More Info:

WAF rule groups should not be empty

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “WAF Global Rule Groups Should Not Be Empty” for AWS CloudWatch using the AWS console, follow these step-by-step instructions:

  1. Login to AWS Console: Go to the AWS Management Console (https://aws.amazon.com/) and login using your credentials.

  2. Navigate to AWS WAF Service: In the AWS Management Console, search for “WAF” in the search bar at the top and click on the “AWS WAF & Shield” service.

  3. Select the Web ACL: In the AWS WAF & Shield dashboard, click on “Web ACLs” from the left-hand menu.

  4. Choose the Web ACL: Select the Web ACL that you want to remediate from the list of Web ACLs displayed.

  5. Edit the Web ACL: Click on the Web ACL that you selected, and then click on the “Rules” tab.

  6. Add Rule Groups: In the Rules tab, you will see the list of rules and rule groups associated with the Web ACL. Click on “Add rules or rule groups” button.

  7. Select Global Rule Groups: In the Add rules or rule groups window, select the “Global Rule Groups” tab.

  8. Add Rule Group: Click on the “Add rule group” button and select a rule group from the list that you want to add to the Web ACL.

  9. Save Changes: After adding the rule group, click on the “Add rule group” button to save the changes.

  10. Review and Update: Review the updated Web ACL configuration to ensure that the Global Rule Groups are not empty.

By following these steps, you have successfully added rule groups to the Web ACL in AWS WAF, ensuring that the Global Rule Groups are not empty and remediating the misconfiguration for AWS CloudWatch.