More Info:

This rule verifies whether AWS AppSync resources are associated with AWS WAF (Web Application Firewall) to protect against common web exploits and security vulnerabilities. Associating AppSync with WAF allows for the enforcement of custom access control rules and provides an additional layer of security against malicious traffic

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Check Cause

  1. Sign in to the AWS Management Console.
  2. Navigate to the AWS AppSync service. You can find this by typing ‘AppSync’ into the search bar at the top of the console.
  3. Once in the AppSync dashboard, select the API that you want to check for WAF association.
  4. In the settings or details of the selected API, look for a section or field related to AWS WAF. If the API is associated with a WAF, it should be listed here. If there is no such section or the field is empty, then the API is not associated with a WAF.