Medium
CloudFront
CloudFront distributions should require encryption in transit
NISTISO 27001
Description
Checks whether an Amazon CloudFront distribution requires viewers to use HTTPS for encryption in transit.
Remediation
To enforce HTTPS for a CloudFront distribution, see the Amazon CloudFront Developer Guide.
Steps
- Open the Amazon CloudFront console.
- Choose the distribution to update.
- Go to the 'Distribution Settings' and select the 'Behaviors' tab.
- Edit the 'Viewer Protocol Policy' to either 'Redirect HTTP to HTTPS' or 'HTTPS Only'.
- Save changes.
Compliance
NISTISO 27001