AWS_ELB_71

Make sure that ALB is protected by a WAF

Description

Ensure that all your public AWS ALB are integrated with the Web Application Firewall (AWS WAF) service to protect against application-layer attacks

Remediation

  1. Go to the AWS WAF service page and select the Web ACLs.
  2. Create a new Web ACL or select an existing one
  3. Select the Associated AWS resources tab
  4. Click on Add AWS resources
  5. Under Resource Type, Select the resource type and then select the resource you want to associate with this web ACL. Note this rule requires the following permission: waf – regional : ListResourcesForWebACL Reference : https://docs.aws.amazon.com/waf/latest/developerguide/getting-started.html

Service

ELB

Severity

Medium

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!