Medium WAF

AWS WAF Classic Global Web ACL logging should be enabled

NISTISO 27001HIPAA

Description

This control checks whether logging is enabled for an AWS WAF global web ACL.


Remediation

To enable logging for an AWS WAF web ACL, refer to the AWS WAF Developer Guide.

Steps

  1. Navigate to the AWS WAF console.
  2. Select the appropriate Web ACL.
  3. Enable logging in the Web ACL settings.

Compliance

NISTISO 27001HIPAA