Skip to main content

πŸ’Ό [WAF.4] AWS WAF Classic Regional web ACLs should have at least one rule or rule group

  • Contextual name: πŸ’Ό [WAF.4] AWS WAF Classic Regional web ACLs should have at least one rule or rule group

  • ID: /frameworks/aws-fsbp-v1.0.0/waf/04

  • Located in: πŸ’Ό WAF

Description​

A WAF Regional web ACL can contain a collection of rules and rule groups that inspect and control web requests. If a web ACL is empty, the web traffic can pass without being detected or acted upon by WAF depending on the default action.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags