Hacker News new | ask | show | jobs
by debarshri 952 days ago
I dont think it is a great idea to mark WAF out of scope. Most of the compliance automation platforms force you to enable it.

Even if you mark it out of scope, this pops up in most of the RFPs. Customers are generally not very keep to see security implementations that are out of the box. It should be kind of industry standard.

Having said that, WAFs are falling out of fashion lately.