Sanctions Compliance solutions for businesses who buy and sell internationally and want to mitigate their risk. Managed Rules for OFAC, EU, India (UN) and Japan sanctioned countries - both IPs and domains. When you purchase the managed Sanctions Compliance rules, your company has the highest sanctions protection available in the market.
ThreatSTOP's Complete Sanctions Compliance managed rule provides unparalleled compliance automation and protection against sanctions imposed by the various standards organizations, including US Treasury Department - Office of Foreign Asset Control (OFAC), the European Union, India (UN), and Japan.
It is a comprehensive solution that detects and prevents communication attempts from sanctioned countries, entities, and their global subsidiaries. These managed rules protect businesses against the risks posed by sanctions violations, effectively mitigating the potential for prohibited business engagements.
ThreatSTOP provides sanctions compliance by converting sanctions intelligence into network enforcement policies that automatically block communications with sanctioned countries, entities, subsidiaries, and associated infrastructure at both the DNS and IP layers. This allows organizations to enforce compliance before a connection or transaction occurs.
Coverage by sanctions regime:
OFAC (United States)
Monitors OFAC sanctions programs, including the Specially Designated Nationals (SDN) list.
Uses additional research (with FiveBy) to identify sanctioned entities, subsidiaries, and related infrastructure that may not be obvious from official lists alone.
Blocks communications with sanctioned countries, entities, and their infrastructure through DNS, firewalls, routers, WAFs, and other enforcement points.
European Union (EU)
Uses the EU's consolidated financial sanctions datasets and related regulatory sources.
Maps sanctioned persons, groups, and entities to their digital infrastructure so network controls can prevent communication with them.
Helps organizations operating in or with EU-regulated partners enforce sanctions requirements automatically.
India (UN)
Builds coverage from multiple Indian regulatory sources, including:
UN sanctions lists
SCOMET export-control restrictions
UAPA terrorist designations
UAPA banned organizations
Converts those designations into DNS and IP protections that prevent interactions with sanctioned infrastructure.
Japan
Uses authoritative Japanese government sources, including:
Ministry of Foreign Affairs sanctions programs
Ministry of Economy, Trade and Industry (METI) export-control and restricted end-user lists
Translates those restrictions into network-layer enforcement policies.
Register with ThreatSTOP on the fulfillment page (no cost) and receive a 1 year subscription for ThreatSTOP's CheckIOC product for free!
Highlights
Sanctions compliance that includes sanctioned entities derived from Office of Foreign Asset Control (OFAC), the European Union, India (UN), and Japan. extensively researched by ThreatSTOP's Security and Research team.
Built from automated and human sanctions intelligence, and meticulously curated by ThreatSTOP's Security and Research team, these AWS Managed Rules are updated continuously to help you integrate the newest sanctions designations into your compliance procedures with utmost speed while keeping false-positives near zero.
Includes comprehensive monitoring and protection automation of the OFAC Specially Designated Nationals and Blocked Persons List (SDN) and sanctioned countries IP address space, updated continually to protect our customers.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay based on usage, measured by the volume of traffic the Network Firewall service processes. Pricing is billed per unit of traffic processed. The dimensions are organized by AWS Region, with a separate line item for each supported Region such as us-west-2, eu-west-1, ap-northeast-1, and many others. This structure means your cost depends on which Region handles your traffic and how much traffic runs through it. You are charged only for what you process in each Region, so there is no upfront commitment tied to a fixed quantity.
Top-of-mind questions for buyers
What counts as one unit of traffic processed for billing?
One unit measures the volume of network traffic the firewall service inspects in a given Region. You are charged for traffic the service actually processes, not for idle capacity or a fixed allotment. Counting is tied to the throughput passing through the firewall in each Region.
Why is there a separate line item for each AWS Region?
Each Region meters and bills traffic independently. Your cost in one Region does not affect another. If you run workloads across several Regions, you accrue charges under each Region's line item based on the traffic processed there. Regions with no traffic accrue no charge.
What does the service do with the traffic it processes for these charges?
The service inspects network traffic and blocks connections to known malicious IP sources and destinations. It applies continuously updated threat intelligence policies across ports and protocols. You pay based on the traffic volume inspected, not on the number of threats blocked or policies applied.
www.threatstop.com
Helpful?
Vendor refund policy
No refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Check Point Managed Rules for AWS Network Firewall reduces operational overhead by providing expertly curated, pre-configured Suricata rule sets, powered by Check Point ThreatCloud AI, designed to detect and prevent malicious network activity.
Simplify compliance and security challenges by blocking inbound IP connections from ITAR and OFAC sanctioned countries. These managed rules track changes from the US State Department International Traffic in Arms Regulations, and the US Treasury Department Office of Foreign Asset Control.
The Fortinet Managed Rules for AWS API Gateway is a comprehensive package for the best web application protection to help protect against the OWASP Top 10 web application threats, including SQLi/XSS attacks, General and Known Exploits, and Malicious Bots.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.