Medium ELB Regional

Classic Load Balancers with SSL listeners should use a predefined security policy that has strong configuration

NISTISO 27001HIPAA

Description

This check verifies that Classic Load Balancers with SSL listeners are using a predefined security policy with strong security configurations to ensure the protection of data in transit.


Remediation

To update the SSL listener to use a strong predefined security policy, follow these steps:

Steps

  1. Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.
  2. On the navigation pane, under LOAD BALANCING, choose Load Balancers.
  3. Select the Classic Load Balancer.
  4. Choose the Listeners tab.
  5. For the SSL or HTTPS listener, choose Change under the Cipher column.
  6. Select a strong predefined security policy from the list.

Compliance

NISTISO 27001HIPAA