Client Side Protection | Check Point WAF

Overview

As part of PCI DSS 4.0 requirements for Client-Side Protection (Requirements 6.4.3 and 11.6.1), CloudGuard WAF introduces automatic Script and IFrame Discovery and Authorization. These features help organizations:

How to set up Client Side Protection?

Step 1: Add URIs to Start Discovery

To Avoid Learning Inline Scripts check the following checkbox:

Step 2: Configure Security Header Checks

Set Security header check to one of the following:

Step 3: Allow the System to Learn

To receive email notifications for Client Side Protection events configure a notification trigger and connect it to the relevant asset.

Step 4: Review Discovered Items

Step 5: Authorize Trusted Scripts & IFrames

To allow all inline scripts check the following checkbox

Step 6: Enable Enforcement

When ready: Enforce Policy

CloudGuard WAF will then block unauthorized or unexpected scripts and iframes.