Medium
ELB
Regional
Application Load Balancers should be associated with an AWS WAF web ACL
NIST
Description
This check ensures that Application Load Balancers are associated with an AWS WAF web ACL to protect against web exploits that could affect availability, compromise security, or consume excessive resources.
Remediation
To associate an Application Load Balancer with an AWS WAF web ACL, follow these steps:
Steps
- Open the AWS WAF console at https://console.aws.amazon.com/wafv2/.
- In the navigation pane, choose Web ACLs.
- Choose the web ACL that you want to associate with a resource.
- On the Web ACL details page, choose the Associated AWS resources tab.
- Choose Add AWS resources.
- Select the Application Load Balancer from the list and choose Add association.
Compliance
NIST