Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Azure logo

CIS Azure Foundations v4.0.0

75 controls
75 checks mapped

The Center for Internet Security (CIS) Benchmarks are consensus-based, prescriptive configuration baselines for hardening cloud environments against the most common attack vectors.

Controls assessed

10.1.1 Ensure soft delete for Azure File Shares is Enabled1

Azure Files offers soft delete for file shares, allowing you to easily recover your data when it is mistakenly deleted by an application or another storage account user.

10.1.2 Ensure 'SMB protocol version' is set to 'SMB 3.1.1' or higher for SMB file shares1

Ensure that SMB file shares are configured to use the latest supported SMB protocol version.

10.1.3 Ensure 'SMB channel encryption' is set to 'AES-256-GCM' or higher for SMB file shares1

Implement SMB channel encryption with AES-256-GCM for SMB file shares to ensure data confidentiality and integrity in transit.

10.2.1 Ensure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled1

Blobs in Azure storage accounts may contain sensitive or personal data, such as ePHI or financial information.

10.2.2 Ensure 'Versioning' is set to 'Enabled' on Azure Blob Storage storage accounts1

Enabling blob versioning allows for the automatic retention of previous versions of objects.

10.3.1.1 Ensure that 'Enable key rotation reminders' is enabled for each Storage Account1

Access Keys authenticate application access requests to data contained in Storage Accounts.

10.3.1.3 Ensure 'Allow storage account key access' for Azure Storage Accounts is 'Disabled'1

Every secure request to an Azure Storage account must be authorized.

10.3.2.1 Ensure Private Endpoints are used to access Storage Accounts1

Use private endpoints for your Azure Storage accounts to allow clients and services to securely access data located over a network via an encrypted Private Link.

10.3.2.2 Ensure that 'Public Network Access' is 'Disabled' for storage accounts1

Disallowing public network access for a storage account overrides the public access settings for individual containers in that storage account for Azure Resource Manager Deployment Model storage accounts.

10.3.2.3 Ensure default network access rule for storage accounts is set to deny1

Restricting default network access helps to provide a new layer of security, since storage accounts accept connections from clients on any network.

10.3.3.1 Ensure that 'Default to Microsoft Entra authorization in the Azure portal' is set to 'Enabled'1

When this property is enabled, the Azure portal authorizes requests to blobs, files, queues, and tables with Microsoft Entra ID by default.

10.3.4 Ensure that 'Secure transfer required' is set to 'Enabled'1

Enable data encryption in transit.

10.3.5 Ensure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Access1

This recommendation assumes that the `Public network access` parameter is set to `Enabled from selected virtual networks and IP addresses`.

10.3.7 Ensure the 'Minimum TLS version' for storage accounts is set to 'Version 1.2'1

In some cases, Azure Storage sets the minimum TLS version to be version 1.

10.3.8 Ensure 'Cross Tenant Replication' is not enabled1

Cross Tenant Replication in Azure allows data to be replicated across multiple Azure tenants.

10.3.9 Ensure that 'Allow Blob Anonymous Access' is set to 'Disabled'1

The Azure Storage setting 'Allow Blob Anonymous Access' (aka \

10.3.12 Ensure Redundancy is set to 'geo-redundant storage (GRS)' on critical Azure Storage Accounts1

Geo-redundant storage (GRS) in Azure replicates data three times within the primary region using locally redundant storage (LRS) and asynchronously copies it to a secondary region hundreds of miles away.

3.1.1 Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)1

Networking for Azure Databricks can be set up in a few different ways.

3.1.2 Ensure that network security groups are configured for Databricks subnets1

Network Security Groups (NSGs) should be implemented to control inbound and outbound traffic to Azure Databricks subnets, ensuring only authorized communication.

3.1.7 Ensure that diagnostic log delivery is configured for Azure Databricks1

Azure Databricks Diagnostic Logging provides insights into system operations, user activities, and security events within a Databricks workspace.

3.1.8 Ensure that data at rest and in transit is encrypted in Azure Databricks using customer managed keys (CMK)1

Azure Databricks encrypts data in transit using TLS 1.

6.2.1 Ensure that 'trusted locations' are defined1

Microsoft Entra ID Conditional Access allows an organization to configure `Named locations` and configure whether those locations are trusted or untrusted.

6.2.6 Ensure that multifactor authentication is required for Windows Azure Service Management API1

This recommendation ensures that users accessing the Windows Azure Service Management API (i.e. Azure Powershell, Azure CLI, Azure Resource Manager API, etc.) are required to use multifactor authentication (MFA) credentials when accessing resources through the Windows Azure Service Management API.

6.3.2 Ensure that guest users are reviewed on a regular basis1

Microsoft Entra ID has native and extended identity functionality allowing you to invite people from outside your organization to be guest users in your cloud account and sign in with their own work, school, or social identities.

6.3.3 Ensure that use of the 'User Access Administrator' role is restricted1

The User Access Administrator role grants the ability to view all resources and manage access assignments at any subscription or management group level within the tenant.

6.14 Ensure that 'Users can register applications' is set to 'No'1

Require administrators or appropriately delegated users to register third-party applications.

6.19 Ensure that 'Users can create security groups in Azure portals, API or PowerShell' is set to 'No'1

Restrict security group creation to administrators only.

6.23 Ensure that no custom subscription administrator roles exist1

The principle of least privilege should be followed and only necessary privileges should be assigned instead of allowing full administrative access.

6.26 Ensure fewer than 5 users have global administrator assignment1

This recommendation aims to maintain a balance between security and operational efficiency by ensuring that a minimum of 2 and a maximum of 4 users are assigned the Global Administrator role in Microsoft Entra ID.

7.1.1.2 Ensure Diagnostic Setting captures appropriate categories1

The diagnostic setting should be configured to log the appropriate activities from the control/management plane.

7.1.1.3 Ensure the storage account containing the container with activity logs is encrypted with Customer Managed Key (CMK)1

Storage accounts with the activity log exports can be configured to use Customer Managed Keys (CMK).

7.1.1.4 Ensure that logging for Azure Key Vault is 'Enabled'1

Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available.

7.1.1.5 Ensure that Network Security Group Flow logs are captured and sent to Log Analytics1

Ensure that network flow logs are captured and fed into a central log analytics workspace.

7.1.1.6 Ensure that logging for Azure AppService 'HTTP logs' is enabled1

Enable AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all http requests are captured and centrally logged.

7.1.1.7 Ensure that virtual network flow logs are captured and sent to Log Analytics1

Ensure that virtual network flow logs are captured and fed into a central log analytics workspace.

7.1.2.1 Ensure that Activity Log Alert exists for Create Policy Assignment1

Create an activity log alert for the Create Policy Assignment event.

7.1.2.2 Ensure that Activity Log Alert exists for Delete Policy Assignment1

Create an activity log alert for the Delete Policy Assignment event.

7.1.2.3 Ensure that Activity Log Alert exists for Create or Update Network Security Group1

Create an Activity Log Alert for the Create or Update Network Security Group event.

7.1.2.4 Ensure that Activity Log Alert exists for Delete Network Security Group1

Create an activity log alert for the Delete Network Security Group event.

7.1.2.5 Ensure that Activity Log Alert exists for Create or Update Security Solution1

Create an activity log alert for the Create or Update Security Solution event.

7.1.2.6 Ensure that Activity Log Alert exists for Delete Security Solution1

Create an activity log alert for the Delete Security Solution event.

7.1.2.7 Ensure that Activity Log Alert exists for Create or Update SQL Server Firewall Rule1

Create an activity log alert for the Create or Update SQL Server Firewall Rule event.

7.1.2.8 Ensure that Activity Log Alert exists for Delete SQL Server Firewall Rule1

Create an activity log alert for the \

7.1.2.9 Ensure that Activity Log Alert exists for Create or Update Public IP Address rule1

Create an activity log alert for the Create or Update Public IP Addresses rule.

7.1.2.10 Ensure that Activity Log Alert exists for Delete Public IP Address rule1

Create an activity log alert for the Delete Public IP Address rule.

8.1 Ensure that RDP access from the Internet is evaluated and restricted1

Network security groups should be periodically evaluated for port misconfigurations.

8.2 Ensure that SSH access from the Internet is evaluated and restricted1

Network security groups should be periodically evaluated for port misconfigurations.

8.3 Ensure that UDP access from the Internet is evaluated and restricted1

Network security groups should be periodically evaluated for port misconfigurations.

8.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted2

Network security groups should be periodically evaluated for port misconfigurations.

8.5 Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'1

Network Security Group Flow Logs should be enabled and the retention period set to greater than or equal to 90 days.

8.6 Ensure that Network Watcher is 'Enabled' for Azure Regions that are in use1

Enable Network Watcher for physical regions in Azure subscriptions.

9.1.3.1 Ensure that Defender for Servers is set to 'On'1

The Defender for Servers plan in Microsoft Defender for Cloud reduces security risk by providing actionable recommendations to improve and remediate machine security posture.

9.1.3.3 Ensure that 'Endpoint protection' component status is set to 'On'1

The Endpoint protection component enables Microsoft Defender for Endpoint (formerly 'Advanced Threat Protection' or 'ATP' or 'WDATP' - see additional info) to communicate with Microsoft Defender for Cloud.

9.1.4.1 Ensure That Microsoft Defender for Containers Is Set To 'On'1

Microsoft Defender for Containers helps improve, monitor, and maintain the security of containerized assets—including Kubernetes clusters, nodes, workloads, container registries, and images—across multi-cloud and on-premises environments.

9.1.5.1 Ensure That Microsoft Defender for Storage Is Set To 'On'1

Turning on Microsoft Defender for Storage enables threat detection for Storage, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.

9.1.6.1 Ensure That Microsoft Defender for App Services Is Set To 'On'1

Turning on Microsoft Defender for App Service enables threat detection for App Service, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.

9.1.7.1 Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On'1

Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.

9.1.7.2 Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To 'On'1

Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.

9.1.7.3 Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To 'On'1

Turning on Microsoft Defender for Azure SQL Databases enables threat detection for Managed Instance Azure SQL databases, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.

9.1.7.4 Ensure That Microsoft Defender for SQL Servers on Machines Is Set To 'On'1

Turning on Microsoft Defender for SQL servers on machines enables threat detection for SQL servers on machines, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.

9.1.8.1 Ensure That Microsoft Defender for Key Vault Is Set To 'On'1

Turning on Microsoft Defender for Key Vault enables threat detection for Key Vault, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.

9.1.9.1 Ensure That Microsoft Defender for Resource Manager Is Set To 'On'1

Microsoft Defender for Resource Manager scans incoming administrative requests to change your infrastructure from both CLI and the Azure portal.

9.1.12 Ensure That 'All users with the following roles' is set to 'Owner'1

Enable security alert emails to subscription owners.

9.1.13 Ensure 'Additional email addresses' is Configured with a Security Contact Email1

Microsoft Defender for Cloud emails the subscription owners whenever a high-severity alert is triggered for their subscription.

9.1.14 Ensure that 'Notify about alerts with the following severity (or higher)' is enabled1

Enables emailing security alerts to the subscription owner or other designated security contact.

9.1.17 [LEGACY] Ensure That Microsoft Defender for DNS Is Set To 'On'1

Microsoft Defender for DNS scans all network traffic exiting from within a subscription.

9.3.1 Ensure that the Expiration Date is set for all Keys in RBAC Key Vaults1

Ensure that all Keys in Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.

9.3.2 Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults.1

Ensure that all Keys in Non Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.

9.3.3 Ensure that the Expiration Date is set for all Secrets in RBAC Key Vaults1

Ensure that all Secrets in Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.

9.3.4 Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults1

Ensure that all Secrets in Non Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.

9.3.5 Ensure the Key Vault is Recoverable1

Key Vaults contain object keys, secrets, and certificates.

9.3.6 Ensure that Role Based Access Control for Azure Key Vault is enabled1

The recommended way to access Key Vaults is to use the Azure Role-Based Access Control (RBAC) permissions model.

9.3.8 Ensure that Private Endpoints are Used for Azure Key Vault1

Private endpoints will secure network traffic from Azure Key Vault to the resources requesting secrets and keys.

9.3.9 Ensure automatic key rotation is enabled within Azure Key Vault1

Automated cryptographic key rotation in Key Vault allows users to configure Key Vault to automatically generate a new key version at a specified frequency.

9.4.1 Ensure an Azure Bastion Host Exists1

The Azure Bastion service allows secure remote access to Azure Virtual Machines over the Internet without exposing remote access protocol ports and services directly to the Internet.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.