More Info:

Origin Failover feature should be enabled for your Amazon CloudFront web distributions in order to improve the availability of the content delivered to your end users

Risk Level

Low

Address

Reliability, Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “Origin Failover Should Be Enabled For CloudFront Distributions” for AWS using the AWS console, follow the below steps:

  1. Log in to the AWS Management Console.
  2. Go to the CloudFront service page.
  3. Select the distribution for which you want to enable Origin Failover.
  4. Click on the “Origins and Origin Groups” tab.
  5. Select the origin for which you want to enable failover.
  6. Click on the “Edit” button.
  7. Scroll down to the “Origin Failover” section.
  8. Click on the “Yes” radio button to enable Origin Failover.
  9. Provide the alternate origin details in the “Alternate Domain Name” field.
  10. Click on the “Create” button to create a new origin group.
  11. Click on the “Save Changes” button to save the changes made.

Once you have followed these steps, Origin Failover will be enabled for your CloudFront distribution.

Additional Reading: