Medium WAF Regional

AWS WAF Classic Regional rules should have at least one condition

NISTISO 27001

Description

This control checks whether an AWS WAF Regional rule has at least one condition. The control fails if no conditions are present within a rule.


Remediation

To add a condition to an empty rule, refer to the AWS WAF Developer Guide.

Steps

  1. Navigate to the AWS WAF Regional console.
  2. Select the appropriate Rule.
  3. Add at least one condition to the Rule.

Compliance

NISTISO 27001