Medium
ELB
Regional
Application and Network Load Balancers with listeners should use recommended security policies
NIST 800-53
Description
Verifies that HTTPS listeners on ALBs and TLS listeners on NLBs use a recommended security policy for encrypting data in transit.
Remediation
To configure a recommended security policy for your load balancer listeners, you need to update the SSL/TLS policy settings.
Steps
- Navigate to the Amazon EC2 console
- Go to 'Load Balancers' and select your load balancer
- Select the listener you want to configure
- Choose 'Edit' and go to 'Security policy'
- Select one of the recommended security policies
- Save the changes to apply the new security policy
- Verify that the listener is using the recommended policy
Compliance
NIST 800-53