WAFY
HomeReferences › A Government and Public-Sector Body

A Government and Public-Sector Body

Part of the F5 Advanced WAF experience behind WAFY, described by business type rather than by name.

Reference

What the work involved.

F5 ASM experience delivering fully OWASP-compliant Advanced WAF policies for a government body's internal systems, handled with discretion and to strict public-sector governance.

WAFY's F5 ASM experience includes a government and public-sector body implementing new internal services to support its work. These were not public-facing services, and the engagement was handled with a high degree of discretion. Advanced WAF (ASM) policies were required as part of the organisation's own internal security procedures, and were built to be fully OWASP-compliant. As is typical in government, progress ran through many meetings and deliberate, slow decision-making over an extended period, so a large part of the work was delivering carefully governed, well-documented policy work at the pace the organisation's processes allowed.

F5 scope
  • Fully OWASP-compliant Advanced WAF (ASM) policies for internal, non-public systems
  • Delivered as part of the organisation's own internal security procedures
  • Handled with discretion, given the sensitivity of the work
  • Worked within slow, meeting-heavy public-sector governance over an extended engagement
  • Careful documentation and change control throughout