Findings
API Gateway Stage missing WAF
Updated: June 19, 2025
Description
The AWS API Gateway stage is missing a WAF implementation.
Remediation
Use the API Gateway console to associate an AWS WAF Regional web ACL with an existing API Gateway API stage.
Security Frameworks
Separate information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information].
Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
- Develop, document, and maintain under configuration control, a current baseline configuration of the system; and
- Review and update the baseline configuration of the system:
- [Assignment: organization-defined frequency];
- When required due to [Assignment: organization-defined circumstances]; and
- When system components are installed or upgraded.