Medium NetworkFirewall Regional

Network Firewall logging should be enabled

NIST 800-53

Description

Confirms that logging is enabled for AWS Network Firewall with at least one log destination configured.


Remediation

Enable logging for the Network Firewall with at least one log destination.

Steps

  1. Navigate to the VPC console
  2. Select the Network Firewall
  3. Go to 'Logging' settings
  4. Add a log destination (CloudWatch Logs, S3, or Firehose)
  5. Apply the changes

Compliance

NIST 800-53