
Resources:
EMRCluster:
Type: AWS::EMR::Cluster
Properties:
Name: analytics-cluster
ReleaseLabel: emr-6.14.0
SecurityConfiguration: !Ref EMRSecurityConfiguration