Description
AWS::Kinesis::Stream declares a Kinesis Data Streams data stream. This inventory information identifies its presence; using a stream is not itself a security issue.
Potential impact
An omitted stream can be missed during reviews of data retention, access, and processing failures.
Remediation
Record the stream’s owner, producers, and consumers, and check encryption keys, retention, access policies, and throughput requirements.
Examples
The second excerpt increases retention from 24 to 168 hours and specifies KMS encryption. Set required capacity separately and choose retention for recovery needs and cost.
Before
yaml
Resources:
MyStream:
Type: AWS::Kinesis::Stream
Properties:
Name: MyKinesisStream1
RetentionPeriodHours: 24
After
yaml
Resources:
MyStream:
Type: AWS::Kinesis::Stream
Properties:
Name: MyKinesisStream1
RetentionPeriodHours: 168
StreamEncryption:
EncryptionType: KMS
KeyId: alias/aws/kinesis