Associate WAF with API stage; enable baseline rules; harden security headers; verify latency impact. Refs: ERD §12; DevOps §6