Description
AWS::SQS::Queue declares a message queue. Its presence belongs in the asset inventory and is not itself a vulnerability.
Potential impact
An omitted queue can be missed during access and redrive-policy reviews, leaving message flows needed for incident response unclear.
Remediation
Record the queue’s owner, producers, and consumers, and check queue policies, encryption, message retention, and failed-message handling.
Examples
The first configuration uses default SSE-SQS encryption at rest; the second selects SSE-KMS for new messages. When using KMS, also grant producers and consumers the required key permissions.
Before
yaml
Resources:
MyQueue:
Type: AWS::SQS::Queue
Properties:
QueueName: SampleQueue
After
yaml
Resources:
MyQueue:
Type: AWS::SQS::Queue
Properties:
QueueName: SampleQueue
KmsMasterKeyId: alias/aws/sqs