Ensure that your websites/web applications are using the Amazon CloudFront Content Distribution Network (CDN) to secure the web content delivery (media files and static resource files such as .html, .css, .js). Before running this rule by the Trend Micro Cloud One™ – Conformity engine, your website/web application domain name needs to be configured in the rule settings, on your Conformity account console.
This rule resolution is part of the Conformity solution.
The Amazon CloudFront Content Distribution Network can have a significant impact on the security of your web content delivery process. Amazon CloudFront can accelerate and deliver your content securely over HTTPS from all of its edge locations (cache servers). In addition to delivering content securely from a worldwide network, you can also configure the CloudFront service to use HTTPS to connect to the distribution origin so that your web content is encrypted end-to-end from the origin to your end users (viewers). The Amazon CloudFront service improves the ability of your websites/web applications to absorb and mitigate potential Distributed Denial of Service (DDoS) attacks and keep the content available for legitimate users.
Audit
To determine if the Amazon CloudFront service is used as a Content Delivery Network (CDN) for your web content delivery, perform the following actions:
Remediation / Resolution
To use Amazon CloudFront as a Content Distribution Network (CDN) for your websites and web applications, you need to create and configure a CloudFront distribution. To create the required CDN distribution, perform the following actions:
References
- AWS Documentation
- What is Amazon CloudFront?
- Overview of distributions
- Steps for creating a distribution (overview)
- Creating a distribution
- Values that you specify when you create or update a distribution
- CIS Amazon Web Services Foundations
- AWS Command Line Interface (CLI) Documentation
- cloudfront
- list-distributions
- create-distribution
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Use CloudFront Content Distribution Network
Risk Level: Medium