WAFY
Home  /  ASM Feature Matrix

What each tier covers.

Around fifty F5 Advanced WAF (ASM) capabilities, and how WAFY builds and tunes each one at Basic, Standard and Premier. WAFY manages and runs these policies for you.

Basic, Standard and Premier are feature tiers: they set how much of the F5 Advanced WAF (ASM) toolkit WAFY applies, independent of how many policies you run. Grades below describe how each capability is built and tuned at that tier, across HTML web applications and API endpoints alike. The OWASP column maps each capability to the OWASP Top 10 items it helps address (Web 2021 and API 2023). Pricing scales separately by policy count, published in full on the Subscription Services grid. Grading, cadence and OWASP mappings shown here are confirmed per estate.

Included and managed Not in this tier · Scoped on request HTMLAPI Where it applies A03 Web 2021API8 API 2023 OWASP item mapped
Capability Basicfrom £3,000 / year Standardfrom £3,500 / year Premierfrom £4,000 / year
Policy scope and cadence
Learning suggestion reviews How often we work through the policy's learning suggestions.
HTMLAPI
Monthly Monthly Weekly
Event logs, correlation reviews and reports Regular review of request/violation logs, correlated and reported back.
HTMLAPIA09 Web 2021
Monthly Monthly Weekly
Attack signature updates (incl. staging review), all scopes Signatures updated, reviewed in staging, then promoted to blocking.
HTMLAPIA03 Web 2021API8 API 2023
Monthly Monthly Monthly
Policy review Periodic health review of the policy's configuration and posture.
HTMLAPI
Entities and positive security
File type entities How tightly file types are enumerated and enforced.
HTMLA05 Web 2021
Compact / Selective Selective / Always Always
URLs / endpoints Explicit URL entities managed in the policy.
HTMLA01 Web 2021API1 API 2023
Never / Compact Selective / Always Selective / Add all
URL allowed / disallowed Allow / disallow rules for URLs.
HTMLAPIA01 Web 2021API5 API 2023
Wildcard / Compact Selective / Always Always
Parameter reviews How thoroughly parameters are enumerated and tuned.
HTMLAPIA03 Web 2021API3 API 2023
Wildcard / Compact Selective / Always Always
Cookie security (allowed / enforced), ASM cookie protection ASM cookie signing and allowed/enforced cookie handling.
HTMLAPIA02 Web 2021
Never or Selective Selective Selective
Content profiles (XML / JSON) Structured request body validation for XML and JSON.
APIA03 Web 2021API8 API 2023
Core protections (every tier)
Evasion techniques (detecting and tuning)
HTMLAPIA03 Web 2021
HTTP protocol compliance (detecting and tuning)
HTMLAPIA03 Web 2021
Response code tuning based on application traffic
HTMLAPI
Illegal HTTP response blocking
HTMLAPIA05 Web 2021
Standard tier and above
Hostnames and redirect domains
HTMLAPIA10 Web 2021
Data Guard Masking of sensitive data (e.g. card / national ID numbers) in responses.
HTMLAPIA02 Web 2021
CSRF configuration
HTMLA01 Web 2021
Complex API policies (methods / content profiles) Method and content-profile enforcement for richer API policies.
APIAPI5 API 2023API8 API 2023
Parameters (URL / flow / global)
HTMLAPIA03 Web 2021API3 API 2023
Parameter properties (including sensitive)
HTMLAPIA02 Web 2021
Premier tier
Web services security
APIA03 Web 2021API8 API 2023
Antivirus / ICAP File upload scanning via ICAP.
HTMLAPIA08 Web 2021
IP address and geolocation settings
HTMLAPIA01 Web 2021
Disallowed access from user / session / device
HTMLAPIA01 Web 2021API1 API 2023
Login pages, bypass and expiry
HTMLAPIA07 Web 2021API2 API 2023
Header protections
HTMLAPIA05 Web 2021
Brute force protection
HTMLAPIA07 Web 2021API2 API 2023
IP address intelligence (licence dependent) Requires the IP Intelligence subscription on the device.
HTML
DDoS profiles and DDoS tuning
HTMLAPIAPI4 API 2023
Policy templates and parent policies
HTMLAPI
Parent policies / inheritance settings
HTMLAPI
Rapid deployment policies for interim protection
HTMLAPI
Further capabilities (scoped on request; grading to confirm)
Bot defence and bot defence tuning (learning / ignoring)
HTMLAPI4 API 2023API6 API 2023
· · ·
Policy cleanup of unused objects
HTMLAPI
· · ·
Threat campaigns
HTMLA03 Web 2021
· · ·
Customised response pages
HTMLAPI
· · ·
PCI compliance PCI DSS, not OWASP.
HTML
· · ·
OWASP compliance reporting and OWASP tightening Addresses the OWASP Top 10 as a whole.
HTMLAPI
· · ·
Policy type setting and tuning
HTMLAPI
· · ·
File types and dynamic file type protections
HTMLAPIA05 Web 2021
· · ·
Microservices protection
HTMLAPIAPI8 API 2023
· · ·
Logging formatting and tuning (Splunk / Syslog)
HTMLAPIA09 Web 2021
· · ·
LTM local traffic policies for ASM distribution / bypassing
HTMLAPI
· · ·
Policy bypassing and failsafe systems
HTMLAPI
· · ·
Shun reporting
HTMLAPI
· · ·
Custom signatures and custom signature sets
HTMLAPIA03 Web 2021
· · ·

The Basic, Standard and Premier tiers and their prices are published in full on the Subscription Services page. Grading, cadence and OWASP mappings shown here are confirmed per estate. “Where” shows whether a capability typically applies to HTML web applications, API endpoints, or both. The OWASP column maps each capability to the OWASP Top 10 items it helps address (Web 2021 and API 2023); a capability often supports more than one, and some are general controls with no single mapping.