AWS Kinesis Data Streams inventory

Document data streams and the systems that use them.

Description

A Kinesis Data Streams inventory helps identify real-time data paths and their owners. The existence of a stream is not itself a vulnerability.

Potential impact

An incomplete inventory can leave streams out of data-flow analysis or access and retention reviews.

Remediation

Record each stream’s owning team, producers, and consumers, then check encryption, access policies, and retention.

Examples

The examples add service and environment tags to a stream without changing data delivery or encryption settings.

Before

hcl
resource "aws_kinesis_stream" "events" {
  name        = "events"
  shard_count = 1
}

After

hcl
resource "aws_kinesis_stream" "events" {
  name        = "events"
  shard_count = 1

  tags = {
    Service     = "events"
    Environment = "production"
  }
}

References