View a markdown version of this page

AWS::NetworkSecurityManager::Policy PolicyConfiguration - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::NetworkSecurityManager::Policy PolicyConfiguration

The configuration settings that control the policy's behavior, including remediation and settings specific to the firewall type.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "RemediationEnabled" : Boolean, "ResourcesCleanUp" : Boolean, "WafConfig" : WafConfig }

Properties

RemediationEnabled

Specifies whether AWS Network Security Manager automatically remediates noncompliant resources. Default: false.

Required: No

Type: Boolean

Update requires: No interruption

ResourcesCleanUp

Specifies whether AWS Network Security Manager automatically removes the resources it created when they are no longer needed. Default: false.

Required: No

Type: Boolean

Update requires: No interruption

WafConfig

AWS WAF-specific policy settings.

This property is required when FirewallType is WAF. Don't specify it when FirewallType is SHIELD_ADVANCED; Network Security Manager rejects a Shield Advanced policy that includes it.

Required: Conditional

Type: WafConfig

Update requires: No interruption