AWS-Kinesis-stream-with-direct-PUT-uses-CMK-server-side-encryption
Severity: High
Description: This control ensure that AWS Kinesis Data Firehose delivery stream with Kinesis Data stream as source has Server-side encryption configured with customer-managed key. It is recommended to have service-side encryption enabled for Amazon Kinesis Delivery Streams with customer-managed key.
Remediation Steps:
Perform following to enable server side encryption for Kinesis:
Login to the AWS Management Console at https://console.aws.amazon.com.
Navigate to Kinesis console.
Go to each kinesis Data firehose delivery stream
Click on Encryption
Click Edit
Mark the box to Enable server-side encryption for source records in delivery stream
Select Use Customer-managed CMK
Select the required key in the dropdown
Click Save.
Important:
Reference:
Blue Hexagon Proprietary