APP-03.3: While not all applications require a web application firewall, this standard protection is typically recommended for many types of applications to reduce the risks of common attacks, especially on vulnerable application components. Cloud WAF can be implemented through a cloud provider's service or using external tooling. This control can be automatically assessed when using CSP WAF tools but will need to be manually assessed when using external tools. A WAF is only as useful as the rules implemented. The OWASP Top 10 is a decent start, but tuned rules are required for greater maturity.
  • Control automation: Either
  • AWS control specification: AWS WAF is enabled on at least one resource (load balancer, API gateway)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Either
  • AWS control specification: AWS WAF is enabled on at least one resource (load balancer, API gateway)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none