More Info:

Default web ACL action for requests that dont match any rules should be in Allow Mode

Risk Level

Critical

Address

Security

Compliance Standards

ISO27001, PCIDSS, CISAWS, GDPR

Triage and Remediation

Remediation

Using Console