Medium ELB Regional

Application Load Balancers should be associated with an AWS WAF web ACL

NIST

Description

This check ensures that Application Load Balancers are associated with an AWS WAF web ACL to protect against web exploits that could affect availability, compromise security, or consume excessive resources.


Remediation

To associate an Application Load Balancer with an AWS WAF web ACL, follow these steps:

Steps

  1. Open the AWS WAF console at https://console.aws.amazon.com/wafv2/.
  2. In the navigation pane, choose Web ACLs.
  3. Choose the web ACL that you want to associate with a resource.
  4. On the Web ACL details page, choose the Associated AWS resources tab.
  5. Choose Add AWS resources.
  6. Select the Application Load Balancer from the list and choose Add association.

Compliance

NIST