Skip to main content

πŸ’Ό [WAF.6] AWS WAF Classic global rules should have at least one condition

  • Contextual name: πŸ’Ό [WAF.6] AWS WAF Classic global rules should have at least one condition

  • ID: /frameworks/aws-fsbp-v1.0.0/waf/06

  • Located in: πŸ’Ό WAF

Description​

A WAF global rule can contain multiple conditions. A rule's conditions allow for traffic inspection and take a defined action (allow, block, or count). Without any conditions, the traffic passes without inspection. A WAF global rule with no conditions, but with a name or tag suggesting allow, block, or count, could lead to the wrong assumption that one of those actions is occurring.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags