What is a web application firewall (WAF)?
A web application firewall (WAF) filters HTTP traffic to a web application and blocks common attacks such as SQL injection and cross-site scripting. It works from rule sets, often managed by the vendor and based on the OWASP Top 10. A WAF can run in blocking mode or in monitoring-only mode.
What the buyer is really asking
Say whether a WAF sits in front of your application, which one, and which rule sets are on. Say whether it blocks or only logs. If you do not use one, describe the application-layer protections you do have.
Other ways buyers ask it
Every one of these wants the same answer:
- “Do you use a web application firewall?”
- “Which WAF rules or managed rule sets are enabled?”
- “Is your WAF in blocking mode?”
Evidence to have ready
- WAF configuration and enabled rule sets
- A sample of blocked requests from WAF logs
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.
Related cloud and infrastructure questions
- Can customers export their data programmatically, and what portability and exit provisions exist (formats, retention, deletion on termination)?
- Which cloud service providers (CSP) do you use to host your services?
- How do you document and apply the shared security responsibility model (SSRM) between your organization, your cloud providers, and your customers?
- How do you manage configuration and hardening of cloud infrastructure?