Web Application Firewall
What is Web Application Firewall?
A security solution that monitors, filters, and blocks HTTP/HTTPS traffic to and from web applications to protect against web-based attacks.
Terms that appear alongside web application firewall
Each of these is named in at least one of the same controls as web application firewall. The number is how many controls name both.
- firewall 5 shared controls
- nist 3 shared controls
- access control 3 shared controls
- zero trust 2 shared controls
- role based access control 2 shared controls
- privileged access management pam 2 shared controls
- multi factor authentication 2 shared controls
- network access control 2 shared controls
Frameworks that govern web application firewall
What the standards actually require on web application firewall
Requirements naming web application firewall across 4 standards, quoted from the control text.
Deploy a web application firewall in front of web applications and APIs and configure rules appropriate to the application-layer attacks those endpoints face.
ASBv3-NS-6 · Deploy web application firewall →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...
LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15 →Incident Response and Resilience are critical for the trust foundation of the AA ecosystem given the sensitive financial data flowing through it.
RBI-AA-IncidentResponse-Resilience-RBI-CERT-In-BCP-DR-Continuity · RBI AA Incident Response + Resilience - Cyber Incident Reporting to RBI + CERT-In + Business Continuity + Disaster Recovery + Resilience + Customer Communication + Forensics →Questions people ask about web application firewall
What is Web Application Firewall?
Why is Web Application Firewall important for compliance?
Which compliance frameworks address Web Application Firewall?
Where can I learn more about Web Application Firewall?
See how Web Application Firewall applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.