WAFv2 web ACLs, rule groups, IP sets, and regex pattern sets with managed and custom rules, CloudWatch visibility metrics, logging configuration, and CloudFront or regional scope for request filtering.
Controls enforced
These compliance controls are checked at terraform plan time.
Run terraform init -upgrade. Terraform state is unchanged β same resource addresses, same provider, no compliance.tf-specific resources. Controls you already applied remain in AWS.
1 controls from this module are active under PCI DSS v4.0.
A1.2 The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives
CC7.2: The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.