6 important risky areas related to WAF for auditors and risk assessors

M S Sripati
2 min readNov 30, 2023

--

So, I wrote another blog post. On 6 important risky areas related to WAF. Useful for auditors and risk assessors. Please find a summary below. For details on each point, please visit my blog

Web Application Firewall (WAF) has become a security imperative whenever a web application goes live. Absence of a WAF in an enterprise is sure to get raised as a risk or an audit finding. However, many auditors and risk assessors miss some or all of the below 6 important areas related to WAF.

Here are 6 focus areas that the risk assessors and auditors need to be mindful of, while auditing or assessing risks, in and around WAF.

  1. Not all public and critical applications are protected by WAF,
  2. Managing sensitive information that passes through WAF
  3. Always learning, no plans to block
  4. Improper log monitoring, backup
  5. No HA or plans for one
  6. No skilled resources or business continuity planned (if there is one) to manage WAF.

#pentesting #pentest #riskassessment #riskanalysis #audit #infosec

– – – – – – – – – – – – – – – – – – – – –

I blog at the intersection of pentesting, auditing, and risk assessment. A bit of all that is infosec.

I am fond of sitting at fence before jumping in. While it makes me lazy, i get useful brainwaves, at times. My blog is a reflection of those brainwaves.

Please consider subscribing to my blog (https://sripati.info) or my WhatsApp channel (link below, if WhatsApp is your thing. No one will see your number while you follow my channel) to know my views.

--

--

M S Sripati

Experienced ISMS implementer, auditor, managed pentesters, can hack and code as well | Blogger, 32K+ views on Quora