Medium
NetworkFirewall
Regional
Network Firewall logging should be enabled
NIST 800-53
Description
Confirms that logging is enabled for AWS Network Firewall with at least one log destination configured.
Remediation
Enable logging for the Network Firewall with at least one log destination.
Steps
- Navigate to the VPC console
- Select the Network Firewall
- Go to 'Logging' settings
- Add a log destination (CloudWatch Logs, S3, or Firehose)
- Apply the changes
Compliance
NIST 800-53