More Info:

WAF rule groups should not be empty

Risk Level

High

Address

Security

Compliance Standards

CBP,RBI_UCB

Triage and Remediation

Remediation

To remediate the misconfiguration of empty WAF Regional Rule Groups in AWS CloudWatch using the AWS console, follow these steps:

  1. Access the AWS Management Console: Go to https://aws.amazon.com/ and sign in to your AWS account.

  2. Navigate to AWS WAF Console: From the AWS Management Console, search for “WAF” in the search bar at the top and select “AWS WAF” from the dropdown.

  3. Select the WAF Regional Rule Group: In the AWS WAF console, select the WAF Regional Rule Group that is empty and needs to be remediated.

  4. Edit the Rule Group: Click on the rule group that is empty to open its details.

  5. Add Rules to the Rule Group: Within the rule group details, you can add rules to the rule group to ensure that it is not empty. You can add pre-configured rules or create custom rules based on your requirements.

  6. Save the Changes: After adding the necessary rules to the rule group, save the changes to update the rule group with the new rules.

  7. Verify the Rule Group: Once the changes are saved, verify that the rule group is no longer empty and contains the necessary rules to secure your AWS resources.

  8. Monitor and Maintain: Regularly monitor the rule group to ensure that it remains updated with the latest rules and configurations to protect your AWS resources effectively.

By following these steps, you can remediate the misconfiguration of empty WAF Regional Rule Groups in AWS CloudWatch using the AWS console.