adammontville / cis-controls-71-measures

0 stars 0 forks source link

Subcontrol 18.10 #164

Open adammontville opened 5 years ago

adammontville commented 5 years ago

Protect web applications by deploying web application firewalls (WAFs) that inspect all traffic flowing to the web application for common web application attacks. For applications that are not web-based, specific application firewalls should be deployed if such tools are available for the given application type. If the traffic is encrypted, the device should either sit behind the encryption or be capable of decrypting the traffic prior to analysis. If neither option is appropriate, a host-based web application firewall should be deployed.

Measures

None provided

Metrics

None provided
adammontville commented 5 years ago

Inputs:

Operations:

Measures: M1 = Enumerated list of all software in the inventory for which an application-level firewall technology exists M2 = Enumerated list of all application-level firewalls M3 = Enumerated list of applications covered by application-level firewalls M4 = Enumerated list of applications not covered by software applications (fourth operation) M5 = |M1| M6 = |M2| M7 = |M3| M8 = |M4|

Metrics: