Web application firewalls (WAFs) provide additional protection for web applications against attacks. This document discusses best practices for using WAFs and criteria for deciding when a WAF is appropriate. It describes how WAFs work, their benefits which include centralizing security and reducing risk, and potential risks like performance issues. The document also compares WAF protections to the OWASP top 10 vulnerabilities. It provides guidelines for introducing and operating a WAF, such as in an iterative process starting with basic protections. Finally it includes checklists and defines roles for managing a WAF-based security approach.