Amazon Kinesis Data Streams inventory

Include data streams, producers, and consumers in the inventory.

Description

AWS::Kinesis::Stream declares a Kinesis Data Streams data stream. This inventory information identifies its presence; using a stream is not itself a security issue.

Potential impact

An omitted stream can be missed during reviews of data retention, access, and processing failures.

Remediation

Record the stream’s owner, producers, and consumers, and check encryption keys, retention, access policies, and throughput requirements.

Examples

The second excerpt increases retention from 24 to 168 hours and specifies KMS encryption. Set required capacity separately and choose retention for recovery needs and cost.

Before

yaml
Resources:
  MyStream:
    Type: AWS::Kinesis::Stream
    Properties:
      Name: MyKinesisStream1
      RetentionPeriodHours: 24

After

yaml
Resources:
  MyStream:
    Type: AWS::Kinesis::Stream
    Properties:
      Name: MyKinesisStream1
      RetentionPeriodHours: 168
      StreamEncryption:
        EncryptionType: KMS
        KeyId: alias/aws/kinesis

References