Skip to main content

💼 [WAF.4] AWS WAF Classic Regional web ACLs should have at least one rule or rule group

  • Contextual name: 💼 [WAF.4] AWS WAF Classic Regional web ACLs should have at least one rule or rule group

  • ID: /frameworks/aws-fsbp-v1.0.0/waf/04

  • Located in: 💼 WAF

Description​

A WAF Regional web ACL can contain a collection of rules and rule groups that inspect and control web requests. If a web ACL is empty, the web traffic can pass without being detected or acted upon by WAF depending on the default action.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST SP 800-53 Revision 5 → 💼 CA-9(1) Internal System Connections _ Compliance Checks21
💼 NIST SP 800-53 Revision 5 → 💼 CM-2 Baseline Configuration725

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags