Hello community,
I work for a small professional services company.
PCI DSS version 4.0 requirement 6.4 calls out security controls for customer-facing apps. This would be a WAF to cover OWASP Top10 + Bots + API Security + automated attacks, etc. The top cloud WAFs are Imperva, Akamai, Cloudflare, and Fastly. I am curious to find out if anyone's gone through this from a PCI DSS perspective. Thank you.