AWS Application and Network Load Balancer (ALB & NLB) Terraform module
Upstream version 10.5.1
6 controls from Registry requirements
Terraform Module Source
pcidssv321.compliance.tf/terraform-aws-modules/alb/awsELB application and classic load balancer logging should be enabled
elb_application_classic_lb_logging_enabled10.1
Framework requirement
ELB application load balancers should be configured with defensive or strictest desync mitigation mode
elb_application_lb_desync_mitigation_mode6.6
Framework requirement
ELB application load balancers should be configured to drop HTTP headers
elb_application_lb_drop_http_headers6.6
Framework requirement
ELB application and network load balancers should only use SSL or HTTPS listeners
elb_application_network_lb_use_ssl_certificate
Framework requirement
ELB application and network load balancer listeners should use secure protocols
elb_application_network_listener_uses_secure_protocol
Framework requirement
VPC Security groups should only allow unrestricted incoming traffic for authorized ports
vpc_security_group_allows_ingress_authorized_ports2.2.2
Framework requirement