---
title: CloudFront distributions should use the recommended TLS security policy
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > CloudFront distributions should use the
  recommended TLS security policy
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# CloudFront distributions should use the recommended TLS security policy
 
## Description{% #description %}

Ensure that AWS CloudFront distributions with custom certificates and without legacy-client support use an AWS-recommended viewer TLS security policy. This check passes only for `TLSv1.2_2021`, `TLSv1.2_2025`, or `TLSv1.3_2025`, matching AWS Security Hub control CloudFront.15. Distributions using the CloudFront default certificate or dedicated-IP legacy-client support are not assessed.

## Remediation{% #remediation %}

To configure or update the TLS version for an AWS CloudFront distribution, please consult the AWS documentation detailing the supported protocols and ciphers between viewers and CloudFront. This will guide you in selecting an appropriate security policy that enforces TLS v1.2 or higher, ensuring your distribution meets contemporary security standards.

For detailed instructions, refer to the [AWS CloudFront Documentation on Supported Protocols and Ciphers](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/secure-connections-supported-viewer-protocols-ciphers.html).
