More Info:

All your AWS CloudFront web distributions should be integrated with the Web Application Firewall (AWS WAF) service to protect against application-layer attacks

Risk Level

Low

Address

Security

Compliance Standards

SOC2, GDPR, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration for AWS, follow these steps:

  1. Log in to the AWS Management Console and navigate to the AWS WAF service.

  2. Create a new web ACL (Access Control List) by clicking on the “Create web ACL” button.

  3. Give your new web ACL a name and description.

  4. Under “Rules”, click on the “Add rule” button.

  5. Select “AWS Managed Rules” and choose the rule set that you want to use. For example, choose the “AWSManagedRulesCommonRuleSet” rule set.

  6. Under “Web ACL associations”, click on the “Add association” button.

  7. Select the CloudFront distribution that you want to associate with the web ACL.

  8. Click on the “Add association” button to complete the association.

  9. Wait for a few minutes for the changes to propagate.

  10. Test your CloudFront distribution to ensure that it is now integrated with AWS WAF.

By following these steps, you should be able to remediate the misconfiguration and integrate your CloudFront distribution with AWS WAF.

Additional Reading: