Description
A Kinesis Data Streams inventory helps identify real-time data paths and their owners. The existence of a stream is not itself a vulnerability.
Potential impact
An incomplete inventory can leave streams out of data-flow analysis or access and retention reviews.
Remediation
Record each stream’s owning team, producers, and consumers, then check encryption, access policies, and retention.
Examples
The examples add service and environment tags to a stream without changing data delivery or encryption settings.
Before
hcl
resource "aws_kinesis_stream" "events" {
name = "events"
shard_count = 1
}
After
hcl
resource "aws_kinesis_stream" "events" {
name = "events"
shard_count = 1
tags = {
Service = "events"
Environment = "production"
}
}