These policies contain rule groups, much as we discussed earlier when configuring our web ACL. In our example earlier, we used third-party rule groups, which provide a number of benefits over creating your own, such as the following:
- A reduction in the time it takes to configure and deploy. The rule groups are already built by both AWS-approved partners and AWS themselves.
- Depending on the rule group, they could help you to meet compliance controls that might be required for HIPAA or PCI.
- Some of them have been carefully curated to help mitigate against known vulnerabilities, such as those listed by the OWASP top 10. This is a great help to many organizations that might not have the skills in-house to put together rule groups that can achieve this level of security.
Now let's see how to create and apply a WAF policy to AWS Firewall Manager. Follow these steps:
- From within the AWS Firewall Manager console, select Security...