Both ALB and WAF are unable to add CSP HTTP header.
You can configure your host web server to include the necessary CSP header.
Alternatively, you can put Amazon CloudFront in front of your ALB, and use either a managed or custom Response Headers Policy (screen shot below)
!Enter image description here Answer from MikeLim on repost.aws
AWS
aws.amazon.com › what is cloud computing? › cloud computing concepts hub › networking & content delivery
What is CSP Network Automation? - CSP Network Automation Explained - AWS
1 week ago - AWS provides end-to-end automation solutions that enable communication service providers (CSPs) to accelerate their cloud transformation efforts. You can overcome technical, operational, and investment challenges when innovating solutions for 5G opportunities.
AWS
aws.amazon.com › blogs › security › tag › csp
CSP | AWS Security Blog
We’re excited to announce that Amazon Web Services (AWS) has completed the 2023 South Korea Cloud Service Providers (CSP) Safety Assessment Program, also known as the Regulation on Supervision on Electronic Financial Transactions (RSEFT) Audit Program. The financial sector in South Korea ...
AWS
docs.aws.amazon.com › aws app studio › user guide › builder documentation › viewing or updating your app's content security settings
Viewing or updating your app's content security settings - AWS App Studio
The content security settings are used to configure Content Security Policy (CSP) headers in your application. CSP is a security standard that helps to secure your app from cross-site scripting (XSS), clickjacking, and other code injection attacks.
Amazon Web Services
aws.amazon.com › compute › savings plans › compute and ec2 instance
Compute Savings Plans
1 week ago - Savings Plans are a flexible pricing model that offer low prices on Amazon EC2, AWS Lambda, and AWS Fargate usage, in exchange for a commitment to a consistent amount of usage (measured in $/hour) for a 1 or 3 year term. When you sign up for a Savings Plan, you will be charged the discounted ...
Amazon Web Services
aws.amazon.com › products › cloud financial management › savings plans
Cloud Cost Savings - Savings Plans - AWS
1 week ago - Maximize your savings by following AWS Cost Explorer Savings Plans recommendations.
AWS
aws.amazon.com › blogs › industries › a-modern-and-simple-approach-to-address-csps-network-performance-analytics-challenges-using-aws
A Modern and Simple Approach to Address CSP’s Network Performance Analytics Challenges Using AWS | Amazon Web Services
April 6, 2021 - Amazon S3 enables CSPs to manage data and access controls, query-in-place for analytics, and provide a wide range of cost-effective storage classes. Amazon S3 provides an optimal foundation for a CSP’s data lake. AWS Lake Formation is a service providing CSPs with an effective, simple way to secure their data lake.
Wiz
wiz.io › academy › how-to-evaluate-cloud-service-provider-security
How To Evaluate CSP Security: A Checklist | Wiz
May 30, 2025 - The shared responsibility model defines the respective responsibilities pertaining to security and compliance for CSPs and their customers. Using a structured checklist can help your business select a cloud provider that has the features you need to meet your security goals. Cloud service providers offer on-demand, scalable computing resources like storage services, applications, and cloud-based compute. AWS, GCP, Azure, and Oracle Cloud Infrastructure (OCI) are all leaders in this field, offering digital infrastructure to make your workloads highly available, secure, and scalable.
NVIDIA
docs.nvidia.com › ace › tokkio › 4.0 › tokkio-aws-csp-setup-guide-automated.html
AWS CSP Automated Setup Guide — Tokkio
February 17, 2025 - # NOTE: Refer to examples for various configuration options project_name: '<replace-with-unique-name-to-identify-your-project>' description: '<add-a-brief-description-about-this-project>' template_version: '0.4.0' csp: 'aws' backend: encrypt: true dynamodb_table: '<replace-with-pre-created-deployment-state-dynamo-db-table-name>' bucket: '<replace-with-pre-created-deployment-state-bucket-name>' region: '<replace-with-aws-region-where-pre-created-deployment-state-bucket-exists>' access_key: '${_aws_access_key_id}' secret_key: '${_aws_secret_access_key}' provider: region: '<replace-with-aws-regio
CloudDefense.ai
clouddefense.ai › glossary › aws › cloud-service-provider-csp
Cloud Service Provider (csp) in AWS
Protect your Applications & Cloud Infastructure from attackers by leveraging CloudDefense.AI ACS patented technology · 579 University Ave, Palo Alto, CA 94301
AWS
aws.amazon.com › certification › certified solutions architect - professional
AWS Certified Solutions Architect - Professional
1 week ago - AWS Certified Solutions Architect - Professional helps certified individuals showcase advanced knowledge and skills in providing complex solutions to complex problems, optimizing security, cost, and performance, and automating manual processes.
AWS
docs.aws.amazon.com › amazon ivs › low-latency streaming user guide › ivs player sdk › ivs player sdk: web guide › working with content security policy
Working With Content Security Policy - Amazon IVS
The Amazon IVS Web player SDK is configured to work on pages that use Content Security Policy (CSP). A few key CSP directives must be in place. Here, we describe a minimal set of directives that are necessary. Additional directives and sources are likely necessary, depending on your specific setup.
AWS
docs.aws.amazon.com › aws cloudformation › template reference › amazon cloudfront › aws::cloudfront::responseheaderspolicy › aws::cloudfront::responseheaderspolicy contentsecuritypolicy
AWS::CloudFront::ResponseHeadersPolicy ContentSecurityPolicy - AWS CloudFormation
Use the CloudFormation AWS::CloudFront::ResponseHeadersPolicy.ContentSecurityPolicy resource for CloudFront.
Amazon Web Services
aws.amazon.com › security, identity, and compliance › aws services in scope by compliance program
AWS - DESC CSP Security Standard
1 week ago - DESC CSP Security Standard Certification - Amazon Web Services (AWS)
AWS
docs.aws.amazon.com › aws config › developer guide › conformance packs for aws config › conformance pack sample templates for aws config › operational best practices for swift csp
Operational Best Practices for SWIFT CSP - AWS Config
You are responsible for making your own assessment of whether your use of the Services meets applicable legal and regulatory requirements. The following provides a sample mapping between the SWIFT's Customer Security Programme (CSP) and AWS managed Config rules.
U.S. Department of Defense
dodcio.defense.gov › Portals › 0 › Documents › Library › DoD Enterprise DevSecOps Reference Design - AWS Managed Services_DoD-CIO_20211019.pdf
DoD Enterprise DevSecOps Reference Design - AWS ...
October 19, 2021 - Official websites use .gov · Secure .gov websites use HTTPS
Top answer 1 of 5
1
Hi, Try using CloudFront function rather, it is another alternative to lambda@edge for such use cases. I recently used it with fairly large CSP headers.
See these articles for more implementation details,
https://aws.amazon.com/blogs/networking-and-content-delivery/adding-http-security-headers-using-lambdaedge-and-amazon-cloudfront/
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/example-function-add-security-headers.html
Hope this helps.
2 of 5
0
I had the same issue and opened a support ticket and had my limit raised you should be able to as well if you have support
Teckbaker's Blog
teckbakers.hashnode.dev › aws-the-leading-csp
AWS: The Leading CSP
February 16, 2023 - These CSPs have the infrastructure ready and available at their end. Now Businesses/ organizations can utilize this infrastructure for their requirements by taking those on rent. So now they don't need to invest in the upfront hardware or care about its maintenance or its configuration. According to the Garther report, AWS (Amazon Web Services) is leading among the rest of the services provided (CSPs).
AWS
docs.aws.amazon.com › aws whitepapers › aws whitepaper › aws services by category › compute
AWS Compute Services category iconCompute - Overview of Amazon Web Services
Wavelength Zones are AWS infrastructure deployments that embed AWS compute and storage services within communications service providers’ (CSP) datacenters at the edge of the 5G network, so application traffic from 5G devices can reach application servers running in Wavelength Zones without ...