3 ms·
It's basically fizzbuzz. If you have a WAF, it proves you know how to add a WAF. Presumably even one you know how to configure when security needs change. Comp
by ryanianian 3y ago
It's basically fizzbuzz. If you have a WAF, it proves you know how to add a WAF. Presumably even one you know how to configure when security needs change.
Compliance auditors are mostly there to underwrite posture, not actual risk.
- SoftTalker 3y agoAuditors pretty much only certify that you have told them you are doing what you are supposed to be doing. They are not logging in to your servers and verifying that an AWF is running in front of your web server. They are not probing your network from the outside to see if an AWF is blocking their activity. Just as financial auditors are only confirming that your financial statements match what your accounting department tells them. If you lie to your auditors, there's a good chance they won't catch it because that's not what they are looking for.
- xyzzy123 3y agoIt's not a lie! The WAF is there, it's attached and it does absolutely nothing with unmatched performance and scalability. We tell the auditor this. There's no audit checkbox for "WAF actually does something useful", so it's fine.
- kccqzy 3y agoYou can lie to these auditors, but you can't lie to pentesters. These people on the other hand are designed to probe your network from the outside.
- PrimeMcFly 3y agoI've audited a lot of networks for compliance, and we always actually check that the protections that are meant to be in place are in place. I don't think I've done an audit where I wasn't using nmap to some degree.