Medium
CloudFront
CloudFront distributions should encrypt traffic to custom origins
NISTISO 27001HIPAA
Description
Flags CloudFront distributions that do not encrypt traffic to custom origins — specifically those with an http-only origin protocol policy, or match-viewer combined with an allow-all viewer protocol policy.
Remediation
To update the Origin Protocol Policy to require encryption for a CloudFront connection, refer to the Amazon CloudFront Developer Guide.
Steps
- Open the Amazon CloudFront console.
- Choose the distribution to update.
- Navigate to the 'Origins and Origin Groups' section.
- Edit the origin and ensure the 'Origin Protocol Policy' is set to 'HTTPS Only' or 'Match Viewer'.
- Save changes.
Compliance
NISTISO 27001HIPAA