Skip to main content

πŸ’Ό [WAF.10] AWS WAF web ACLs should have at least one rule or rule group

  • Contextual name: πŸ’Ό [WAF.10] AWS WAF web ACLs should have at least one rule or rule group

  • ID: /frameworks/aws-fsbp-v1.0.0/waf/10

  • Located in: πŸ’Ό WAF

Description​

A web ACL gives you fine-grained control over all of the HTTP(S) web requests that your protected resource responds to. A web ACL should contain a collection of rules and rule groups that inspect and control web requests. If a web ACL is empty, the web traffic can pass without being detected or acted upon by AWS WAF depending on the default action.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags