Findings
AppSync Graphql API is missing WAF
Updated: June 19, 2025
Description
The AWS AppSync Graphql API is missing a WAF implementation.
Remediation
Attach an AWS WAF to the AppSync Graphql API
Security Frameworks
Separate information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information].
Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
- Develop, document, and maintain under configuration control, a current baseline configuration of the system; and
- Review and update the baseline configuration of the system:
- [Assignment: organization-defined frequency];
- When required due to [Assignment: organization-defined circumstances]; and
- When system components are installed or upgraded.