Description
AWS::SNS::Topic declares a topic for delivering notifications and messages. Its presence is asset information; using a topic is not itself a vulnerability.
Potential impact
An omitted topic can be missed during publisher-permission and subscription reviews, obscuring message-delivery paths.
Remediation
Record the topic’s owner and purpose, and check topic policies, publish permissions, subscription endpoints, and encryption at rest.
Examples
The second example selects a KMS key to encrypt stored message bodies. Grant publishers the required key permissions and check the connected services’ key-support requirements.
Before
yaml
Resources:
SnsTopic:
Type: AWS::SNS::Topic
Properties:
TopicName: alarm-action
After
yaml
Resources:
SnsTopic:
Type: AWS::SNS::Topic
Properties:
TopicName: alarm-action
KmsMasterKeyId: alias/aws/sns