AWS Application and Network Load Balancer (ALB & NLB) Terraform module
Upstream version 10.5.1
8 controls from NIST SP 800-171 Rev 2 requirements
Terraform Module Source
nist800171.compliance.tf/terraform-aws-modules/alb/awsELB application and classic load balancer logging should be enabled
elb_application_classic_lb_logging_enabled3.1.12
Framework requirement
ELB application load balancer deletion protection should be enabled
elb_application_lb_deletion_protection_enabled3.4.1
Framework requirement
ELB application load balancers should be configured to drop HTTP headers
elb_application_lb_drop_http_headers
Framework requirement
ELB application and network load balancers should use recommended security policies
elb_application_network_lb_https_tls_listener_recommended_security_policy3.5.10
Framework requirement
ELB application and network load balancers should only use SSL or HTTPS listeners
elb_application_network_lb_use_ssl_certificate
Framework requirement
ELB application and network load balancer listeners should use secure protocols
elb_application_network_listener_uses_secure_protocol3.1.13
Framework requirement
ELB network load balancers should have TLS listener security policy configured
elb_network_lb_tls_listener_security_policy_configured3.5.10
Framework requirement
VPC Security groups should only allow unrestricted incoming traffic for authorized ports
vpc_security_group_allows_ingress_authorized_ports3.13.1
Framework requirement