Low NetworkFirewall Regional

Network Firewall firewall policies should be tagged

Description

Flags AWS Network Firewall firewall policies that have no user-defined tags. Tags help associate policies with their owning team and intended traffic profile; untagged policies are operationally opaque.


Remediation

Apply at least one user-defined tag to every Network Firewall firewall policy.

Steps

  1. Open the VPC console and choose Network Firewall, then Firewall policies.
  2. Select the policy and choose Manage tags.
  3. Add at least one tag with a non-aws: prefixed key.
  4. Save the changes.