Skip to main content

More Info:

Web ACL rule group logging should be enabled

Risk Level

High

Address

Operational Maturity, Reliability, Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • GDPR
  • HITRUST CSF
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST CSF
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • PCI
  • SOC2
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • Securities and Exchange Board of India (SEBI) - Cloud Security Adoption Framework
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Using Console

To remediate the misconfiguration of WAFv2 WebACL Rule Group Logging not being enabled in AWS CloudWatch using the AWS Management Console, follow these steps:
  1. Sign in to the AWS Management Console: Go to https://aws.amazon.com/ and sign in to your AWS account.
  2. Navigate to AWS WAF & Shield console: Click on the ‘Services’ dropdown menu at the top left corner of the console, then select ‘WAF & Shield’ under the Security, Identity, & Compliance section.
  3. Select the desired WebACL: In the AWS WAF & Shield console, click on ‘Web ACLs’ from the left-hand menu, then select the WebACL that you want to enable logging for.
  4. Edit the WebACL: Click on the WebACL that you have selected, then click on the ‘Edit’ button to make changes to the WebACL configuration.
  5. Enable Logging for the Rule Group: In the WebACL configuration page, scroll down to the ‘Logging configuration’ section. Ensure that ‘Log’ is enabled for the desired rule group(s) that you want to log.
  6. Save Changes: Once you have enabled logging for the rule group(s), click on the ‘Save’ button to save the changes to the WebACL configuration.
  7. Verify Logging Configuration: After saving the changes, you can verify that logging is enabled for the rule group(s) by checking the ‘Logging configuration’ section in the WebACL configuration page.
By following these steps, you have successfully remediated the misconfiguration of WAFv2 WebACL Rule Group Logging not being enabled in AWS CloudWatch using the AWS Management Console.

To remediate the misconfiguration for WAFv2 WebACL Rule Group Logging in AWS CloudWatch using AWS CLI, follow these steps:
  1. List all the WAFv2 WebACLs in your AWS account to identify the WebACL Rule Group for which logging needs to be enabled:
  1. Get the details of the specific WebACL Rule Group that needs logging enabled:
  1. Enable logging for the identified WebACL Rule Group by updating its configuration:
  1. Verify that the logging is enabled for the WebACL Rule Group:
By following these steps, you can successfully remediate the misconfiguration and enable logging for the WAFv2 WebACL Rule Group in AWS CloudWatch using AWS CLI.
To remediate the misconfiguration of WAFv2 WebACL Rule Group Logging not being enabled in AWS CloudWatch using Python, you can use the AWS SDK for Python (Boto3) to programmatically enable logging for the WebACL Rule Group. Below are the step-by-step instructions to remediate this issue:
  1. Install Boto3: Make sure you have the Boto3 library installed. You can install it using pip:
  1. Configure AWS Credentials: Ensure that you have configured your AWS credentials either by setting environment variables or using AWS CLI aws configure command.
  2. Write a Python script: Create a Python script with the following code to enable logging for the WAFv2 WebACL Rule Group:
  1. Replace the placeholders:
    • Replace YOUR_WEB_ACL_ARN with the ARN of the WebACL Rule Group for which you want to enable logging.
    • Replace REGION, ACCOUNT_ID, and LOG_GROUP_NAME in the LogDestinationConfigs with your AWS region, account ID, and the name of the CloudWatch Logs log group where you want to store the logs.
  2. Run the Python script: Execute the Python script to enable logging for the specified WebACL Rule Group. Make sure the script runs successfully without any errors.
By following these steps and running the Python script, you can remediate the misconfiguration of WAFv2 WebACL Rule Group Logging not being enabled in AWS CloudWatch.
This Terraform enables WAFv2 Web ACL logging by attaching a logging configuration that sends logs to a Kinesis Data Firehose stream, which in turn delivers them to CloudWatch Logs (matching the CLI behavior of using a Firehose destination).No existing aws_wafv2_web_acl resource will be replaced; the change adds or updates the separate aws_wafv2_web_acl_logging_configuration resource. Be aware that any existing logging configuration for that Web ACL will be overwritten.For CloudFront‑scope Web ACLs, ensure your provider "aws" is configured with region = "us-east-1".Verification: terraform plan should show aws_wafv2_web_acl_logging_configuration.waf_logging (and the Firehose/CloudWatch resources, if new) being created or updated, with log_destination_configs set to the Firehose stream ARN.