Medium ELB Regional

Application and Network Load Balancers with listeners should use recommended security policies

NIST 800-53

Description

Verifies that HTTPS listeners on ALBs and TLS listeners on NLBs use a recommended security policy for encrypting data in transit.


Remediation

To configure a recommended security policy for your load balancer listeners, you need to update the SSL/TLS policy settings.

Steps

  1. Navigate to the Amazon EC2 console
  2. Go to 'Load Balancers' and select your load balancer
  3. Select the listener you want to configure
  4. Choose 'Edit' and go to 'Security policy'
  5. Select one of the recommended security policies
  6. Save the changes to apply the new security policy
  7. Verify that the listener is using the recommended policy

Compliance

NIST 800-53