Medium
CloudFront
CloudFront distributions should use the recommended TLS security policy
FSBPHIPAA
Description
Ensures CloudFront distributions use the recommended TLS security policy for secure viewer connections.
Remediation
Configure your CloudFront distribution to use the recommended TLS security policy (TLSv1.2_2021 or newer).
Steps
- Navigate to the CloudFront console
- Select the distribution that needs a TLS policy update
- In the 'Viewer Certificate' section, select 'Custom SSL Certificate' or 'ACM Certificate'
- Set the 'Security Policy' to 'TLSv1.2_2021' or newer
- Save the changes and wait for the distribution to deploy
Compliance
FSBPHIPAA