Network Firewall firewalls should have deletion protection enabled

Description

This control verifies if deletion protection is activated for an AWS Network Firewall.

AWS Network Firewall is a managed stateful network security service, offering traffic inspection and filtering for traffic flowing into, out of, or between Virtual Private Clouds (VPCs). Enabling deletion protection safeguards the firewall from being unintentionally deleted.

Remediation

For guidance on configuring deletion protection, please refer to the Updating a firewall section of the AWS Network Firewall Developer Guide.