Medium CloudFront

CloudFront distributions should use the recommended TLS security policy

FSBPHIPAA

Description

Ensures CloudFront distributions use the recommended TLS security policy for secure viewer connections.


Remediation

Configure your CloudFront distribution to use the recommended TLS security policy (TLSv1.2_2021 or newer).

Steps

  1. Navigate to the CloudFront console
  2. Select the distribution that needs a TLS policy update
  3. In the 'Viewer Certificate' section, select 'Custom SSL Certificate' or 'ACM Certificate'
  4. Set the 'Security Policy' to 'TLSv1.2_2021' or newer
  5. Save the changes and wait for the distribution to deploy

Compliance

FSBPHIPAA