Complete OFAC Sanctions Compliance solution is for businesses who buy and sell internationally and want to mitigate their risk on OFAC Sanctioned Countries, Entities, and their Subsidiaries by providing protection from serious consequences of sanctions violations. When you purchase the Complete OFAC Sanctions Compliance managed rules, your company has the highest sanctions protection available in the market.
ThreatSTOP's Complete OFAC Sanctions Compliance managed rule provides unparalleled compliance automation and protection against sanctions imposed by the US Treasury Department - Office of Foreign Asset Control (OFAC). A comprehensive solution that detects and prevents communication attempts from OFAC-sanctioned countries, entities, and their global subsidiaries. These rules integrate sanctioned countries IP addresses with the sanctions research and expertise of ThreatSTOP's Security and Research Team. These managed rules protect businesses against the risks posed by OFAC sanctions, effectively mitigating the potential for prohibited business engagements.
Pricing information:
Pricing consists of two dimensions:
$42 per month for each web ACL using the ThreatSTOP & FiveBy OFAC Managed Rules, per region
$0.10 per million requests in each region
Pricing examples:
Example 1: 2 WebACLs in a single AWS region, 50 million requests/month
Managed rule group charges = (# of WebACLs) x $42 = $84.00
Managed rule group request charges = (# of requests/month) x $0.10 = $5.00
Total estimated AWS Marketplace charges = $89.00/month
Example 2: 10 WebACLs (5 each in two regions) and one Cloudfront region, 100 million requests/month
Managed rule group charges = ((# of WebACLs) + (# of Cloudfront)) x $42 = $420.00
Managed rule group request charges = (# of requests/month) x $0.10 = $10.00
Total estimated AWS Marketplace charges = $430.00/month
Highlights
Complete OFAC sanction compliance that includes sanctioned Sanctioned Entities and Subsidiaries extensively researched by ThreatSTOP's Security and Research team.
Built from automated and human sanctions intelligence, and meticulously curated by ThreatSTOP's Security and Research team, these AWS Managed Rules are updated continuously to help you integrate the newest sanctions designations into your compliance procedures with utmost speed while keeping false-positives near zero.
Includes comprehensive monitoring and protection automation of the OFAC Specially Designated Nationals and Blocked Persons List (SDN) and sanctioned countries IP address space, updated continually to protect our customers.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay on two usage-based dimensions that combine into your total cost. The first is a monthly charge for each AWS region where you run the rules, pro-rated by the hour. This means you only pay for the hours the service is active in a region. The second is a per-request charge, billed for each million requests processed in each region. Together, these scale with both your regional footprint and your traffic volume. Costs rise as you add regions or handle more requests, and drop when usage falls.
Top-of-mind questions for buyers
What does the ITAR and OFAC rule set for AWS WAF actually block?
These managed rules block communications with countries sanctioned by the U.S. State Department and U.S. Treasury Department. ThreatSTOP updates the rule groups automatically using curated threat intelligence feeds, so your firewall stays current with changing sanctions restrictions without manual work on your side.
How does the monthly regional charge behave if the rules run in only part of a region's month?
The monthly charge is pro-rated by the hour in each region. You pay only for the hours the rules are active. If you start or stop mid-month, or run in a region only part of the time, your charge reflects the actual active hours rather than a fixed monthly fee.
Which charge drives most of my bill — the monthly regional fee or the per-request fee?
Both charges apply at once and appear together. The monthly regional fee scales with how many regions you deploy in and the active hours. The per-request fee scales with traffic, billed per million requests per region. High-traffic sites tend to see the request charge dominate; low-traffic multi-region setups lean on the regional fee.
www.threatstop.com
Helpful?
Vendor refund policy
Non-Refundable
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
New and Active Bots identifies and blocks the attacker infrastructure hosting and controlling malicious Bots like Crawlers and Spiders that target your exposed services. The rules are dynamically updated using leading intelligence sources that have been curated by ThreatSTOP Security.
The New and Active HTTP Threats Managed Rules for AWS WAF protects exposed services from a range of threats including SSH attacks, Brute Forcers, Crackers, Shellshock, Apache Server Attacks, and more. Multiple HTTP threat intel feeds are aggregated and analyzed for continuously updated protection.
Our famous CoreThreats is built by aggregating and analyzing over 800 quality threat intelligence feeds, applying human and machine intelligence, then rapidly updating the managed rules to block threats and attacker infrastructure. CoreThreats stops a broad range of attacks with very high accuracy.
Simplify compliance and security challenges by blocking inbound IP connections from ITAR and OFAC sanctioned countries. These managed rules track changes from the US State Department International Traffic in Arms Regulations, and the US Treasury Department Office of Foreign Asset Control.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.