Checks Performed
- ALB Should Have Logging Enabled
- ALB With Desync Mitigation Mode Should Be Set
- ALBs Should Have Latest SSL/TLS Configurations
- ALBs Should Not Have Insecure Configurations
- Classic ELB Listeners Should Have At Least One ACM Certificate
- Classic Load Balancer Has Multiple Availability Zones
- CLB With Desync Mitigation Mode Should Be Enabled
- ELB Listeners Should Have At Least One ACM Certificate
- ELB Security Layer Should Have At Least One Valid Security Group
- ELB Should Accept HTTPS Connections Only
- ELB Should Have Logging Enabled
- ELB Should Have WAF Enabled
- ELBs Should Be Evenly Distributed over AZs
- ELBs Should Drop Invalid HTTP Header
- ELBs Should Have Connection Draining Enabled
- ELBs Should Have Cross Zone Enabled
- ELBs Should Have Deletion Protection Flag Enabled
- ELBs Should Not Have Insecure Ciphers
- ELBs Should Not Have Insecure Configurations
- ELBs Should Use Latest AWS Security Policies
- ELBs Should Use Secure Listeners Only
- FMS Policy Owner Specifies WebACLId
- Internet Facing ELBs Should Be Regularly Reviewed
- Latest AWS Security Policy for SSL Negotiations Should Be Used For App-Tier ELBs
- Latest AWS Security Policy for SSL Negotiations Should Be Used For Web-Tier ELBs
- Minimum Number of EC2 Instances Should Be Configured For ELBs
- NLBs Should Have Latest SSL/TLS Configurations
- NLBs Should Not Have Insecure Configurations
- No Classic ELB Should Be In Use
- No Idle ELBs Should Be Present
- No Unused ELBs Should Be Present
- Right Health Check Configurations Should Be Used For App-Tier ELBs
- Right Health Check Configurations Should Be Used For Web-Tier ELBs
- Secure Listeners Should Be In App-tier ELBs
- Secure Listeners Should Be In Web-tier ELBs

