diff --git a/prowler/compliance/aws/cis_1.4_aws.json b/prowler/compliance/aws/cis_1.4_aws.json
index db4559ea02..da77feb991 100644
--- a/prowler/compliance/aws/cis_1.4_aws.json
+++ b/prowler/compliance/aws/cis_1.4_aws.json
@@ -455,7 +455,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Amazon S3 provides a variety of no, or low, cost encryption options to protect data at rest.",
@@ -476,7 +477,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "At the Amazon S3 bucket level, you can configure permissions through a bucket policy making the objects accessible only through HTTPS.",
@@ -497,7 +499,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.",
@@ -518,7 +521,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.",
@@ -540,7 +544,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon S3 provides `Block public access (bucket settings)` and `Block public access (account settings)` to help you manage public access to Amazon S3 resources. By default, S3 buckets and objects are created with public access disabled. However, an IAM principal with sufficient S3 permissions can enable public access at the bucket and/or object level. While enabled, `Block public access (bucket settings)` prevents an individual bucket, and its contained objects, from becoming publicly accessible. Similarly, `Block public access (account settings)` prevents all buckets, and contained objects, from becoming publicly accessible across the entire account.",
@@ -561,7 +566,8 @@
],
"Attributes": [
{
- "Section": "2.2. Elastic Compute Cloud (EC2)",
+ "Section": "2. Storage",
+ "SubSection": "2.2. Elastic Compute Cloud (EC2)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.",
@@ -582,7 +588,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon RDS encrypted DB instances use the industry standard AES-256 encryption algorithm to encrypt your data on the server that hosts your Amazon RDS DB instances. After your data is encrypted, Amazon RDS handles authentication of access and decryption of your data transparently with a minimal impact on performance.",
diff --git a/prowler/compliance/aws/cis_1.5_aws.json b/prowler/compliance/aws/cis_1.5_aws.json
index cf6743d2a0..6d5283b81c 100644
--- a/prowler/compliance/aws/cis_1.5_aws.json
+++ b/prowler/compliance/aws/cis_1.5_aws.json
@@ -455,7 +455,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Amazon S3 provides a variety of no, or low, cost encryption options to protect data at rest.",
@@ -476,7 +477,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "At the Amazon S3 bucket level, you can configure permissions through a bucket policy making the objects accessible only through HTTPS.",
@@ -497,7 +499,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.",
@@ -518,7 +521,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.",
@@ -540,7 +544,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon S3 provides `Block public access (bucket settings)` and `Block public access (account settings)` to help you manage public access to Amazon S3 resources. By default, S3 buckets and objects are created with public access disabled. However, an IAM principal with sufficient S3 permissions can enable public access at the bucket and/or object level. While enabled, `Block public access (bucket settings)` prevents an individual bucket, and its contained objects, from becoming publicly accessible. Similarly, `Block public access (account settings)` prevents all buckets, and contained objects, from becoming publicly accessible across the entire account.",
@@ -561,7 +566,8 @@
],
"Attributes": [
{
- "Section": "2.2. Elastic Compute Cloud (EC2)",
+ "Section": "2. Storage",
+ "SubSection": "2.2. Elastic Compute Cloud (EC2)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.",
@@ -582,7 +588,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon RDS encrypted DB instances use the industry standard AES-256 encryption algorithm to encrypt your data on the server that hosts your Amazon RDS DB instances. After your data is encrypted, Amazon RDS handles authentication of access and decryption of your data transparently with a minimal impact on performance.",
@@ -603,7 +610,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that RDS database instances have the Auto Minor Version Upgrade flag enabled in order to receive automatically minor engine upgrades during the specified maintenance window. So, RDS instances can get the new features, bug fixes, and security patches for their database engines.",
@@ -624,7 +632,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure and verify that RDS database instances provisioned in your AWS account do restrict unauthorized access in order to minimize security risks. To restrict access to any publicly accessible RDS database instance, you must disable the database Publicly Accessible flag and update the VPC security group associated with the instance.",
@@ -645,7 +654,8 @@
],
"Attributes": [
{
- "Section": "2.4 Elastic File System (EFS)",
+ "Section": "2. Storage",
+ "SubSection": "2.4 Elastic File System (EFS)",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "EFS data should be encrypted at rest using AWS KMS (Key Management Service).",
diff --git a/prowler/compliance/aws/cis_2.0_aws.json b/prowler/compliance/aws/cis_2.0_aws.json
index a2cbcbd3ae..09f2ebe08f 100644
--- a/prowler/compliance/aws/cis_2.0_aws.json
+++ b/prowler/compliance/aws/cis_2.0_aws.json
@@ -474,7 +474,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "At the Amazon S3 bucket level, you can configure permissions through a bucket policy making the objects accessible only through HTTPS.",
@@ -495,7 +496,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.",
@@ -516,7 +518,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.",
@@ -538,7 +541,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon S3 provides `Block public access (bucket settings)` and `Block public access (account settings)` to help you manage public access to Amazon S3 resources. By default, S3 buckets and objects are created with public access disabled. However, an IAM principal with sufficient S3 permissions can enable public access at the bucket and/or object level. While enabled, `Block public access (bucket settings)` prevents an individual bucket, and its contained objects, from becoming publicly accessible. Similarly, `Block public access (account settings)` prevents all buckets, and contained objects, from becoming publicly accessible across the entire account.",
@@ -559,7 +563,8 @@
],
"Attributes": [
{
- "Section": "2.2. Elastic Compute Cloud (EC2)",
+ "Section": "2. Storage",
+ "SubSection": "2.2. Elastic Compute Cloud (EC2)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.",
@@ -580,7 +585,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon RDS encrypted DB instances use the industry standard AES-256 encryption algorithm to encrypt your data on the server that hosts your Amazon RDS DB instances. After your data is encrypted, Amazon RDS handles authentication of access and decryption of your data transparently with a minimal impact on performance.",
@@ -601,7 +607,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that RDS database instances have the Auto Minor Version Upgrade flag enabled in order to receive automatically minor engine upgrades during the specified maintenance window. So, RDS instances can get the new features, bug fixes, and security patches for their database engines.",
@@ -622,7 +629,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure and verify that RDS database instances provisioned in your AWS account do restrict unauthorized access in order to minimize security risks. To restrict access to any publicly accessible RDS database instance, you must disable the database Publicly Accessible flag and update the VPC security group associated with the instance.",
@@ -643,7 +651,8 @@
],
"Attributes": [
{
- "Section": "2.4 Elastic File System (EFS)",
+ "Section": "2. Storage",
+ "SubSection": "2.4 Elastic File System (EFS)",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "EFS data should be encrypted at rest using AWS KMS (Key Management Service).",
diff --git a/prowler/compliance/aws/cis_3.0_aws.json b/prowler/compliance/aws/cis_3.0_aws.json
index 6b0bf7f6e0..9b45e6c7b8 100644
--- a/prowler/compliance/aws/cis_3.0_aws.json
+++ b/prowler/compliance/aws/cis_3.0_aws.json
@@ -474,7 +474,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "At the Amazon S3 bucket level, you can configure permissions through a bucket policy making the objects accessible only through HTTPS.",
@@ -495,7 +496,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.",
@@ -516,7 +518,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Amazon S3 buckets can contain sensitive data, that for security purposes should be discovered, monitored, classified and protected. Macie along with other 3rd party tools can automatically provide an inventory of Amazon S3 buckets.",
@@ -538,7 +541,8 @@
],
"Attributes": [
{
- "Section": "2.1. Simple Storage Service (S3)",
+ "Section": "2. Storage",
+ "SubSection": "2.1. Simple Storage Service (S3)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon S3 provides `Block public access (bucket settings)` and `Block public access (account settings)` to help you manage public access to Amazon S3 resources. By default, S3 buckets and objects are created with public access disabled. However, an IAM principal with sufficient S3 permissions can enable public access at the bucket and/or object level. While enabled, `Block public access (bucket settings)` prevents an individual bucket, and its contained objects, from becoming publicly accessible. Similarly, `Block public access (account settings)` prevents all buckets, and contained objects, from becoming publicly accessible across the entire account.",
@@ -559,7 +563,8 @@
],
"Attributes": [
{
- "Section": "2.2. Elastic Compute Cloud (EC2)",
+ "Section": "2. Storage",
+ "SubSection": "2.2. Elastic Compute Cloud (EC2)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Elastic Compute Cloud (EC2) supports encryption at rest when using the Elastic Block Store (EBS) service. While disabled by default, forcing encryption at EBS volume creation is supported.",
@@ -580,7 +585,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Amazon RDS encrypted DB instances use the industry standard AES-256 encryption algorithm to encrypt your data on the server that hosts your Amazon RDS DB instances. After your data is encrypted, Amazon RDS handles authentication of access and decryption of your data transparently with a minimal impact on performance.",
@@ -601,7 +607,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that RDS database instances have the Auto Minor Version Upgrade flag enabled in order to receive automatically minor engine upgrades during the specified maintenance window. So, RDS instances can get the new features, bug fixes, and security patches for their database engines.",
@@ -622,7 +629,8 @@
],
"Attributes": [
{
- "Section": "2.3. Relational Database Service (RDS)",
+ "Section": "2. Storage",
+ "SubSection": "2.3. Relational Database Service (RDS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure and verify that RDS database instances provisioned in your AWS account do restrict unauthorized access in order to minimize security risks. To restrict access to anypublicly accessible RDS database instance, you must disable the database PubliclyAccessible flag and update the VPC security group associated with the instance",
@@ -643,7 +651,8 @@
],
"Attributes": [
{
- "Section": "2.4 Elastic File System (EFS)",
+ "Section": "2. Storage",
+ "SubSection": "2.4 Elastic File System (EFS)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "EFS data should be encrypted at rest using AWS KMS (Key Management Service).",
diff --git a/prowler/compliance/azure/cis_2.0_azure.json b/prowler/compliance/azure/cis_2.0_azure.json
index 715ae7b2fe..6e914f5057 100644
--- a/prowler/compliance/azure/cis_2.0_azure.json
+++ b/prowler/compliance/azure/cis_2.0_azure.json
@@ -12,7 +12,8 @@
],
"Attributes": [
{
- "Section": "1.1 Security Defaults",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.1 Security Defaults",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Security defaults in Azure Active Directory (Azure AD) make it easier to be secure and help protect your organization. Security defaults contain preconfigured security settings for common attacks. Security defaults is available to everyone. The goal is to ensure that all organizations have a basic level of security",
@@ -34,7 +35,8 @@
],
"Attributes": [
{
- "Section": "1.1 Security Defaults",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.1 Security Defaults",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Enable multi-factor authentication for all roles, groups, and users that have write access or permissions to Azure resources. These include custom created objects or built-in roles such as; • Service Co-Administrators • Subscription Owners • Contributors",
@@ -56,7 +58,8 @@
],
"Attributes": [
{
- "Section": "1.1 Security Defaults",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.1 Security Defaults",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable multi-factor authentication for all non-privileged users.",
@@ -76,7 +79,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Security Defaults",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.1 Security Defaults",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Do not allow users to remember multi-factor authentication on devices.",
@@ -98,7 +102,8 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Azure Active Directory Conditional Access allows an organization to configure Named locations and configure whether those locations are trusted or untrusted. These settings provide organizations the means to specify Geographical locations for use in conditional access policies, or define actual IP addresses and IP ranges and whether or not those IP addresses and/or ranges are trusted by the organization.",
@@ -118,7 +123,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "CAUTION: If these policies are created without first auditing and testing the result, misconfiguration can potentially lock out administrators or create undesired access issues. Conditional Access Policies can be used to block access from geographic locations that are deemed out-of-scope for your organization or application. The scope and variables for this policy should be carefully examined and defined.",
@@ -138,7 +144,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on login.",
@@ -158,7 +165,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on logins.",
@@ -178,7 +186,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on login.",
@@ -198,7 +207,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on logins.",
@@ -220,7 +230,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Require administrators or appropriately delegated users to create new tenants.",
@@ -240,7 +250,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "This recommendation extends guest access review by utilizing the Azure AD Privileged Identity Management feature provided in Azure AD Premium P2. Azure AD is extended to include Azure AD B2B collaboration, allowing you to invite people from outside your organization to be guest users in your cloud account and sign in with their own work, school, or social identities. Guest users allow you to share your company's applications and services with users from any other organization, while maintaining control over your own corporate data. Work with external partners, large or small, even if they don't have Azure AD or an IT department. A simple invitation and redemption process lets partners use their own credentials to access your company's resources a a guest user.",
@@ -260,7 +270,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Azure AD is extended to include Azure AD B2B collaboration, allowing you to invite people from outside your organization to be guest users in your cloud account and sign in with their own work, school, or social identities. Guest users allow you to share your company's applications and services with users from any other organization, while maintaining control over your own corporate data. Work with external partners, large or small, even if they don't have Azure AD or an IT department. A simple invitation and redemption process lets partners use their own credentials to access your company's resources as a guest user. Guest users in every subscription should be review on a regular basis to ensure that inactive and unneeded accounts are removed.",
@@ -280,7 +290,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Ensures that two alternate forms of identification are provided before allowing a password reset.",
@@ -300,7 +310,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Microsoft Azure provides a Global Banned Password policy that applies to Azure administrative and normal user accounts. This is not applied to user accounts that are synced from an on-premise Active Directory unless Azure AD Connect is used and you enable EnforceCloudPasswordPolicyForPasswordSyncedUsers. Please see the list in default values on the specifics of this policy. To further password security, it is recommended to further define a custom banned password policy.",
@@ -320,7 +330,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Ensure that the number of days before users are asked to re-confirm their authentication information is not set to 0.",
@@ -340,7 +350,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Ensure that users are notified on their primary and secondary emails on password resets.",
@@ -360,7 +370,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Ensure that all Global Administrators are notified if any other administrator resets their password.",
@@ -382,7 +392,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Require administrators to provide consent for applications before use.",
@@ -404,7 +414,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Allow users to provide consent for selected permissions when a request is coming from a verified publisher.",
@@ -424,7 +434,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Require administrators to provide consent for the apps before use.",
@@ -446,7 +456,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Require administrators or appropriately delegated users to register third-party applications.",
@@ -468,7 +478,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Limit guest user permissions.",
@@ -490,7 +500,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Restrict invitations to users with specific administrative roles only.",
@@ -510,7 +520,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Restrict access to the Azure AD administration portal to administrators only. NOTE: This only affects access to the Azure AD administrator's web portal. This setting does not prohibit privileged users from using other methods such as Rest API or Powershell to obtain sensitive information from Azure AD.",
@@ -530,7 +540,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Restricts group creation to administrators with permissions only.",
@@ -552,7 +562,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Restrict security group creation to administrators only.",
@@ -572,7 +582,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Restrict security group management to administrators only.",
@@ -594,7 +604,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Restrict Microsoft 365 group creation to administrators only.",
@@ -614,7 +624,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Joining or registering devices to the active directory should require Multi-factor authentication.",
@@ -636,7 +646,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The principle of least privilege should be followed and only necessary privileges should be assigned instead of allowing full administrative access.",
@@ -658,7 +668,7 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Resource locking is a powerful protection mechanism that can prevent inadvertent modification/deletion of resources within Azure subscriptions/Resource Groups and is a recommended NIST configuration.",
@@ -678,7 +688,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1. Identity and Access Management",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Users who are set as subscription owners are able to make administrative changes to the subscriptions and move them into and out of Azure Active Directories.",
@@ -700,7 +710,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Servers enables threat detection for Servers, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -722,7 +733,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for App Service enables threat detection for App Service, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -744,7 +756,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.",
@@ -766,7 +779,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Azure SQL Databases enables threat detection for Azure SQL database servers, providing threat intelligence, anomaly detection, andbehavior analytics in the Microsoft Defender for Cloud.",
@@ -788,7 +802,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for SQL servers on machines enables threat detection for SQL servers on machines, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -810,7 +825,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -832,7 +848,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Storage enables threat detection for Storage, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -854,7 +871,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Containers enables threat detection for Container Registries including Kubernetes, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -876,7 +894,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.",
@@ -898,7 +917,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Turning on Microsoft Defender for Key Vault enables threat detection for Key Vault, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -920,7 +940,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Defender for DNS scans all network traffic exiting from within a subscription.",
@@ -942,7 +963,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Defender for Resource Manager scans incoming administrative requests to change your infrastructure from both CLI and the Azure portal.",
@@ -964,7 +986,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Ensure that the latest OS patches for all virtual machines are applied.",
@@ -986,7 +1009,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "None of the settings offered by ASC Default policy should be set to effect Disabled.",
@@ -1008,7 +1032,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Enable automatic provisioning of the monitoring agent to collect security data.",
@@ -1030,7 +1055,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.",
@@ -1050,7 +1076,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable automatic provisioning of the Microsoft Defender for Containers components.",
@@ -1072,7 +1099,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable security alert emails to subscription owners.",
@@ -1094,7 +1122,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Cloud emails the subscription owners whenever a high-severity alert is triggered for their subscription. You should provide a security contact email address as an additional email address.",
@@ -1116,7 +1145,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enables emailing security alerts to the subscription owner or other designated security contact.",
@@ -1138,7 +1168,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "This integration setting enables Microsoft Defender for Cloud Apps (formerly 'Microsoft Cloud App Security' or 'MCAS' - see additional info) to communicate with Microsoft Defender for Cloud.",
@@ -1160,7 +1191,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "This integration setting enables Microsoft Defender for Endpoint (formerly 'Advanced Threat Protection' or 'ATP' or 'WDATP' - see additional info) to communicate with Microsoft Defender for Cloud. IMPORTANT: When enabling integration between DfE & DfC it needs to be taken into account that this will have some side effects that may be undesirable. 1. For server 2019 & above if defender is installed (default for these server SKU's) this will trigger a deployment of the new unified agent and link to any of the extended configuration in the Defender portal. 2. If the new unified agent is required for server SKU's of Win 2016 or Linux and lower there is additional integration that needs to be switched on and agents need to be aligned.",
@@ -1182,7 +1214,8 @@
],
"Attributes": [
{
- "Section": "2.2 Microsoft Defender for IoT",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.2 Microsoft Defender for IoT",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Defender for IoT acts as a central security hub for IoT devices within your organization.",
@@ -1524,7 +1557,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable auditing on SQL Servers.",
@@ -1546,7 +1580,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that no SQL Databases allow ingress from 0.0.0.0/0 (ANY IP).",
@@ -1568,7 +1603,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Transparent Data Encryption (TDE) with Customer-managed key support provides increased transparency and control over the TDE Protector, increased security with an HSM-backed external service, and promotion of separation of duties. With TDE, data is encrypted at rest with a symmetric key (called the database encryption key) stored in the database or data warehouse distribution. To protect this data encryption key (DEK) in the past, only a certificate that the Azure SQL Service managed could be used. Now, with Customer-managed key support for TDE, the DEK can be protected with an asymmetric key that is stored in the Azure Key Vault. The Azure Key Vault is a highly available and scalable cloud-based key store which offers central key management, leverages FIPS 140-2 Level 2 validated hardware security modules (HSMs), and allows separation of management of keys and data for additional security. Based on business needs or criticality of data/databases hosted on a SQL server, it is recommended that the TDE protector is encrypted by a key that is managed by the data owner (Customer-managed key).",
@@ -1590,7 +1626,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Use Azure Active Directory Authentication for authentication with SQL Database to manage credentials in a single place.",
@@ -1612,7 +1649,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable Transparent Data Encryption on every SQL server.",
@@ -1634,7 +1672,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "SQL Server Audit Retention should be configured to be greater than 90 days.",
@@ -1656,7 +1695,8 @@
],
"Attributes": [
{
- "Section": "4.2 SQL Server - Microsoft Defender for SQL",
+ "Section": "4. Database Services",
+ "SubSection": "4.2 SQL Server - Microsoft Defender for SQL",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable 'Microsoft Defender for SQL' on critical SQL Servers.",
@@ -1678,7 +1718,8 @@
],
"Attributes": [
{
- "Section": "4.2 SQL Server - Microsoft Defender for SQL",
+ "Section": "4. Database Services",
+ "SubSection": "4.2 SQL Server - Microsoft Defender for SQL",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable Vulnerability Assessment (VA) service scans for critical SQL servers and corresponding SQL databases.",
@@ -1700,7 +1741,8 @@
],
"Attributes": [
{
- "Section": "4.2 SQL Server - Microsoft Defender for SQL",
+ "Section": "4. Database Services",
+ "SubSection": "4.2 SQL Server - Microsoft Defender for SQL",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable Vulnerability Assessment (VA) service scans for critical SQL servers and corresponding SQL databases.",
@@ -1722,7 +1764,8 @@
],
"Attributes": [
{
- "Section": "4.2 SQL Server - Microsoft Defender for SQL",
+ "Section": "4. Database Services",
+ "SubSection": "4.2 SQL Server - Microsoft Defender for SQL",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Configure 'Send scan reports to' with email addresses of concerned data owners/stakeholders for a critical SQL servers",
@@ -1744,7 +1787,8 @@
],
"Attributes": [
{
- "Section": "4.2 SQL Server - Microsoft Defender for SQL",
+ "Section": "4. Database Services",
+ "SubSection": "4.2 SQL Server - Microsoft Defender for SQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable Vulnerability Assessment (VA) setting 'Also send email notifications to admins and subscription owners'.",
@@ -1766,7 +1810,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable SSL connection on PostgreSQL Servers.",
@@ -1788,7 +1833,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable log_checkpoints on PostgreSQL Servers.",
@@ -1810,7 +1856,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable log_connections on PostgreSQL Servers.",
@@ -1832,7 +1879,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable log_disconnections on PostgreSQL Servers.",
@@ -1854,7 +1902,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable connection_throttling on PostgreSQL Servers.",
@@ -1876,7 +1925,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure log_retention_days on PostgreSQL Servers is set to an appropriate value.",
@@ -1898,7 +1948,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Disable access from Azure services to PostgreSQL Database Server.",
@@ -1918,7 +1969,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Azure Database for PostgreSQL servers should be created with 'infrastructure double encryption' enabled.",
@@ -1940,7 +1992,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable SSL connection on MYSQL Servers.",
@@ -1962,7 +2015,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure TLS version on MySQL flexible servers is set to the default value.",
@@ -1984,7 +2038,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable audit_log_enabled on MySQL Servers.",
@@ -2006,7 +2061,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Set audit_log_enabled to include CONNECTION on MySQL Servers.",
@@ -2028,7 +2084,8 @@
],
"Attributes": [
{
- "Section": "4.5 Cosmos DB",
+ "Section": "4. Database Services",
+ "SubSection": "4.5 Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Limiting your Cosmos DB to only communicate on whitelisted networks lowers its attack footprint.",
@@ -2050,7 +2107,8 @@
],
"Attributes": [
{
- "Section": "4.5 Cosmos DB",
+ "Section": "4. Database Services",
+ "SubSection": "4.5 Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Private endpoints limit network traffic to approved sources.",
@@ -2072,7 +2130,8 @@
],
"Attributes": [
{
- "Section": "4.5 Cosmos DB",
+ "Section": "4. Database Services",
+ "SubSection": "4.5 Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Cosmos DB can use tokens or AAD for client authentication which in turn will use Azure RBAC for authorization. Using AAD is significantly more secure because AAD handles the credentials and allows for MFA and centralized management, and the Azure RBAC better integrated with the rest of Azure.",
@@ -2094,7 +2153,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Enable Diagnostic settings for exporting activity logs. Diagnos tic settings are available for each individual resource within a subscription. Settings should be configured for allappropriate resources for your environment.",
@@ -2116,7 +2176,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Prerequisite: A Diagnostic Setting must exist. If a Diagnostic Setting does not exist, the navigation and options within this recommendation will not be available. Please review the recommendation at the beginning of this subsection titled: 'Ensure that a 'Diagnostic Setting' exists.' The diagnostic setting should be configured to log the appropriate activities from the control/management plane.",
@@ -2138,7 +2199,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The storage account container containing the activity log export should not be publicly accessible.",
@@ -2160,7 +2222,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Storage accounts with the activity log exports can be configured to use Customer Managed Keys (CMK).",
@@ -2182,7 +2245,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available.",
@@ -2204,7 +2268,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Ensure that network flow logs are captured and fed into a central log analytics workspace.",
@@ -2226,7 +2291,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all http requests are captured and centrally logged.",
@@ -2248,7 +2314,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create Policy Assignment event.",
@@ -2270,7 +2337,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Policy Assignment event.",
@@ -2292,7 +2360,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an Activity Log Alert for the Create or Update Network Security Group event.",
@@ -2314,7 +2383,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Network Security Group event.",
@@ -2336,7 +2406,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update Security Solution event.",
@@ -2358,7 +2429,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Security Solution event.",
@@ -2380,7 +2452,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update SQL Server Firewall Rule event.",
@@ -2402,7 +2475,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the 'Delete SQL Server Firewall Rule.'",
@@ -2424,7 +2498,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update Public IP Addresses rule.",
@@ -2446,7 +2521,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Public IP Address rule.",
@@ -2466,7 +2542,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3 Configuring Application Insights",
+ "Section": "5. Logging and Monitoring",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Resource Logs capture activity to the data access plane while the Activity log is a subscription-level log for the control plane. Resource-level diagnostic logs provide insight into operations that were performed within that resource itself; for example, reading or updating a secret from a Key Vault. Currently, 95 Azure resources support Azure Monitoring (See the more information section for a complete list), including Network Security Groups, Load Balancers, Key Vault, AD, Logic Apps, and CosmosDB. The content of these logs varies by resource type. A number of back-end services were not configured to log and store Resource Logs for certain activities or for a sufficient length. It is crucial that monitoring is correctly configured to log all relevant activities and retain those logs for a sufficient length of time. Given that the mean time to detection in an enterprise is 240 days, a minimum retention period of two years is recommended.",
@@ -2486,7 +2562,7 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3 Configuring Application Insights",
+ "Section": "5. Logging and Monitoring",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "The use of Basic or Free SKUs in Azure whilst cost effective have significant limitations in terms of what can be monitored and what support can be realized from Microsoft. Typically, these SKU’s do not have a service SLA and Microsoft will usually refuse to provide support for them. Consequently Basic/Free SKUs should never be used for production workloads.",
@@ -2508,7 +2584,8 @@
],
"Attributes": [
{
- "Section": "5.3 Configuring Application Insights",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.3 Configuring Application Insights",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Application Insights within Azure act as an Application Performance Monitoring solution providing valuable data into how well an application performs and additional information when performing incident response. The types of log data collected include application metrics, telemetry data, and application trace logging data providing organizations with detailed information about application activity and application transactions. Both data sets help organizations adopt a proactive and retroactive means to handle security and performance related metrics within their modern applications.",
diff --git a/prowler/compliance/azure/cis_2.1_azure.json b/prowler/compliance/azure/cis_2.1_azure.json
index 0ed4d69719..bf3a5a5161 100644
--- a/prowler/compliance/azure/cis_2.1_azure.json
+++ b/prowler/compliance/azure/cis_2.1_azure.json
@@ -494,7 +494,8 @@
],
"Attributes": [
{
- "Section": "1.1 Security Defaults Security Defaults",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.1 Security Defaults Security Defaults",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Security defaults in Microsoft Entra ID make it easier to be secure and help protect your organization. Security defaults contain preconfigured security settings for common attacks. Security defaults is available to everyone. The goal is to ensure that all organizations have a basic level of security enabled at no extra cost. You may turn on security defaults in the Azure portal.",
@@ -516,7 +517,8 @@
],
"Attributes": [
{
- "Section": "1.1 Security Defaults Security Defaults",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.1 Security Defaults Security Defaults",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Enable multi-factor authentication for all roles, groups, and users that have write access or permissions to Azure resources. These include custom created objects or built-in roles such as; - Service Co-Administrators - Subscription Owners - Contributors",
@@ -538,7 +540,8 @@
],
"Attributes": [
{
- "Section": "1.1 Security Defaults",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.1 Security Defaults Security Defaults",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable multi-factor authentication for all non-privileged users.",
@@ -558,7 +561,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Security Defaults",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.1 Security Defaults Security Defaults",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Do not allow users to remember multi-factor authentication on devices.",
@@ -580,7 +584,8 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Microsoft Entra ID Conditional Access allows an organization to configure `Named locations` and configure whether those locations are trusted or untrusted. These settings provide organizations the means to specify Geographical locations for use in conditional access policies, or define actual IP addresses and IP ranges and whether or not those IP addresses and/or ranges are trusted by the organization.",
@@ -600,7 +605,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "**CAUTION**: If these policies are created without first auditing and testing the result, misconfiguration can potentially lock out administrators or create undesired access issues. Conditional Access Policies can be used to block access from geographic locations that are deemed out-of-scope for your organization or application. The scope and variables for this policy should be carefully examined and defined.",
@@ -620,7 +626,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on login.",
@@ -640,7 +647,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on logins.",
@@ -660,7 +668,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on login.",
@@ -682,7 +691,8 @@
],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "This recommendation ensures that users accessing the Windows Azure Service Management API (i.e. Azure Powershell, Azure CLI, Azure Resource Manager API, etc.) are required to use multifactor authentication (MFA) credentials when accessing resources through the Windows Azure Service Management API.",
@@ -702,7 +712,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 Conditional Access",
+ "Section": "1.Identity and Access Management",
+ "SubSection": "1.2 Conditional Access",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "This recommendation ensures that users accessing Microsoft Admin Portals (i.e. Microsoft 365 Admin, Microsoft 365 Defender, Exchange Admin Center, Azure Portal, etc.) are required to use multifactor authentication (MFA) credentials when logging into an Admin Portal.",
@@ -724,7 +735,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Servers enables threat detection for Servers, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -746,7 +758,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for App Service enables threat detection for App Service, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -768,7 +781,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Azure SQL Databases enables threat detection for Managed Instance Azure SQL databases, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.",
@@ -790,7 +804,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for SQL servers on machines enables threat detection for SQL servers on machines, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.",
@@ -812,7 +827,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -834,7 +850,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.",
@@ -856,7 +873,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Storage enables threat detection for Storage, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -878,7 +896,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Containers enables threat detection for Container Registries including Kubernetes, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud. The following services will be enabled for container instances: - Defender agent in Azure - Azure Policy for Kubernetes - Agentless discovery for Kubernetes - Agentless container vulnerability assessment",
@@ -900,7 +919,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Key Vault enables threat detection for Key Vault, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -922,7 +942,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "[**NOTE:** As of August 1, customers with an existing subscription to Defender for DNS can continue to use the service, but new subscribers will receive alerts about suspicious DNS activity as part of Defender for Servers P2.] Microsoft Defender for DNS scans all network traffic exiting from within a subscription.",
@@ -944,7 +965,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Resource Manager scans incoming administrative requests to change your infrastructure from both CLI and the Azure portal.",
@@ -966,7 +988,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that the latest OS patches for all virtual machines are applied.",
@@ -988,7 +1011,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "The Microsoft Cloud Security Benchmark (or MCSB) is an Azure Policy Initiative containing many security policies to evaluate resource configuration against best practice recommendations. If a policy in the MCSB is set with effect type `Disabled`, it is not evaluated and may prevent administrators from being informed of valuable security recommendations.",
@@ -1010,7 +1034,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable automatic provisioning of the monitoring agent to collect security data.",
@@ -1032,7 +1057,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.",
@@ -1052,7 +1078,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable automatic provisioning of the Microsoft Defender for Containers components.",
@@ -1074,7 +1101,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable security alert emails to subscription owners.",
@@ -1096,7 +1124,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Cloud emails the subscription owners whenever a high-severity alert is triggered for their subscription. You should provide a security contact email address as an additional email address.",
@@ -1118,7 +1147,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enables emailing security alerts to the subscription owner or other designated security contact.",
@@ -1140,7 +1170,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "This integration setting enables Microsoft Defender for Cloud Apps (formerly 'Microsoft Cloud App Security' or 'MCAS' - see additional info) to communicate with Microsoft Defender for Cloud.",
@@ -1162,7 +1193,8 @@
],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "This integration setting enables Microsoft Defender for Endpoint (formerly 'Advanced Threat Protection' or 'ATP' or 'WDATP' - see additional info) to communicate with Microsoft Defender for Cloud. **IMPORTANT:** When enabling integration between DfE & DfC it needs to be taken into account that this will have some side effects that may be undesirable. 1. For server 2019 & above if defender is installed (default for these server SKU's) this will trigger a deployment of the new unified agent and link to any of the extended configuration in the Defender portal. 1. If the new unified agent is required for server SKU's of Win 2016 or Linux and lower there is additional integration that needs to be switched on and agents need to be aligned.",
@@ -1182,7 +1214,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.1 Microsoft Defender for Cloud",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.1 Microsoft Defender for Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "An organization's attack surface is the collection of assets with a public network identifier or URI that an external threat actor can see or access from outside your cloud. It is the set of points on the boundary of a system, a system element, system component, or an environment where an attacker can try to enter, cause an effect on, or extract data from, that system, system element, system component, or environment. The larger the attack surface, the harder it is to protect. This tool can be configured to scan your organization's online infrastructure such as specified domains, hosts, CIDR blocks, and SSL certificates, and store them in an Inventory. Inventory items can be added, reviewed, approved, and removed, and may contain enrichments (insights) and additional information collected from the tool's different scan engines and open-source intelligence sources. A Defender EASM workspace will generate an Inventory of publicly exposed assets by crawling and scanning the internet using _Seeds_ you provide when setting up the tool. Seeds can be FQDNs, IP CIDR blocks, and WHOIS records. Defender EASM will generate Insights within 24-48 hours after Seeds are provided, and these insights include vulnerability data (CVEs), ports and protocols, and weak or expired SSL certificates that could be used by an attacker for reconnaisance or exploitation. Results are classified High/Medium/Low and some of them include proposed mitigations.",
@@ -1204,7 +1237,8 @@
],
"Attributes": [
{
- "Section": "2.2 Microsoft Defender for IoT",
+ "Section": "2. Microsoft Defender",
+ "SubSection": "2.2 Microsoft Defender for IoT",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Defender for IoT acts as a central security hub for IoT devices within your organization.",
@@ -1586,7 +1620,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable auditing on SQL Servers.",
@@ -1608,7 +1643,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that no SQL Databases allow ingress from 0.0.0.0/0 (ANY IP).",
@@ -1630,7 +1666,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Transparent Data Encryption (TDE) with Customer-managed key support provides increased transparency and control over the TDE Protector, increased security with an HSM-backed external service, and promotion of separation of duties. With TDE, data is encrypted at rest with a symmetric key (called the database encryption key) stored in the database or data warehouse distribution. To protect this data encryption key (DEK) in the past, only a certificate that the Azure SQL Service managed could be used. Now, with Customer-managed key support for TDE, the DEK can be protected with an asymmetric key that is stored in the Azure Key Vault. The Azure Key Vault is a highly available and scalable cloud-based key store which offers central key management, leverages FIPS 140-2 Level 2 validated hardware security modules (HSMs), and allows separation of management of keys and data for additional security. Based on business needs or criticality of data/databases hosted on a SQL server, it is recommended that the TDE protector is encrypted by a key that is managed by the data owner (Customer-managed key).",
@@ -1652,7 +1689,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Use Microsoft Entra authentication for authentication with SQL Database to manage credentials in a single place.",
@@ -1674,7 +1712,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable Transparent Data Encryption on every SQL server.",
@@ -1696,7 +1735,8 @@
],
"Attributes": [
{
- "Section": "4.1 SQL Server - Auditing",
+ "Section": "4. Database Services",
+ "SubSection": "4.1 SQL Server - Auditing",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "SQL Server Audit Retention should be configured to be greater than 90 days.",
@@ -1718,7 +1758,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `SSL connection` on `PostgreSQL` Servers.",
@@ -1740,7 +1781,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `log_checkpoints` on `PostgreSQL Servers`.",
@@ -1762,7 +1804,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `log_connections` on `PostgreSQL Servers`.",
@@ -1784,7 +1827,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `log_disconnections` on `PostgreSQL Servers`.",
@@ -1806,7 +1850,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `connection_throttling` on `PostgreSQL Servers`.",
@@ -1828,7 +1873,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure `log_retention_days` on `PostgreSQL Servers` is set to an appropriate value.",
@@ -1850,7 +1896,8 @@
],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Disable access from Azure services to PostgreSQL Database Server.",
@@ -1870,7 +1917,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.3 PostgreSQL Database Server. Storage Accounts",
+ "Section": "4. Database Services",
+ "SubSection": "4.3 PostgreSQL Database Server. Storage Accounts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Azure Database for PostgreSQL servers should be created with 'infrastructure double encryption' enabled.",
@@ -1892,7 +1940,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `SSL connection` on `MYSQL` Servers.",
@@ -1914,7 +1963,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure `TLS version` on `MySQL flexible` servers is set to use TLS version 1.2 or higher.",
@@ -1936,7 +1986,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable audit_log_enabled on MySQL Servers.",
@@ -1958,7 +2009,8 @@
],
"Attributes": [
{
- "Section": "4.4 MySQL Database",
+ "Section": "4. Database Services",
+ "SubSection": "4.4 MySQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Set `audit_log_enabled` to include CONNECTION on MySQL Servers.",
@@ -1980,7 +2032,8 @@
],
"Attributes": [
{
- "Section": "4.5 Cosmos DB",
+ "Section": "4. Database Services",
+ "SubSection": "4.5 Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Limiting your Cosmos DB to only communicate on whitelisted networks lowers its attack footprint.",
@@ -2002,7 +2055,8 @@
],
"Attributes": [
{
- "Section": "4.5 Cosmos DB",
+ "Section": "4. Database Services",
+ "SubSection": "4.5 Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Private endpoints limit network traffic to approved sources.",
@@ -2024,7 +2078,8 @@
],
"Attributes": [
{
- "Section": "4.5 Cosmos DB",
+ "Section": "4. Database Services",
+ "SubSection": "4.5 Cosmos DB",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Cosmos DB can use tokens or Entra ID for client authentication which in turn will use Azure RBAC for authorization. Using Entra ID is significantly more secure because Entra ID handles the credentials and allows for MFA and centralized management, and the Azure RBAC better integrated with the rest of Azure.",
@@ -2086,7 +2141,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Enable Diagnostic settings for exporting activity logs. Diagnostic settings are available for each individual resource within a subscription. Settings should be configured for all appropriate resources for your environment.",
@@ -2108,7 +2164,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "**Prerequisite**: A Diagnostic Setting must exist. If a Diagnostic Setting does not exist, the navigation and options within this recommendation will not be available. Please review the recommendation at the beginning of this subsection titled: Ensure that a 'Diagnostic Setting' exists. The diagnostic setting should be configured to log the appropriate activities from the control/management plane.",
@@ -2130,7 +2187,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Storage accounts with the activity log exports can be configured to use Customer Managed Keys (CMK).",
@@ -2152,7 +2210,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available.",
@@ -2174,7 +2233,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Ensure that network flow logs are captured and fed into a central log analytics workspace.",
@@ -2196,7 +2256,8 @@
],
"Attributes": [
{
- "Section": "5.1 Configuring Diagnostic Settings",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.1 Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all http requests are captured and centrally logged.",
@@ -2218,7 +2279,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create Policy Assignment event.",
@@ -2240,7 +2302,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Policy Assignment event.",
@@ -2262,7 +2325,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an Activity Log Alert for the Create or Update Network Security Group event.",
@@ -2284,7 +2348,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Network Security Group event.",
@@ -2306,7 +2371,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update Security Solution event.",
@@ -2328,7 +2394,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Security Solution event.",
@@ -2350,7 +2417,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update SQL Server Firewall Rule event.",
@@ -2372,7 +2440,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete SQL Server Firewall Rule.",
@@ -2394,7 +2463,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update Public IP Addresses rule.",
@@ -2416,7 +2486,8 @@
],
"Attributes": [
{
- "Section": "5.2 Monitoring using Activity Log Alerts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.2 Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Public IP Address rule.",
@@ -2438,7 +2509,8 @@
],
"Attributes": [
{
- "Section": "5.3 Configuring Application Insights. Storage Accounts",
+ "Section": "5. Logging and Monitoring",
+ "SubSection": "5.3 Configuring Application Insights. Storage Accounts",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Application Insights within Azure act as an Application Performance Monitoring solution providing valuable data into how well an application performs and additional information when performing incident response. The types of log data collected include application metrics, telemetry data, and application trace logging data providing organizations with detailed information about application activity and application transactions. Both data sets help organizations adopt a proactive and retroactive means to handle security and performance related metrics within their modern applications.",
diff --git a/prowler/compliance/azure/cis_3.0_azure.json b/prowler/compliance/azure/cis_3.0_azure.json
index 8e70ab3637..bb4338556f 100644
--- a/prowler/compliance/azure/cis_3.0_azure.json
+++ b/prowler/compliance/azure/cis_3.0_azure.json
@@ -514,7 +514,8 @@
],
"Attributes": [
{
- "Section": "2.1. Security Defaults (Per-User MFA)",
+ "Section": "2. Identity",
+ "SubSection": "2.1. Security Defaults (Per-User MFA)",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "[**IMPORTANT - Please read the section overview:** If your organization pays for Microsoft Entra ID licensing (included in Microsoft 365 E3, E5, or F5, and EM&S E3 or E5 licenses) and **CAN** use Conditional Access, ignore the recommendations in this section and proceed to the Conditional Access section.]Security defaults in Microsoft Entra ID make it easier to be secure and help protect your organization. Security defaults contain preconfigured security settings for common attacks.Security defaults is available to everyone. The goal is to ensure that all organizations have a basic level of security enabled at no extra cost. You may turn on security defaults in the Azure portal.",
@@ -536,7 +537,8 @@
],
"Attributes": [
{
- "Section": "2.1. Security Defaults (Per-User MFA)",
+ "Section": "2. Identity",
+ "SubSection": "2.1. Security Defaults (Per-User MFA)",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "[**IMPORTANT - Please read the section overview:** If your organization pays for Microsoft Entra ID licensing (included in Microsoft 365 E3, E5, or F5, and EM&S E3 or E5 licenses) and **CAN** use Conditional Access, ignore the recommendations in this section and proceed to the Conditional Access section.]Enable multi-factor authentication for all roles, groups, and users that have write access or permissions to Azure resources. These include custom created objects or built-in roles such as;- Service Co-Administrators- Subscription Owners- Contributors",
@@ -558,7 +560,8 @@
],
"Attributes": [
{
- "Section": "2.1. Security Defaults (Per-User MFA)",
+ "Section": "2. Identity",
+ "SubSection": "2.1. Security Defaults (Per-User MFA)",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "[**IMPORTANT - Please read the section overview:** If your organization pays for Microsoft Entra ID licensing (included in Microsoft 365 E3, E5, or F5, and EM&S E3 or E5 licenses) and **CAN** use Conditional Access, ignore the recommendations in this section and proceed to the Conditional Access section.]Enable multi-factor authentication for all non-privileged users.",
@@ -578,7 +581,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.1. Security Defaults (Per-User MFA)",
+ "Section": "2. Identity",
+ "SubSection": "2.1. Security Defaults (Per-User MFA)",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "[**IMPORTANT - Please read the section overview:** If your organization pays for Microsoft Entra ID licensing (included in Microsoft 365 E3, E5, or F5, and EM&S E3 or E5 licenses) and **CAN** use Conditional Access, ignore the recommendations in this section and proceed to the Conditional Access section.]Do not allow users to remember multi-factor authentication on devices.",
@@ -600,7 +604,8 @@
],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Entra ID Conditional Access allows an organization to configure `Named locations` and configure whether those locations are trusted or untrusted. These settings provide organizations the means to specify Geographical locations for use in conditional access policies, or define actual IP addresses and IP ranges and whether or not those IP addresses and/or ranges are trusted by the organization.",
@@ -620,7 +625,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "**CAUTION**: If these policies are created without first auditing and testing the result, misconfiguration can potentially lock out administrators or create undesired access issues.Conditional Access Policies can be used to block access from geographic locations that are deemed out-of-scope for your organization or application. The scope and variables for this policy should be carefully examined and defined.",
@@ -640,7 +646,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Conditional Access Policies can be used to prevent the Device code authentication flow. Device code flow should be permitted only for users that regularly perform duties that explicitly require the use of Device Code to authenticate, such as utilizing Azure with PowerShell.",
@@ -660,7 +667,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on login.",
@@ -680,7 +688,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "For designated users, they will be prompted to use their multi-factor authentication (MFA) process on logins.",
@@ -700,7 +709,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Entra ID tracks the behavior of sign-in events. If the Entra ID domain is licensed with P2, the sign-in behavior can be used as a detection mechanism for additional scrutiny during the sign-in event. If this policy is set up, then Risky Sign-in events will prompt users to use multi-factor authentication (MFA) tokens on login for additional verification.",
@@ -722,7 +732,8 @@
],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "This recommendation ensures that users accessing the Windows Azure Service Management API (i.e. Azure Powershell, Azure CLI, Azure Resource Manager API, etc.) are required to use multi-factor authentication (MFA) credentials when accessing resources through the Windows Azure Service Management API.",
@@ -744,7 +755,8 @@
],
"Attributes": [
{
- "Section": "2.2. Conditional Access",
+ "Section": "2. Identity",
+ "SubSection": "2.2. Conditional Access",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "This recommendation ensures that users accessing Microsoft Admin Portals (i.e. Microsoft 365 Admin, Microsoft 365 Defender, Exchange Admin Center, Azure Portal, etc.) are required to use multi-factor authentication (MFA) credentials when logging into an Admin Portal.",
@@ -766,7 +778,8 @@
],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that the latest OS patches for all virtual machines are applied.",
@@ -788,7 +801,8 @@
],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "The Microsoft Cloud Security Benchmark (or 'MCSB') is an Azure Policy Initiative containing many security policies to evaluate resource configuration against best practice recommendations. If a policy in the MCSB is set with effect type `Disabled`, it is not evaluated and may prevent administrators from being informed of valuable security recommendations.",
@@ -810,7 +824,8 @@
],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable security alert emails to subscription owners.",
@@ -832,7 +847,8 @@
],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Cloud emails the subscription owners whenever a high-severity alert is triggered for their subscription. You should provide a security contact email address as an additional email address.",
@@ -854,7 +870,8 @@
],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enables emailing security alerts to the subscription owner or other designated security contact.",
@@ -874,7 +891,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "An organization's attack surface is the collection of assets with a public network identifier or URI that an external threat actor can see or access from outside your cloud. It is the set of points on the boundary of a system, a system element, system component, or an environment where an attacker can try to enter, cause an effect on, or extract data from, that system, system element, system component, or environment. The larger the attack surface, the harder it is to protect.This tool can be configured to scan your organization's online infrastructure such as specified domains, hosts, CIDR blocks, and SSL certificates, and store them in an Inventory. Inventory items can be added, reviewed, approved, and removed, and may contain enrichments ('insights') and additional information collected from the tool's different scan engines and open-source intelligence sources.A Defender EASM workspace will generate an Inventory of publicly exposed assets by crawling and scanning the internet using _Seeds_ you provide when setting up the tool. Seeds can be FQDNs, IP CIDR blocks, and WHOIS records.Defender EASM will generate Insights within 24-48 hours after Seeds are provided, and these insights include vulnerability data (CVEs), ports and protocols, and weak or expired SSL certificates that could be used by an attacker for reconnaisance or exploitation.Results are classified High/Medium/Low and some of them include proposed mitigations.",
@@ -896,7 +914,8 @@
],
"Attributes": [
{
- "Section": "3.1. Microsoft Defender For Cloud",
+ "Section": "3. Security",
+ "SubSection": "3.1. Microsoft Defender For Cloud",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "[**NOTE:** As of August 1, 2023 customers with an existing subscription to Defender for DNS can continue to use the service, but new subscribers will receive alerts about suspicious DNS activity as part of Defender for Servers P2.]Microsoft Defender for DNS scans all network traffic exiting from within a subscription.",
@@ -918,7 +937,8 @@
],
"Attributes": [
{
- "Section": "3.1.1 Microsoft Cloud Security Posture Management (CSPM)",
+ "Section": "3. Security",
+ "SubSection": "3.1.1 Microsoft Cloud Security Posture Management (CSPM)",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable automatic provisioning of the monitoring agent to collect security data.**DEPRECATION PLANNED:** The Log Analytics Agent is slated for deprecation in August 2024. The Microsoft Defender for Endpoint agent, in tandem with new agentless capabilities will be providing replacement functionality. More detail is available here: [https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-strategy-and-plan-towards-log/ba-p/3883341](https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-strategy-and-plan-towards-log/ba-p/3883341).",
@@ -940,7 +960,8 @@
],
"Attributes": [
{
- "Section": "3.1.1 Microsoft Cloud Security Posture Management (CSPM)",
+ "Section": "3. Security",
+ "SubSection": "3.1.1 Microsoft Cloud Security Posture Management (CSPM)",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "This integration setting enables Microsoft Defender for Cloud Apps (formerly 'Microsoft Cloud App Security' or 'MCAS' - see additional info) to communicate with Microsoft Defender for Cloud.",
@@ -962,7 +983,8 @@
],
"Attributes": [
{
- "Section": "3.1.3. Defender Plan: Servers",
+ "Section": "3. Security",
+ "SubSection": "3.1.3. Defender Plan: Servers",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Servers enables threat detection for Servers, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -984,7 +1006,8 @@
],
"Attributes": [
{
- "Section": "3.1.3. Defender Plan: Servers",
+ "Section": "3. Security",
+ "SubSection": "3.1.3. Defender Plan: Servers",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.",
@@ -1004,7 +1027,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1.3. Defender Plan: Servers",
+ "Section": "3. Security",
+ "SubSection": "3.1.3. Defender Plan: Servers",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "The Endpoint protection component enables Microsoft Defender for Endpoint (formerly 'Advanced Threat Protection' or 'ATP' or 'WDATP' - see additional info) to communicate with Microsoft Defender for Cloud.**IMPORTANT:** When enabling integration between DfE & DfC it needs to be taken into account that this will have some side effects that may be undesirable.1. For server 2019 & above if defender is installed (default for these server SKUs) this will trigger a deployment of the new unified agent and link to any of the extended configuration in the Defender portal.1. If the new unified agent is required for server SKUs of Win 2016 or Linux and lower there is additional integration that needs to be switched on and agents need to be aligned.",
@@ -1024,7 +1048,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1.3. Defender Plan: Servers",
+ "Section": "3. Security",
+ "SubSection": "3.1.3. Defender Plan: Servers",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Using disk snapshots, the agentless scanner scans for installed software, vulnerabilities, and plain text secrets.",
@@ -1044,7 +1069,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1.3. Defender Plan: Servers",
+ "Section": "3. Security",
+ "SubSection": "3.1.3. Defender Plan: Servers",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "File Integrity Monitoring (FIM) is a feature that monitors critical system files in Windows or Linux for potential signs of attack or compromise.",
@@ -1066,7 +1092,8 @@
],
"Attributes": [
{
- "Section": "3.1.4. Defender Plan: Containers",
+ "Section": "3. Security",
+ "SubSection": "3.1.4. Defender Plan: Containers",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Containers enables threat detection for Container Registries including Kubernetes, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud. The following services will be enabled for container instances:- Defender agent in Azure- Azure Policy for Kubernetes- Agentless discovery for Kubernetes- Agentless container vulnerability assessment",
@@ -1086,7 +1113,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1.4. Defender Plan: Containers",
+ "Section": "3. Security",
+ "SubSection": "3.1.4. Defender Plan: Containers",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable automatic discovery and configuration scanning of the Microsoft Kubernetes clusters.",
@@ -1106,7 +1134,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1.4. Defender Plan: Containers",
+ "Section": "3. Security",
+ "SubSection": "3.1.4. Defender Plan: Containers",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable automatic vulnerability management for images stored in ACR or running in AKS clusters.",
@@ -1128,7 +1157,8 @@
],
"Attributes": [
{
- "Section": "3.1.5. Defender Plan: Storage",
+ "Section": "3. Security",
+ "SubSection": "3.1.5. Defender Plan: Storage",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Storage enables threat detection for Storage, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -1150,7 +1180,8 @@
],
"Attributes": [
{
- "Section": "3.1.6. Defender Plan: App Service",
+ "Section": "3. Security",
+ "SubSection": "3.1.6. Defender Plan: App Service",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for App Service enables threat detection for App Service, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -1172,7 +1203,8 @@
],
"Attributes": [
{
- "Section": "3.1.7. Defender Plan: Databases",
+ "Section": "3. Security",
+ "SubSection": "3.1.7. Defender Plan: Databases",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.",
@@ -1194,7 +1226,8 @@
],
"Attributes": [
{
- "Section": "3.1.7. Defender Plan: Databases",
+ "Section": "3. Security",
+ "SubSection": "3.1.7. Defender Plan: Databases",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -1216,7 +1249,8 @@
],
"Attributes": [
{
- "Section": "3.1.7. Defender Plan: Databases",
+ "Section": "3. Security",
+ "SubSection": "3.1.7. Defender Plan: Databases",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Azure SQL Databases enables threat detection for Managed Instance Azure SQL databases, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.",
@@ -1238,7 +1272,8 @@
],
"Attributes": [
{
- "Section": "3.1.7. Defender Plan: Databases",
+ "Section": "3. Security",
+ "SubSection": "3.1.7. Defender Plan: Databases",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for SQL servers on machines enables threat detection for SQL servers on machines, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.",
@@ -1260,7 +1295,8 @@
],
"Attributes": [
{
- "Section": "3.1.8. Defender Plan: Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.1.8. Defender Plan: Key Vault",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Turning on Microsoft Defender for Key Vault enables threat detection for Key Vault, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.",
@@ -1282,7 +1318,8 @@
],
"Attributes": [
{
- "Section": "3.1.9. Defender Plan: Resource Manager",
+ "Section": "3. Security",
+ "SubSection": "3.1.9. Defender Plan: Resource Manager",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Microsoft Defender for Resource Manager scans incoming administrative requests to change your infrastructure from both CLI and the Azure portal.",
@@ -1304,7 +1341,8 @@
],
"Attributes": [
{
- "Section": "3.2. Microsoft Defender for IoT",
+ "Section": "3. Security",
+ "SubSection": "3.2. Microsoft Defender for IoT",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Microsoft Defender for IoT acts as a central security hub for IoT devices within your organization.",
@@ -1326,7 +1364,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that all Keys in Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.",
@@ -1348,7 +1387,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that all Keys in Non Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.",
@@ -1370,7 +1410,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that all Secrets in Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.",
@@ -1392,7 +1433,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that all Secrets in Non Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.",
@@ -1414,7 +1456,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The Key Vault contains object keys, secrets, and certificates. Accidental unavailability of a Key Vault can cause immediate data loss or loss of security functions (authentication, validation, verification, non-repudiation, etc.) supported by the Key Vault objects.It is recommended the Key Vault be made recoverable by enabling the 'Do Not Purge' and 'Soft Delete' functions. This is in order to prevent loss of encrypted data, including storage accounts, SQL databases, and/or dependent services provided by Key Vault objects (Keys, Secrets, Certificates) etc. This may happen in the case of accidental deletion by a user or from disruptive activity by a malicious user.**NOTE:** In February 2025, Microsoft will enable soft-delete protection on all key vaults, and users will no longer be able to opt out of or turn off soft-delete. **WARNING:** A current limitation is that role assignments disappearing when Key Vault is deleted. All role assignments will need to be recreated after recovery.",
@@ -1436,7 +1479,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "The recommended way to access Key Vaults is to use the Azure Role-Based Access Control (RBAC) permissions model.Azure RBAC is an authorization system built on Azure Resource Manager that provides fine-grained access management of Azure resources. It allows users to manage Key, Secret, and Certificate permissions. It provides one place to manage all permissions across all key vaults.",
@@ -1458,7 +1502,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Private endpoints will secure network traffic from Azure Key Vault to the resources requesting secrets and keys.",
@@ -1480,7 +1525,8 @@
],
"Attributes": [
{
- "Section": "3.3. Key Vault",
+ "Section": "3. Security",
+ "SubSection": "3.3. Key Vault",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Automatic Key Rotation is available in Public Preview. The currently supported applications are Key Vault, Managed Disks, and Storage accounts accessing keys within Key Vault. The number of supported applications will incrementally increased.",
@@ -1862,7 +1908,8 @@
],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable auditing on SQL Servers.",
@@ -1884,7 +1931,8 @@
],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure that no SQL Databases allow ingress from 0.0.0.0/0 (ANY IP).",
@@ -1906,7 +1954,8 @@
],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Transparent Data Encryption (TDE) with Customer-managed key support provides increased transparency and control over the TDE Protector, increased security with an HSM-backed external service, and promotion of separation of duties.With TDE, data is encrypted at rest with a symmetric key (called the database encryption key) stored in the database or data warehouse distribution. To protect this data encryption key (DEK) in the past, only a certificate that the Azure SQL Service managed could be used. Now, with Customer-managed key support for TDE, the DEK can be protected with an asymmetric key that is stored in the Azure Key Vault. The Azure Key Vault is a highly available and scalable cloud-based key store which offers central key management, leverages FIPS 140-2 Level 2 validated hardware security modules (HSMs), and allows separation of management of keys and data for additional security.Based on business needs or criticality of data/databases hosted on a SQL server, it is recommended that the TDE protector is encrypted by a key that is managed by the data owner (Customer-managed key).",
@@ -1928,7 +1977,8 @@
],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Use Microsoft Entra authentication for authentication with SQL Database to manage credentials in a single place.",
@@ -1950,7 +2000,8 @@
],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable Transparent Data Encryption on every SQL server.",
@@ -1972,7 +2023,8 @@
],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "SQL Server Audit Retention should be configured to be greater than 90 days.",
@@ -1992,7 +2044,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1. Azure SQL Database",
+ "Section": "5. Database Services",
+ "SubSection": "5.1. Azure SQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Disabling public network access restricts the service from accessing public networks.",
@@ -2014,7 +2067,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `require_secure_transport` on `PostgreSQL flexible servers`.",
@@ -2036,7 +2090,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `log_checkpoints` on `PostgreSQL flexible servers`.",
@@ -2058,7 +2113,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable connection throttling on `PostgreSQL flexible servers`.",
@@ -2080,7 +2136,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure `logfiles.retention_days` on `PostgreSQL flexible servers` is set to an appropriate value.",
@@ -2102,7 +2159,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Disable access from Azure services to `PostgreSQL flexible server`.",
@@ -2124,7 +2182,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `log_connections` on `PostgreSQL single servers`.**NOTE:** This recommendation currently only applies to Single Server, not Flexible Server. See additional information below for details about the planned retirement of Azure PostgreSQL Single Server.",
@@ -2146,7 +2205,8 @@
],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `log_disconnections` on `PostgreSQL Servers`.**NOTE:** This recommendation currently only applies to Single Server, not Flexible Server. See additional information below for details about the planned retirement of Azure PostgreSQL Single Server.",
@@ -2166,7 +2226,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.2. Azure SQL Database for PostgreSQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.2. Azure SQL Database for PostgreSQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Azure Database for PostgreSQL servers should be created with 'infrastructure double encryption' enabled.**NOTE:** This recommendation currently only applies to Single Server, not Flexible Server. See additional information below for details about the planned retirement of Azure PostgreSQL Single Server.",
@@ -2188,7 +2249,8 @@
],
"Attributes": [
{
- "Section": "5.3. Azure for MySQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.3. Azure for MySQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable `require_secure_transport` on `MySQL flexible servers`.",
@@ -2208,7 +2270,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3. Azure for MySQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.3. Azure for MySQL",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure `tls_version` on `MySQL flexible servers` is set to use TLS version 1.2 or higher.",
@@ -2230,7 +2293,8 @@
],
"Attributes": [
{
- "Section": "5.3. Azure for MySQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.3. Azure for MySQL",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Enable `audit_log_enabled` on `MySQL flexible servers`.",
@@ -2252,7 +2316,8 @@
],
"Attributes": [
{
- "Section": "5.3. Azure for MySQL",
+ "Section": "5. Database Services",
+ "SubSection": "5.3. Azure for MySQL",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Set `audit_log_events` to include `CONNECTION` on `MySQL flexible servers`.",
@@ -2274,7 +2339,8 @@
],
"Attributes": [
{
- "Section": "5.4. Azure Cosmos DB",
+ "Section": "5. Database Services",
+ "SubSection": "5.4. Azure Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Limiting your Cosmos DB to only communicate on whitelisted networks lowers its attack footprint.",
@@ -2296,7 +2362,8 @@
],
"Attributes": [
{
- "Section": "5.4. Azure Cosmos DB",
+ "Section": "5. Database Services",
+ "SubSection": "5.4. Azure Cosmos DB",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Private endpoints limit network traffic to approved sources.",
@@ -2318,7 +2385,8 @@
],
"Attributes": [
{
- "Section": "5.4. Azure Cosmos DB",
+ "Section": "5. Database Services",
+ "SubSection": "5.4. Azure Cosmos DB",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Cosmos DB can use tokens or Entra ID for client authentication which in turn will use Azure RBAC for authorization. Using Entra ID is significantly more secure because Entra ID handles the credentials and allows for MFA and centralized management, and the Azure RBAC is better integrated with the rest of Azure.",
@@ -2380,7 +2448,8 @@
],
"Attributes": [
{
- "Section": "6.1. Configuring Diagnostic Settings",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.1. Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "Enable Diagnostic settings for exporting activity logs.Diagnostic settings are available for each individual resource within a subscription. Settings should be configured for all appropriate resources for your environment.",
@@ -2402,7 +2471,8 @@
],
"Attributes": [
{
- "Section": "6.1. Configuring Diagnostic Settings",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.1. Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "**Prerequisite**: A Diagnostic Setting must exist. If a Diagnostic Setting does not exist, the navigation and options within this recommendation will not be available. Please review the recommendation at the beginning of this subsection titled: 'Ensure that a 'Diagnostic Setting' exists.'The diagnostic setting should be configured to log the appropriate activities from the control/management plane.",
@@ -2424,7 +2494,8 @@
],
"Attributes": [
{
- "Section": "6.1. Configuring Diagnostic Settings",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.1. Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Storage accounts with the activity log exports can be configured to use Customer Managed Keys (CMK).",
@@ -2446,7 +2517,8 @@
],
"Attributes": [
{
- "Section": "6.1. Configuring Diagnostic Settings",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.1. Configuring Diagnostic Settings",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available.",
@@ -2468,7 +2540,8 @@
],
"Attributes": [
{
- "Section": "6.1. Configuring Diagnostic Settings",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.1. Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Ensure that network flow logs are captured and fed into a central log analytics workspace.",
@@ -2490,7 +2563,8 @@
],
"Attributes": [
{
- "Section": "6.1. Configuring Diagnostic Settings",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.1. Configuring Diagnostic Settings",
"Profile": "Level 2",
"AssessmentStatus": "Manual",
"Description": "Enable AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all http requests are captured and centrally logged.",
@@ -2512,7 +2586,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create Policy Assignment event.",
@@ -2534,7 +2609,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Policy Assignment event.",
@@ -2556,7 +2632,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an Activity Log Alert for the Create or Update Network Security Group event.",
@@ -2578,7 +2655,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Network Security Group event.",
@@ -2600,7 +2678,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update Security Solution event.",
@@ -2622,7 +2701,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Security Solution event.",
@@ -2644,7 +2724,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update SQL Server Firewall Rule event.",
@@ -2666,7 +2747,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the 'Delete SQL Server Firewall Rule.",
@@ -2688,7 +2770,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Create or Update Public IP Addresses rule.",
@@ -2710,7 +2793,8 @@
],
"Attributes": [
{
- "Section": "6.2. Monitoring using Activity Log Alerts",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.2. Monitoring using Activity Log Alerts",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Create an activity log alert for the Delete Public IP Address rule.",
@@ -2732,7 +2816,8 @@
],
"Attributes": [
{
- "Section": "6.3. Configuring Application Insights",
+ "Section": "6. Logging and Monitoring",
+ "SubSection": "6.3. Configuring Application Insights",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "Application Insights within Azure act as an Application Performance Monitoring solution providing valuable data into how well an application performs and additional information when performing incident response. The types of log data collected include application metrics, telemetry data, and application trace logging data providing organizations with detailed information about application activity and application transactions. Both data sets help organizations adopt a proactive and retroactive means to handle security and performance related metrics within their modern applications.",
diff --git a/prowler/compliance/gcp/cis_2.0_gcp.json b/prowler/compliance/gcp/cis_2.0_gcp.json
index a13cb61364..abc6238a09 100644
--- a/prowler/compliance/gcp/cis_2.0_gcp.json
+++ b/prowler/compliance/gcp/cis_2.0_gcp.json
@@ -1292,7 +1292,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "6.1. MySQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.1. MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "It is recommended to set a password for the administrative user (`root` by default) to prevent unauthorized access to the SQL database instances. This recommendation is applicable only for MySQL Instances. PostgreSQL does not offer any setting for No Password from the cloud console.",
@@ -1313,7 +1314,8 @@
],
"Attributes": [
{
- "Section": "6.1. MySQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.1. MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `skip_show_database` database flag for Cloud SQL Mysql instance to `on`",
@@ -1334,7 +1336,8 @@
],
"Attributes": [
{
- "Section": "6.1. MySQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.1. MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set the `local_infile` database flag for a Cloud SQL MySQL instance to `off`.",
@@ -1355,7 +1358,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "The `log_error_verbosity` flag controls the verbosity/details of messages logged. Valid values are: - `TERSE` - `DEFAULT` - `VERBOSE` `TERSE` excludes the logging of `DETAIL`, `HINT`, `QUERY`, and `CONTEXT` error information. `VERBOSE` output includes the `SQLSTATE` error code, source code file name, function name, and line number that generated the error. Ensure an appropriate value is set to 'DEFAULT' or stricter.",
@@ -1376,7 +1380,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The `log_min_error_statement` flag defines the minimum message severity level that are considered as an error statement. Messages for error statements are logged with the SQL statement. Valid values include `DEBUG5`, `DEBUG4`, `DEBUG3`, `DEBUG2`, `DEBUG1`, `INFO`, `NOTICE`, `WARNING`, `ERROR`, `LOG`, `FATAL`, and `PANIC`. Each severity level includes the subsequent levels mentioned above. Ensure a value of `ERROR` or stricter is set.",
@@ -1397,7 +1402,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "The value of `log_statement` flag determined the SQL statements that are logged. Valid values are: - `none` - `ddl` - `mod` - `all` The value `ddl` logs all data definition statements. The value `mod` logs all ddl statements, plus data-modifying statements. The statements are logged after a basic parsing is done and statement type is determined, thus this does not logs statements with errors. When using extended query protocol, logging occurs after an Execute message is received and values of the Bind parameters are included. A value of 'ddl' is recommended unless otherwise directed by your organization's logging policy.",
@@ -1418,7 +1424,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Instance addresses can be public IP or private IP. Public IP means that the instance is accessible through the public internet. In contrast, instances using only private IP are not accessible through the public internet, but are accessible through a Virtual Private Cloud (VPC). Limiting network access to your database will limit potential attacks.",
@@ -1439,7 +1446,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure `cloudsql.enable_pgaudit` database flag for Cloud SQL PostgreSQL instance is set to `on` to allow for centralized logging.",
@@ -1460,7 +1468,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enabling the `log_connections` setting causes each attempted connection to the server to be logged, along with successful completion of client authentication. This parameter cannot be changed after the session starts.",
@@ -1481,7 +1490,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enabling the `log_disconnections` setting logs the end of each session, including the session duration.",
@@ -1502,7 +1512,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The `log_min_duration_statement` flag defines the minimum amount of execution time of a statement in milliseconds where the total duration of the statement is logged. Ensure that `log_min_duration_statement` is disabled, i.e., a value of `-1` is set.",
@@ -1523,7 +1534,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The `log_min_messages` flag defines the minimum message severity level that is considered as an error statement. Messages for error statements are logged with the SQL statement. Valid values include `DEBUG5`, `DEBUG4`, `DEBUG3`, `DEBUG2`, `DEBUG1`, `INFO`, `NOTICE`, `WARNING`, `ERROR`, `LOG`, `FATAL`, and `PANIC`. Each severity level includes the subsequent levels mentioned above. ERROR is considered the best practice setting. Changes should only be made in accordance with the organization's logging policy.",
@@ -1544,7 +1556,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `3625 (trace flag)` database flag for Cloud SQL SQL Server instance to `on`.",
@@ -1565,7 +1578,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `external scripts enabled` database flag for Cloud SQL SQL Server instance to `off`",
@@ -1586,7 +1600,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `remote access` database flag for Cloud SQL SQL Server instance to `off`.",
@@ -1607,7 +1622,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to check the `user connections` for a Cloud SQL SQL Server instance to ensure that it is not artificially limiting connections.",
@@ -1628,7 +1644,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended that, `user options` database flag for Cloud SQL SQL Server instance should not be configured.",
@@ -1649,7 +1666,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `contained database authentication` database flag for Cloud SQL on the SQL Server instance to `off`.",
@@ -1670,7 +1688,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `cross db ownership chaining` database flag for Cloud SQL SQL Server instance to `off`.",
diff --git a/prowler/compliance/gcp/cis_3.0_gcp.json b/prowler/compliance/gcp/cis_3.0_gcp.json
index 7c43232a5b..6ae75a260e 100644
--- a/prowler/compliance/gcp/cis_3.0_gcp.json
+++ b/prowler/compliance/gcp/cis_3.0_gcp.json
@@ -1330,7 +1330,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "6.1. MySQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.1. MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Manual",
"Description": "It is recommended to set a password for the administrative user (`root` by default) to prevent unauthorized access to the SQL database instances.This recommendation is applicable only for MySQL Instances. PostgreSQL does not offer any setting for No Password from the cloud console.",
@@ -1352,7 +1353,8 @@
],
"Attributes": [
{
- "Section": "6.1. MySQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.1. MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `skip_show_database` database flag for Cloud SQL Mysql instance to `on`",
@@ -1374,7 +1376,8 @@
],
"Attributes": [
{
- "Section": "6.1. MySQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.1. MySQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set the `local_infile` database flag for a Cloud SQL MySQL instance to `off`.",
@@ -1396,7 +1399,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "The `log_error_verbosity` flag controls the verbosity/details of messages logged. Valid values are:- `TERSE`- `DEFAULT`- `VERBOSE``TERSE` excludes the logging of `DETAIL`, `HINT`, `QUERY`, and `CONTEXT` error information.`VERBOSE` output includes the `SQLSTATE` error code, source code file name, function name, and line number that generated the error.Ensure an appropriate value is set to 'DEFAULT' or stricter.",
@@ -1418,7 +1422,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enabling the `log_connections` setting causes each attempted connection to the server to be logged, along with successful completion of client authentication. This parameter cannot be changed after the session starts.",
@@ -1440,7 +1445,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Enabling the `log_disconnections` setting logs the end of each session, including the session duration.",
@@ -1462,7 +1468,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 2",
"AssessmentStatus": "Automated",
"Description": "The value of `log_statement` flag determined the SQL statements that are logged. Valid values are:- `none`- `ddl`- `mod`- `all`The value `ddl` logs all data definition statements.The value `mod` logs all ddl statements, plus data-modifying statements.The statements are logged after a basic parsing is done and statement type is determined, thus this does not logs statements with errors. When using extended query protocol, logging occurs after an Execute message is received and values of the Bind parameters are included.A value of 'ddl' is recommended unless otherwise directed by your organization's logging policy.",
@@ -1484,7 +1491,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The `log_min_messages` flag defines the minimum message severity level that is considered as an error statement. Messages for error statements are logged with the SQL statement. Valid values include (from lowest to highest severity) `DEBUG5`, `DEBUG4`, `DEBUG3`, `DEBUG2`, `DEBUG1`, `INFO`, `NOTICE`, `WARNING`, `ERROR`, `LOG`, `FATAL`, and `PANIC`.Each severity level includes the subsequent levels mentioned above. ERROR is considered the best practice setting. Changes should only be made in accordance with the organization's logging policy.",
@@ -1506,7 +1514,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The `log_min_error_statement` flag defines the minimum message severity level that are considered as an error statement. Messages for error statements are logged with the SQL statement. Valid values include (from lowest to highest severity) `DEBUG5`, `DEBUG4`, `DEBUG3`, `DEBUG2`, `DEBUG1`, `INFO`, `NOTICE`, `WARNING`, `ERROR`, `LOG`, `FATAL`, and `PANIC`.Each severity level includes the subsequent levels mentioned above. Ensure a value of `ERROR` or stricter is set.",
@@ -1528,7 +1537,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "The `log_min_duration_statement` flag defines the minimum amount of execution time of a statement in milliseconds where the total duration of the statement is logged. Ensure that `log_min_duration_statement` is disabled, i.e., a value of `-1` is set.",
@@ -1550,7 +1560,8 @@
],
"Attributes": [
{
- "Section": "6.2. PostgreSQL Database",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.2. PostgreSQL Database",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "Ensure `cloudsql.enable_pgaudit` database flag for Cloud SQL PostgreSQL instance is set to `on` to allow for centralized logging.",
@@ -1572,7 +1583,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `external scripts enabled` database flag for Cloud SQL SQL Server instance to `off`",
@@ -1594,7 +1606,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `cross db ownership chaining` database flag for Cloud SQL SQL Server instance to `off`.This flag is deprecated for all SQL Server versions in CGP. Going forward, you can't set its value to on. However, if you have this flag enabled, we strongly recommend that you either remove the flag from your database or set it to off. For cross-database access, use the [Microsoft tutorial for signing stored procedures with a certificate](https://learn.microsoft.com/en-us/sql/relational-databases/tutorial-signing-stored-procedures-with-a-certificate?view=sql-server-ver16).",
@@ -1616,7 +1629,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to check the `user connections` for a Cloud SQL SQL Server instance to ensure that it is not artificially limiting connections.",
@@ -1638,7 +1652,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended that, `user options` database flag for Cloud SQL SQL Server instance should not be configured.",
@@ -1660,7 +1675,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `remote access` database flag for Cloud SQL SQL Server instance to `off`.",
@@ -1682,7 +1698,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended to set `3625 (trace flag)` database flag for Cloud SQL SQL Server instance to `on`.",
@@ -1704,7 +1721,8 @@
],
"Attributes": [
{
- "Section": "6.3. SQL Server",
+ "Section": "6. Cloud SQL Database Services",
+ "SubSection": "6.3. SQL Server",
"Profile": "Level 1",
"AssessmentStatus": "Automated",
"Description": "It is recommended not to set `contained database authentication` database flag for Cloud SQL on the SQL Server instance to `on`.",
diff --git a/prowler/compliance/kubernetes/cis_1.10_kubernetes.json b/prowler/compliance/kubernetes/cis_1.10_kubernetes.json
index ff2ad3f92a..7c7c9e6898 100644
--- a/prowler/compliance/kubernetes/cis_1.10_kubernetes.json
+++ b/prowler/compliance/kubernetes/cis_1.10_kubernetes.json
@@ -10,7 +10,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the API server pod specification file has permissions of `600` or more restrictive.",
@@ -30,7 +31,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the API server pod specification file ownership is set to `root:root`.",
@@ -50,7 +52,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.",
@@ -70,7 +73,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the controller manager pod specification file ownership is set to `root:root`.",
@@ -90,7 +94,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the scheduler pod specification file has permissions of `600` or more restrictive.",
@@ -110,7 +115,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the scheduler pod specification file ownership is set to `root:root`.",
@@ -130,7 +136,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `/etc/kubernetes/manifests/etcd.yaml` file has permissions of `600` or more restrictive.",
@@ -150,7 +157,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `/etc/kubernetes/manifests/etcd.yaml` file ownership is set to `root:root`.",
@@ -170,7 +178,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Container Network Interface files have permissions of `600` or more restrictive.",
@@ -190,7 +199,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Container Network Interface files have ownership set to `root:root`.",
@@ -210,7 +220,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the etcd data directory has permissions of `700` or more restrictive.",
@@ -230,7 +241,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the etcd data directory ownership is set to `etcd:etcd`.",
@@ -250,7 +262,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `admin.conf` file (and `super-admin.conf` file, where it exists) have permissions of `600`.",
@@ -270,7 +283,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `admin.conf` (and `super-admin.conf` file, where it exists) file ownership is set to `root:root`.",
@@ -290,7 +304,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `scheduler.conf` file has permissions of `600` or more restrictive.",
@@ -310,7 +325,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `scheduler.conf` file ownership is set to `root:root`.",
@@ -330,7 +346,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `controller-manager.conf` file has permissions of 600 or more restrictive.",
@@ -350,7 +367,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `controller-manager.conf` file ownership is set to `root:root`.",
@@ -370,7 +388,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the Kubernetes PKI directory and file ownership is set to `root:root`.",
@@ -390,7 +409,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that Kubernetes PKI certificate files have permissions of `600` or more restrictive.",
@@ -410,7 +430,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1. Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1. Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that Kubernetes PKI key files have permissions of `600`.",
@@ -432,7 +453,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Disable anonymous requests to the API server.",
@@ -454,7 +476,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not use token based authentication.",
@@ -476,7 +499,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "This admission controller rejects all net-new usage of the Service field externalIPs.",
@@ -498,7 +522,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Enable certificate based kubelet authentication.",
@@ -520,7 +545,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Verify kubelet's certificate before establishing connection.",
@@ -542,7 +568,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not always authorize all requests.",
@@ -564,7 +591,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Restrict kubelet nodes to reading only objects associated with them.",
@@ -586,7 +614,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Turn on Role Based Access Control.",
@@ -608,7 +637,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Limit the rate at which the API server accepts requests.",
@@ -630,7 +660,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not allow all requests.",
@@ -652,7 +683,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Always pull images.",
@@ -674,7 +706,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Automate service accounts management.",
@@ -696,7 +729,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Reject creating objects in a namespace that is undergoing termination.",
@@ -718,7 +752,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Limit the `Node` and `Pod` objects that a kubelet could modify.",
@@ -740,7 +775,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Disable profiling, if not needed.",
@@ -762,7 +798,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Enable auditing on the Kubernetes API Server and set the desired audit log path.",
@@ -784,7 +821,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Retain the logs for at least 30 days or as appropriate.",
@@ -806,7 +844,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Retain 10 or an appropriate number of old log files.",
@@ -828,7 +867,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Rotate log files on reaching 100 MB or as appropriate.",
@@ -850,7 +890,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Set global request timeout for API server requests as appropriate.",
@@ -872,7 +913,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Validate service account before validating token.",
@@ -894,7 +936,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Explicitly set a service account public key file for service accounts on the apiserver.",
@@ -916,7 +959,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "etcd should be configured to make use of TLS encryption for client connections.",
@@ -938,7 +982,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Setup TLS connection on the API server.",
@@ -960,7 +1005,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Setup TLS connection on the API server.",
@@ -982,7 +1028,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "etcd should be configured to make use of TLS encryption for client connections.",
@@ -1004,7 +1051,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Encrypt etcd key-value store.",
@@ -1024,7 +1072,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Where `etcd` encryption is used, appropriate providers should be configured.",
@@ -1046,7 +1095,8 @@
],
"Attributes": [
{
- "Section": "1.2. API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2. API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the API server is configured to only use strong cryptographic ciphers.",
@@ -1068,7 +1118,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Activate garbage collector on pod termination, as appropriate.",
@@ -1090,7 +1141,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Disable profiling, if not needed.",
@@ -1112,7 +1164,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Use individual service account credentials for each controller.",
@@ -1134,7 +1187,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Explicitly set a service account private key file for service accounts on the controller manager.",
@@ -1156,7 +1210,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Allow pods to verify the API server's serving certificate before establishing connections.",
@@ -1178,7 +1233,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Enable kubelet server certificate rotation on controller-manager.",
@@ -1200,7 +1256,8 @@
],
"Attributes": [
{
- "Section": "1.3. Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3. Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not bind the Controller Manager service to non-loopback insecure addresses.",
@@ -1222,7 +1279,8 @@
],
"Attributes": [
{
- "Section": "1.4. Scheduler",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.4. Scheduler",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Disable profiling, if not needed.",
@@ -1244,7 +1302,8 @@
],
"Attributes": [
{
- "Section": "1.4. Scheduler",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.4. Scheduler",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not bind the scheduler service to non-loopback insecure addresses.",
@@ -1418,7 +1477,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1. Authentication and Authorization",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.1. Authentication and Authorization",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides the option to use client certificates for user authentication. However as there is no way to revoke these certificates when a user leaves an organization or loses their credential, they are not suitable for this purpose.It is not possible to fully disable client certificate use within a cluster as it is used for component to component authentication.",
@@ -1438,7 +1498,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1. Authentication and Authorization",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.1. Authentication and Authorization",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides service account tokens which are intended for use by workloads running in the Kubernetes cluster, for authentication to the API server.These tokens are not designed for use by end-users and do not provide for features such as revocation or expiry, making them insecure. A newer version of the feature (Bound service account token volumes) does introduce expiry but still does not allow for specific revocation.",
@@ -1458,7 +1519,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1. Authentication and Authorization",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.1. Authentication and Authorization",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides bootstrap tokens which are intended for use by new nodes joining the clusterThese tokens are not designed for use by end-users they are specifically designed for the purpose of bootstrapping new nodes and not for general authentication",
@@ -1478,7 +1540,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.2. Logging",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.2. Logging",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes can audit the details of requests made to the API server. The `--audit-policy-file` flag must be set for this logging to be enabled.",
@@ -1498,7 +1561,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.2. Logging",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.2. Logging",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the audit policy created for the cluster covers key security concerns.",
@@ -1520,7 +1584,8 @@
],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet` service file has permissions of `600` or more restrictive.",
@@ -1542,7 +1607,8 @@
],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet` service file ownership is set to `root:root`.",
@@ -1562,7 +1628,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "If `kube-proxy` is running, and if it is using a file-based kubeconfig file, ensure that the proxy kubeconfig file has permissions of `600` or more restrictive.",
@@ -1582,7 +1649,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "If `kube-proxy` is running, ensure that the file ownership of its kubeconfig file is set to `root:root`.",
@@ -1604,7 +1672,8 @@
],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet.conf` file has permissions of `600` or more restrictive.",
@@ -1626,7 +1695,8 @@
],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet.conf` file ownership is set to `root:root`.",
@@ -1646,7 +1716,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the certificate authorities file has permissions of `600` or more restrictive.",
@@ -1666,7 +1737,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the certificate authorities file ownership is set to `root:root`.",
@@ -1688,7 +1760,8 @@
],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that if the kubelet refers to a configuration file with the `--config` argument, that file has permissions of 600 or more restrictive.",
@@ -1710,7 +1783,8 @@
],
"Attributes": [
{
- "Section": "4.1. Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1. Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that if the kubelet refers to a configuration file with the `--config` argument, that file is owned by root:root.",
@@ -1732,7 +1806,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Disable anonymous requests to the Kubelet server.",
@@ -1754,7 +1829,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Do not allow all requests. Enable explicit authorization.",
@@ -1776,7 +1852,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Enable Kubelet authentication using certificates.",
@@ -1798,7 +1875,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Disable the read-only port.",
@@ -1820,7 +1898,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Do not disable timeouts on streaming connections.",
@@ -1842,7 +1921,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Allow Kubelet to manage iptables.",
@@ -1862,7 +1942,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Do not override node hostnames.",
@@ -1884,7 +1965,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 2 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Security relevant information should be captured. The eventRecordQPS on the Kubelet configuration can be used to limit the rate at which events are gathered and sets the maximum event creations per second. Setting this too low could result in relevant events not being logged, however the unlimited setting of `0` could result in a denial of service on the kubelet.",
@@ -1906,7 +1988,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Setup TLS connection on the Kubelets.",
@@ -1928,7 +2011,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Enable kubelet client certificate rotation.",
@@ -1948,7 +2032,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Enable kubelet server certificate rotation.",
@@ -1970,7 +2055,8 @@
],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Kubelet is configured to only use strong cryptographic ciphers.",
@@ -1990,7 +2076,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.2. Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2. Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Kubelet sets limits on the number of PIDs that can be created by pods running on the node.",
@@ -2010,7 +2097,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.3. kube-proxy",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.3. kube-proxy",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Do not bind the kube-proxy metrics port to non-loopback addresses.",
@@ -2032,7 +2120,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "The RBAC role `cluster-admin` provides wide-ranging powers over the environment and should be used only where and when needed.",
@@ -2054,7 +2143,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "The Kubernetes API stores secrets, which may be service account tokens for the Kubernetes API or credentials used by workloads in the cluster. Access to these secrets should be restricted to the smallest possible group of users to reduce the risk of privilege escalation.",
@@ -2076,7 +2166,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Kubernetes Roles and ClusterRoles provide access to resources based on sets of objects and actions that can be taken on those objects. It is possible to set either of these to be the wildcard \"*\" which matches all items. Use of wildcards is not optimal from a security perspective as it may allow for inadvertent access to be granted when new resources are added to the Kubernetes API either as CRDs or in later versions of the product.",
@@ -2098,7 +2189,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "The ability to create pods in a namespace can provide a number of opportunities for privilege escalation, such as assigning privileged service accounts to these pods or mounting hostPaths with access to sensitive data (unless Pod Security Policies are implemented to restrict this access)As such, access to create new pods should be restricted to the smallest possible group of users.",
@@ -2118,7 +2210,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "The `default` service account should not be used to ensure that rights granted to applications can be more easily audited and reviewed.",
@@ -2138,7 +2231,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Service accounts tokens should not be mounted in pods except where the workload running in the pod explicitly needs to communicate with the API server",
@@ -2158,7 +2252,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The special group `system:masters` should not be used to grant permissions to any user or service account, except where strictly necessary (e.g. bootstrapping access prior to RBAC being fully available)",
@@ -2178,7 +2273,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Cluster roles and roles with the impersonate, bind or escalate permissions should not be granted unless strictly required. Each of these permissions allow a particular subject to escalate their privileges beyond those explicitly granted by cluster administrators",
@@ -2200,7 +2296,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The ability to create persistent volumes in a cluster can provide an opportunity for privilege escalation, via the creation of `hostPath` volumes. As persistent volumes are not covered by Pod Security Admission, a user with access to create persistent volumes may be able to get access to sensitive files from the underlying host even where restrictive Pod Security Admission policies are in place.",
@@ -2222,7 +2319,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with access to the `Proxy` sub-resource of `Node` objects automatically have permissions to use the Kubelet API, which may allow for privilege escalation or bypass cluster security controls such as audit logs.The Kubelet provides an API which includes rights to execute commands in any container running on the node. Access to this API is covered by permissions to the main Kubernetes API via the `node` object. The proxy sub-resource specifically allows wide ranging access to the Kubelet API.Direct access to the Kubelet API bypasses controls like audit logging (there is no audit log of Kubelet API access) and admission control.",
@@ -2244,7 +2342,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with access to the update the `approval` sub-resource of `certificateaigningrequests` objects can approve new client certificates for the Kubernetes API effectively allowing them to create new high-privileged user accounts.This can allow for privilege escalation to full cluster administrator, depending on users configured in the cluster",
@@ -2266,7 +2365,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with rights to create/modify/delete `validatingwebhookconfigurations` or `mutatingwebhookconfigurations` can control webhooks that can read any object admitted to the cluster, and in the case of mutating webhooks, also mutate admitted objects. This could allow for privilege escalation or disruption of the operation of the cluster.",
@@ -2288,7 +2388,8 @@
],
"Attributes": [
{
- "Section": "5.1. RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1. RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with rights to create new service account tokens at a cluster level, can create long-lived privileged credentials in the cluster. This could allow for privilege escalation and persistent access to the cluster, even if the users account has been revoked.",
@@ -2308,7 +2409,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Every Kubernetes cluster should have at least one policy control mechanism in place to enforce the other requirements in this section. This could be the in-built Pod Security Admission controller, or a third party policy control system.",
@@ -2330,7 +2432,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run with the `securityContext.privileged` flag set to `true`.",
@@ -2352,7 +2455,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run with the `hostPID` flag set to true.",
@@ -2374,7 +2478,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run with the `hostIPC` flag set to true.",
@@ -2396,7 +2501,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run with the `hostNetwork` flag set to true.",
@@ -2418,7 +2524,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run with the `allowPrivilegeEscalation` flag set to true. Allowing this right can lead to a process running a container getting more rights than it started with.It's important to note that these rights are still constrained by the overall container sandbox, and this setting does not relate to the use of privileged containers.",
@@ -2440,7 +2547,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run as the root user.",
@@ -2462,7 +2570,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers with the potentially dangerous NET_RAW capability.",
@@ -2484,7 +2593,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers with capabilities assigned beyond the default set.",
@@ -2506,7 +2616,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers with capabilities",
@@ -2528,7 +2639,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit Windows containers to be run with the `hostProcess` flag set to true.",
@@ -2548,7 +2660,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally admit containers which make use of `hostPath` volumes.",
@@ -2570,7 +2683,8 @@
],
"Attributes": [
{
- "Section": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
+ "Section": "5. Policies",
+ "SubSection": "5.2. Ensure that the cluster has at least one active policy control mechanism in place",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers which require the use of HostPorts.",
@@ -2590,7 +2704,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3. Network Policies and CNI",
+ "Section": "5. Policies",
+ "SubSection": "5.3. Network Policies and CNI",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "There are a variety of CNI plugins available for Kubernetes. If the CNI in use does not support Network Policies it may not be possible to effectively restrict traffic in the cluster.",
@@ -2610,7 +2725,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3. Network Policies and CNI",
+ "Section": "5. Policies",
+ "SubSection": "5.3. Network Policies and CNI",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Use network policies to isolate traffic in your cluster network.",
@@ -2632,7 +2748,8 @@
],
"Attributes": [
{
- "Section": "5.4. Secrets Management",
+ "Section": "5. Policies",
+ "SubSection": "5.4. Secrets Management",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes supports mounting secrets as data volumes or as environment variables. Minimize the use of environment variable secrets.",
@@ -2652,7 +2769,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.4. Secrets Management",
+ "Section": "5. Policies",
+ "SubSection": "5.4. Secrets Management",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Consider the use of an external secrets storage and management system, instead of using Kubernetes Secrets directly, if you have more complex secret management needs. Ensure the solution requires authentication to access secrets, has auditing of access to and use of secrets, and encrypts secrets. Some solutions also make it easier to rotate secrets.",
@@ -2672,7 +2790,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.5. Extensible Admission Control",
+ "Section": "5. Policies",
+ "SubSection": "5.5. Extensible Admission Control",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Configure Image Provenance for your deployment.",
@@ -2692,7 +2811,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.7. General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7. General Policies",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Use namespaces to isolate your Kubernetes objects.",
@@ -2714,7 +2834,8 @@
],
"Attributes": [
{
- "Section": "5.7. General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7. General Policies",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Enable `docker/default` seccomp profile in your pod definitions.",
@@ -2734,7 +2855,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.7. General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7. General Policies",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Apply Security Context to Your Pods and Containers",
@@ -2754,7 +2876,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.7. General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7. General Policies",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides a default namespace, where objects are placed if no namespace is specified for them. Placing objects in this namespace makes application of RBAC and other controls more difficult.",
diff --git a/prowler/compliance/kubernetes/cis_1.8_kubernetes.json b/prowler/compliance/kubernetes/cis_1.8_kubernetes.json
index f6ddccd6b5..d5786b6668 100644
--- a/prowler/compliance/kubernetes/cis_1.8_kubernetes.json
+++ b/prowler/compliance/kubernetes/cis_1.8_kubernetes.json
@@ -10,7 +10,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the API server pod specification file has permissions of `600` or more restrictive.",
@@ -30,7 +31,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the API server pod specification file ownership is set to `root:root`.",
@@ -50,7 +52,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.",
@@ -70,7 +73,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the controller manager pod specification file ownership is set to `root:root`.",
@@ -90,7 +94,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the scheduler pod specification file has permissions of `600` or more restrictive.",
@@ -110,7 +115,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the scheduler pod specification file ownership is set to `root:root`.",
@@ -130,7 +136,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `/etc/kubernetes/manifests/etcd.yaml` file has permissions of `600` or more restrictive.",
@@ -150,7 +157,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `/etc/kubernetes/manifests/etcd.yaml` file ownership is set to `root:root`.",
@@ -170,7 +178,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Container Network Interface files have permissions of `600` or more restrictive.",
@@ -190,7 +199,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Container Network Interface files have ownership set to `root:root`.",
@@ -210,7 +220,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the etcd data directory has permissions of `700` or more restrictive.",
@@ -230,7 +241,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the etcd data directory ownership is set to `etcd:etcd`.",
@@ -250,7 +262,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `admin.conf` file has permissions of `600`.",
@@ -270,7 +283,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `admin.conf` file ownership is set to `root:root`.",
@@ -290,7 +304,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `scheduler.conf` file has permissions of `600` or more restrictive.",
@@ -310,7 +325,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `scheduler.conf` file ownership is set to `root:root`.",
@@ -330,7 +346,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `controller-manager.conf` file has permissions of 600 or more restrictive.",
@@ -350,7 +367,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `controller-manager.conf` file ownership is set to `root:root`.",
@@ -370,7 +388,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the Kubernetes PKI directory and file ownership is set to `root:root`.",
@@ -390,7 +409,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that Kubernetes PKI certificate files have permissions of `600` or more restrictive.",
@@ -410,7 +430,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.1 Control Plane Node Configuration Files",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.1 Control Plane Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that Kubernetes PKI key files have permissions of `600`.",
@@ -432,7 +453,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Disable anonymous requests to the API server.",
@@ -454,7 +476,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not use token based authentication.",
@@ -476,7 +499,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "This admission controller rejects all net-new usage of the Service field externalIPs.",
@@ -498,7 +522,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Enable certificate based kubelet authentication.",
@@ -520,7 +545,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Verify kubelet's certificate before establishing connection.",
@@ -542,7 +568,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not always authorize all requests.",
@@ -564,7 +591,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Restrict kubelet nodes to reading only objects associated with them.",
@@ -586,7 +614,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Turn on Role Based Access Control.",
@@ -608,7 +637,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Limit the rate at which the API server accepts requests.",
@@ -630,7 +660,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not allow all requests.",
@@ -652,7 +683,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Always pull images.",
@@ -674,7 +706,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The SecurityContextDeny admission controller can be used to deny pods which make use of some SecurityContext fields which could allow for privilege escalation in the cluster. This should be used where PodSecurityPolicy is not in place within the cluster.",
@@ -696,7 +729,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Automate service accounts management.",
@@ -718,7 +752,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Reject creating objects in a namespace that is undergoing termination.",
@@ -740,7 +775,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Limit the `Node` and `Pod` objects that a kubelet could modify.",
@@ -762,7 +798,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Disable profiling, if not needed.",
@@ -784,7 +821,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Enable auditing on the Kubernetes API Server and set the desired audit log path.",
@@ -806,7 +844,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Retain the logs for at least 30 days or as appropriate.",
@@ -828,7 +867,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Retain 10 or an appropriate number of old log files.",
@@ -850,7 +890,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Rotate log files on reaching 100 MB or as appropriate.",
@@ -872,7 +913,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Set global request timeout for API server requests as appropriate.",
@@ -894,7 +936,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Validate service account before validating token.",
@@ -916,7 +959,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Explicitly set a service account public key file for service accounts on the apiserver.",
@@ -938,7 +982,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "etcd should be configured to make use of TLS encryption for client connections.",
@@ -960,7 +1005,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Setup TLS connection on the API server.",
@@ -982,7 +1028,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Setup TLS connection on the API server.",
@@ -1004,7 +1051,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "etcd should be configured to make use of TLS encryption for client connections.",
@@ -1026,7 +1074,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Encrypt etcd key-value store.",
@@ -1046,7 +1095,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Where `etcd` encryption is used, appropriate providers should be configured.",
@@ -1068,7 +1118,8 @@
],
"Attributes": [
{
- "Section": "1.2 API Server",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.2 API Server",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the API server is configured to only use strong cryptographic ciphers.",
@@ -1090,7 +1141,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Activate garbage collector on pod termination, as appropriate.",
@@ -1112,7 +1164,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Disable profiling, if not needed.",
@@ -1134,7 +1187,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Use individual service account credentials for each controller.",
@@ -1156,7 +1210,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Explicitly set a service account private key file for service accounts on the controller manager.",
@@ -1178,7 +1233,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Allow pods to verify the API server's serving certificate before establishing connections.",
@@ -1200,7 +1256,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Enable kubelet server certificate rotation on controller-manager.",
@@ -1222,7 +1279,8 @@
],
"Attributes": [
{
- "Section": "1.3 Controller Manager",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.3 Controller Manager",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not bind the Controller Manager service to non-loopback insecure addresses.",
@@ -1244,7 +1302,8 @@
],
"Attributes": [
{
- "Section": "1.4 Scheduler",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.4 Scheduler",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Disable profiling, if not needed.",
@@ -1266,7 +1325,8 @@
],
"Attributes": [
{
- "Section": "1.4 Scheduler",
+ "Section": "1. Control Plane Components",
+ "SubSection": "1.4 Scheduler",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not bind the scheduler service to non-loopback insecure addresses.",
@@ -1440,7 +1500,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1 Authentication and Authorization",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.1 Authentication and Authorization",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides the option to use client certificates for user authentication. However as there is no way to revoke these certificates when a user leaves an organization or loses their credential, they are not suitable for this purpose. It is not possible to fully disable client certificate use within a cluster as it is used for component to component authentication.",
@@ -1460,7 +1521,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1 Authentication and Authorization",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.1 Authentication and Authorization",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides service account tokens which are intended for use by workloads running in the Kubernetes cluster, for authentication to the API server. These tokens are not designed for use by end-users and do not provide for features such as revocation or expiry, making them insecure. A newer version of the feature (Bound service account token volumes) does introduce expiry but still does not allow for specific revocation.",
@@ -1480,7 +1542,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.1 Authentication and Authorization",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.1 Authentication and Authorization",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides bootstrap tokens which are intended for use by new nodes joining the cluster These tokens are not designed for use by end-users they are specifically designed for the purpose of bootstrapping new nodes and not for general authentication",
@@ -1500,7 +1563,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.2 Logging",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.2 Logging",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes can audit the details of requests made to the API server. The `--audit-policy-file` flag must be set for this logging to be enabled.",
@@ -1520,7 +1584,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "3.2 Logging",
+ "Section": "3. Control Plane Configuration",
+ "SubSection": "3.2 Logging",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the audit policy created for the cluster covers key security concerns.",
@@ -1542,7 +1607,8 @@
],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet` service file has permissions of `600` or more restrictive.",
@@ -1564,7 +1630,8 @@
],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet` service file ownership is set to `root:root`.",
@@ -1584,7 +1651,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "If `kube-proxy` is running, and if it is using a file-based kubeconfig file, ensure that the proxy kubeconfig file has permissions of `600` or more restrictive.",
@@ -1604,7 +1672,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "If `kube-proxy` is running, ensure that the file ownership of its kubeconfig file is set to `root:root`.",
@@ -1626,7 +1695,8 @@
],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet.conf` file has permissions of `600` or more restrictive.",
@@ -1648,7 +1718,8 @@
],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that the `kubelet.conf` file ownership is set to `root:root`.",
@@ -1668,7 +1739,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the certificate authorities file has permissions of `600` or more restrictive.",
@@ -1688,7 +1760,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the certificate authorities file ownership is set to `root:root`.",
@@ -1710,7 +1783,8 @@
],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that if the kubelet refers to a configuration file with the `--config` argument, that file has permissions of 600 or more restrictive.",
@@ -1732,7 +1806,8 @@
],
"Attributes": [
{
- "Section": "4.1 Worker Node Configuration Files",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.1 Worker Node Configuration Files",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Ensure that if the kubelet refers to a configuration file with the `--config` argument, that file is owned by root:root.",
@@ -1754,7 +1829,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Disable anonymous requests to the Kubelet server.",
@@ -1776,7 +1852,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Do not allow all requests. Enable explicit authorization.",
@@ -1798,7 +1875,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Enable Kubelet authentication using certificates.",
@@ -1820,7 +1898,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Disable the read-only port.",
@@ -1842,7 +1921,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Do not disable timeouts on streaming connections.",
@@ -1864,7 +1944,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Allow Kubelet to manage iptables.",
@@ -1884,7 +1965,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Do not override node hostnames.",
@@ -1906,7 +1988,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 2 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Security relevant information should be captured. The eventRecordQPS on the Kubelet configuration can be used to limit the rate at which events are gathered and sets the maximum event creations per second. Setting this too low could result in relevant events not being logged, however the unlimited setting of `0` could result in a denial of service on the kubelet.",
@@ -1928,7 +2011,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Setup TLS connection on the Kubelets.",
@@ -1950,7 +2034,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Automated",
"Description": "Enable kubelet client certificate rotation.",
@@ -1970,7 +2055,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Enable kubelet server certificate rotation.",
@@ -1992,7 +2078,8 @@
],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Kubelet is configured to only use strong cryptographic ciphers.",
@@ -2012,7 +2099,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "4.2 Kubelet",
+ "Section": "4. Worker Nodes",
+ "SubSection": "4.2 Kubelet",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Ensure that the Kubelet sets limits on the number of PIDs that can be created by pods running on the node.",
@@ -2034,7 +2122,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The RBAC role `cluster-admin` provides wide-ranging powers over the environment and should be used only where and when needed.",
@@ -2056,7 +2145,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The Kubernetes API stores secrets, which may be service account tokens for the Kubernetes API or credentials used by workloads in the cluster. Access to these secrets should be restricted to the smallest possible group of users to reduce the risk of privilege escalation.",
@@ -2078,7 +2168,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Worker Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes Roles and ClusterRoles provide access to resources based on sets of objects and actions that can be taken on those objects. It is possible to set either of these to be the wildcard \"*\" which matches all items. Use of wildcards is not optimal from a security perspective as it may allow for inadvertent access to be granted when new resources are added to the Kubernetes API either as CRDs or in later versions of the product.",
@@ -2100,7 +2191,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The ability to create pods in a namespace can provide a number of opportunities for privilege escalation, such as assigning privileged service accounts to these pods or mounting hostPaths with access to sensitive data (unless Pod Security Policies are implemented to restrict this access) As such, access to create new pods should be restricted to the smallest possible group of users.",
@@ -2120,7 +2212,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The `default` service account should not be used to ensure that rights granted to applications can be more easily audited and reviewed.",
@@ -2140,7 +2233,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Service accounts tokens should not be mounted in pods except where the workload running in the pod explicitly needs to communicate with the API server",
@@ -2160,7 +2254,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The special group `system:masters` should not be used to grant permissions to any user or service account, except where strictly necessary (e.g. bootstrapping access prior to RBAC being fully available)",
@@ -2180,7 +2275,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Cluster roles and roles with the impersonate, bind or escalate permissions should not be granted unless strictly required. Each of these permissions allow a particular subject to escalate their privileges beyond those explicitly granted by cluster administrators",
@@ -2202,7 +2298,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "The ability to create persistent volumes in a cluster can provide an opportunity for privilege escalation, via the creation of `hostPath` volumes. As persistent volumes are not covered by Pod Security Admission, a user with access to create persistent volumes may be able to get access to sensitive files from the underlying host even where restrictive Pod Security Admission policies are in place.",
@@ -2224,7 +2321,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with access to the `Proxy` sub-resource of `Node` objects automatically have permissions to use the Kubelet API, which may allow for privilege escalation or bypass cluster security controls such as audit logs. The Kubelet provides an API which includes rights to execute commands in any container running on the node. Access to this API is covered by permissions to the main Kubernetes API via the `node` object. The proxy sub-resource specifically allows wide ranging access to the Kubelet API. Direct access to the Kubelet API bypasses controls like audit logging (there is no audit log of Kubelet API access) and admission control.",
@@ -2246,7 +2344,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with access to the update the `approval` sub-resource of `certificateaigningrequest` objects can approve new client certificates for the Kubernetes API effectively allowing them to create new high-privileged user accounts. This can allow for privilege escalation to full cluster administrator, depending on users configured in the cluster",
@@ -2268,7 +2367,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with rights to create/modify/delete `validatingwebhookconfigurations` or `mutatingwebhookconfigurations` can control webhooks that can read any object admitted to the cluster, and in the case of mutating webhooks, also mutate admitted objects. This could allow for privilege escalation or disruption of the operation of the cluster.",
@@ -2290,7 +2390,8 @@
],
"Attributes": [
{
- "Section": "5.1 RBAC and Service Accounts",
+ "Section": "5. Policies",
+ "SubSection": "5.1 RBAC and Service Accounts",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Users with rights to create new service account tokens at a cluster level, can create long-lived privileged credentials in the cluster. This could allow for privilege escalation and persistent access to the cluster, even if the users account has been revoked.",
@@ -2310,7 +2411,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Every Kubernetes cluster should have at least one policy control mechanism in place to enforce the other requirements in this section. This could be the in-built Pod Security Admission controller, or a third party policy control system.",
@@ -2332,7 +2434,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers to be run with the `securityContext.privileged` flag set to `true`.",
@@ -2354,7 +2457,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers to be run with the `hostPID` flag set to true.",
@@ -2376,7 +2480,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers to be run with the `hostIPC` flag set to true.",
@@ -2398,7 +2503,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers to be run with the `hostNetwork` flag set to true.",
@@ -2420,7 +2526,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers to be run with the `allowPrivilegeEscalation` flag set to true. Allowing this right can lead to a process running a container getting more rights than it started with. It's important to note that these rights are still constrained by the overall container sandbox, and this setting does not relate to the use of privileged containers.",
@@ -2442,7 +2549,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers to be run as the root user.",
@@ -2464,7 +2572,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers with the potentially dangerous NET_RAW capability.",
@@ -2486,7 +2595,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Automated",
"Description": "Do not generally permit containers with capabilities assigned beyond the default set.",
@@ -2508,7 +2618,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers with capabilities",
@@ -2530,7 +2641,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit Windows containers to be run with the `hostProcess` flag set to true.",
@@ -2550,7 +2662,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally admit containers which make use of `hostPath` volumes.",
@@ -2572,7 +2685,8 @@
],
"Attributes": [
{
- "Section": "5.2 Pod Security Standards",
+ "Section": "5. Policies",
+ "SubSection": "5.2 Pod Security Standards",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Do not generally permit containers which require the use of HostPorts.",
@@ -2592,7 +2706,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3 Network Policies and CNI",
+ "Section": "5. Policies",
+ "SubSection": "5.3 Network Policies and CNI",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "There are a variety of CNI plugins available for Kubernetes. If the CNI in use does not support Network Policies it may not be possible to effectively restrict traffic in the cluster.",
@@ -2612,7 +2727,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.3 Network Policies and CNI",
+ "Section": "5. Policies",
+ "SubSection": "5.3 Network Policies and CNI",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Use network policies to isolate traffic in your cluster network.",
@@ -2634,7 +2750,8 @@
],
"Attributes": [
{
- "Section": "5.4 Secrets Management",
+ "Section": "5. Policies",
+ "SubSection": "5.4 Secrets Management",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes supports mounting secrets as data volumes or as environment variables. Minimize the use of environment variable secrets.",
@@ -2654,7 +2771,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.4 Secrets Management",
+ "Section": "5. Policies",
+ "SubSection": "5.4 Secrets Management",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Consider the use of an external secrets storage and management system, instead of using Kubernetes Secrets directly, if you have more complex secret management needs. Ensure the solution requires authentication to access secrets, has auditing of access to and use of secrets, and encrypts secrets. Some solutions also make it easier to rotate secrets.",
@@ -2674,7 +2792,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.4 Secrets Management",
+ "Section": "5. Policies",
+ "SubSection": "5.4 Secrets Management",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Configure Image Provenance for your deployment.",
@@ -2694,7 +2813,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.7 General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7 General Policies",
"Profile": "Level 1 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Use namespaces to isolate your Kubernetes objects.",
@@ -2716,7 +2836,8 @@
],
"Attributes": [
{
- "Section": "5.7 General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7 General Policies",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Enable `docker/default` seccomp profile in your pod definitions.",
@@ -2736,7 +2857,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.7 General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7 General Policies",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Apply Security Context to Your Pods and Containers",
@@ -2756,7 +2878,8 @@
"Checks": [],
"Attributes": [
{
- "Section": "5.7 General Policies",
+ "Section": "5. Policies",
+ "SubSection": "5.7 General Policies",
"Profile": "Level 2 - Master Node",
"AssessmentStatus": "Manual",
"Description": "Kubernetes provides a default namespace, where objects are placed if no namespace is specified for them. Placing objects in this namespace makes application of RBAC and other controls more difficult.",
diff --git a/prowler/lib/check/compliance_models.py b/prowler/lib/check/compliance_models.py
index 45a9b6fc76..fff0d6c38e 100644
--- a/prowler/lib/check/compliance_models.py
+++ b/prowler/lib/check/compliance_models.py
@@ -83,6 +83,7 @@ class CIS_Requirement_Attribute(BaseModel):
"""CIS Requirement Attribute"""
Section: str
+ SubSection: Optional[str]
Profile: CIS_Requirement_Attribute_Profile
AssessmentStatus: CIS_Requirement_Attribute_AssessmentStatus
Description: str
diff --git a/prowler/lib/outputs/compliance/cis/cis_aws.py b/prowler/lib/outputs/compliance/cis/cis_aws.py
index 665d92643e..070152d20f 100644
--- a/prowler/lib/outputs/compliance/cis/cis_aws.py
+++ b/prowler/lib/outputs/compliance/cis/cis_aws.py
@@ -48,6 +48,7 @@ class AWSCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
@@ -78,6 +79,7 @@ class AWSCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
diff --git a/prowler/lib/outputs/compliance/cis/cis_azure.py b/prowler/lib/outputs/compliance/cis/cis_azure.py
index 9ebe7fddaf..942f4a6a6f 100644
--- a/prowler/lib/outputs/compliance/cis/cis_azure.py
+++ b/prowler/lib/outputs/compliance/cis/cis_azure.py
@@ -48,6 +48,7 @@ class AzureCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
@@ -79,6 +80,7 @@ class AzureCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
diff --git a/prowler/lib/outputs/compliance/cis/cis_gcp.py b/prowler/lib/outputs/compliance/cis/cis_gcp.py
index 3e59f1cfae..573ead30cd 100644
--- a/prowler/lib/outputs/compliance/cis/cis_gcp.py
+++ b/prowler/lib/outputs/compliance/cis/cis_gcp.py
@@ -48,6 +48,7 @@ class GCPCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
@@ -78,6 +79,7 @@ class GCPCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
diff --git a/prowler/lib/outputs/compliance/cis/cis_kubernetes.py b/prowler/lib/outputs/compliance/cis/cis_kubernetes.py
index 97874bedf9..2850a0f475 100644
--- a/prowler/lib/outputs/compliance/cis/cis_kubernetes.py
+++ b/prowler/lib/outputs/compliance/cis/cis_kubernetes.py
@@ -50,6 +50,7 @@ class KubernetesCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
@@ -81,6 +82,7 @@ class KubernetesCIS(ComplianceOutput):
Requirements_Id=requirement.Id,
Requirements_Description=requirement.Description,
Requirements_Attributes_Section=attribute.Section,
+ Requirements_Attributes_SubSection=attribute.SubSection,
Requirements_Attributes_Profile=attribute.Profile,
Requirements_Attributes_AssessmentStatus=attribute.AssessmentStatus,
Requirements_Attributes_Description=attribute.Description,
diff --git a/prowler/lib/outputs/compliance/cis/models.py b/prowler/lib/outputs/compliance/cis/models.py
index d8e1889d52..2227885603 100644
--- a/prowler/lib/outputs/compliance/cis/models.py
+++ b/prowler/lib/outputs/compliance/cis/models.py
@@ -1,3 +1,5 @@
+from typing import Optional
+
from pydantic import BaseModel
@@ -14,6 +16,7 @@ class AWSCISModel(BaseModel):
Requirements_Id: str
Requirements_Description: str
Requirements_Attributes_Section: str
+ Requirements_Attributes_SubSection: Optional[str]
Requirements_Attributes_Profile: str
Requirements_Attributes_AssessmentStatus: str
Requirements_Attributes_Description: str
@@ -44,6 +47,7 @@ class AzureCISModel(BaseModel):
Requirements_Id: str
Requirements_Description: str
Requirements_Attributes_Section: str
+ Requirements_Attributes_SubSection: Optional[str]
Requirements_Attributes_Profile: str
Requirements_Attributes_AssessmentStatus: str
Requirements_Attributes_Description: str
@@ -75,6 +79,7 @@ class GCPCISModel(BaseModel):
Requirements_Id: str
Requirements_Description: str
Requirements_Attributes_Section: str
+ Requirements_Attributes_SubSection: Optional[str]
Requirements_Attributes_Profile: str
Requirements_Attributes_AssessmentStatus: str
Requirements_Attributes_Description: str
@@ -105,6 +110,7 @@ class KubernetesCISModel(BaseModel):
Requirements_Id: str
Requirements_Description: str
Requirements_Attributes_Section: str
+ Requirements_Attributes_SubSection: Optional[str]
Requirements_Attributes_Profile: str
Requirements_Attributes_AssessmentStatus: str
Requirements_Attributes_Description: str
diff --git a/tests/lib/outputs/compliance/cis/cis_aws_test.py b/tests/lib/outputs/compliance/cis/cis_aws_test.py
index b5ffa093b6..e7fc73d4e9 100644
--- a/tests/lib/outputs/compliance/cis/cis_aws_test.py
+++ b/tests/lib/outputs/compliance/cis/cis_aws_test.py
@@ -31,6 +31,10 @@ class TestAWSCIS:
output_data.Requirements_Attributes_Section
== CIS_1_4_AWS.Requirements[0].Attributes[0].Section
)
+ assert (
+ output_data.Requirements_Attributes_SubSection
+ == CIS_1_4_AWS.Requirements[0].Attributes[0].SubSection
+ )
assert (
output_data.Requirements_Attributes_Profile
== CIS_1_4_AWS.Requirements[0].Attributes[0].Profile
@@ -88,6 +92,10 @@ class TestAWSCIS:
output_data_manual.Requirements_Attributes_Section
== CIS_1_4_AWS.Requirements[1].Attributes[0].Section
)
+ assert (
+ output_data_manual.Requirements_Attributes_SubSection
+ == CIS_1_4_AWS.Requirements[1].Attributes[0].SubSection
+ )
assert (
output_data_manual.Requirements_Attributes_Profile
== CIS_1_4_AWS.Requirements[1].Attributes[0].Profile
@@ -143,5 +151,5 @@ class TestAWSCIS:
mock_file.seek(0)
content = mock_file.read()
- expected_csv = f'PROVIDER;DESCRIPTION;ACCOUNTID;REGION;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\naws;The CIS Benchmark for CIS Amazon Web Services Foundations Benchmark, v1.4.0, Level 1 and 2 provides prescriptive guidance for configuring security options for a subset of Amazon Web Services. It has an emphasis on foundational, testable, and architecture agnostic settings;123456789012;eu-west-1;{datetime.now()};2.1.3;Ensure MFA Delete is enabled on S3 buckets;2.1. Simple Storage Service (S3);Level 1;Automated;Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.;Adding MFA delete to an S3 bucket, requires additional authentication when you change the version state of your bucket or you delete and object version adding another layer of security in the event your security credentials are compromised or unauthorized access is granted.;;"Perform the steps below to enable MFA delete on an S3 bucket.\n\nNote:\n-You cannot enable MFA Delete using the AWS Management Console. You must use the AWS CLI or API.\n-You must use your \'root\' account to enable MFA Delete on S3 buckets.\n\n**From Command line:**\n\n1. Run the s3api put-bucket-versioning command\n\n```\naws s3api put-bucket-versioning --profile my-root-profile --bucket Bucket_Name --versioning-configuration Status=Enabled,MFADelete=Enabled --mfa “arn:aws:iam::aws_account_id:mfa/root-account-mfa-device passcode”\n```";"Perform the steps below to confirm MFA delete is configured on an S3 Bucket\n\n**From Console:**\n\n1. Login to the S3 console at `https://console.aws.amazon.com/s3/`\n\n2. Click the `Check` box next to the Bucket name you want to confirm\n\n3. In the window under `Properties`\n\n4. Confirm that Versioning is `Enabled`\n\n5. Confirm that MFA Delete is `Enabled`\n\n**From Command Line:**\n\n1. Run the `get-bucket-versioning`\n```\naws s3api get-bucket-versioning --bucket my-bucket\n```\n\nOutput example:\n```\n \n Enabled\n Enabled \n\n```\n\nIf the Console or the CLI output does not show Versioning and MFA Delete `enabled` refer to the remediation below.";;https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete:https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingMFADelete.html:https://aws.amazon.com/blogs/security/securing-access-to-aws-using-mfa-part-3/:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html;PASS;;;;test-check-id;False\r\naws;The CIS Benchmark for CIS Amazon Web Services Foundations Benchmark, v1.4.0, Level 1 and 2 provides prescriptive guidance for configuring security options for a subset of Amazon Web Services. It has an emphasis on foundational, testable, and architecture agnostic settings;;;{datetime.now()};2.1.4;Ensure MFA Delete is enabled on S3 buckets;2.1. Simple Storage Service (S3);Level 1;Automated;Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.;Adding MFA delete to an S3 bucket, requires additional authentication when you change the version state of your bucket or you delete and object version adding another layer of security in the event your security credentials are compromised or unauthorized access is granted.;;"Perform the steps below to enable MFA delete on an S3 bucket.\n\nNote:\n-You cannot enable MFA Delete using the AWS Management Console. You must use the AWS CLI or API.\n-You must use your \'root\' account to enable MFA Delete on S3 buckets.\n\n**From Command line:**\n\n1. Run the s3api put-bucket-versioning command\n\n```\naws s3api put-bucket-versioning --profile my-root-profile --bucket Bucket_Name --versioning-configuration Status=Enabled,MFADelete=Enabled --mfa “arn:aws:iam::aws_account_id:mfa/root-account-mfa-device passcode”\n```";"Perform the steps below to confirm MFA delete is configured on an S3 Bucket\n\n**From Console:**\n\n1. Login to the S3 console at `https://console.aws.amazon.com/s3/`\n\n2. Click the `Check` box next to the Bucket name you want to confirm\n\n3. In the window under `Properties`\n\n4. Confirm that Versioning is `Enabled`\n\n5. Confirm that MFA Delete is `Enabled`\n\n**From Command Line:**\n\n1. Run the `get-bucket-versioning`\n```\naws s3api get-bucket-versioning --bucket my-bucket\n```\n\nOutput example:\n```\n \n Enabled\n Enabled \n\n```\n\nIf the Console or the CLI output does not show Versioning and MFA Delete `enabled` refer to the remediation below.";;https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete:https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingMFADelete.html:https://aws.amazon.com/blogs/security/securing-access-to-aws-using-mfa-part-3/:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html;MANUAL;Manual check;manual_check;Manual check;manual;False\r\n'
+ expected_csv = f'PROVIDER;DESCRIPTION;ACCOUNTID;REGION;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_SUBSECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\naws;The CIS Benchmark for CIS Amazon Web Services Foundations Benchmark, v1.4.0, Level 1 and 2 provides prescriptive guidance for configuring security options for a subset of Amazon Web Services. It has an emphasis on foundational, testable, and architecture agnostic settings;123456789012;eu-west-1;{datetime.now()};2.1.3;Ensure MFA Delete is enabled on S3 buckets;2. Storage;2.1. Simple Storage Service (S3);Level 1;Automated;Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.;Adding MFA delete to an S3 bucket, requires additional authentication when you change the version state of your bucket or you delete and object version adding another layer of security in the event your security credentials are compromised or unauthorized access is granted.;;"Perform the steps below to enable MFA delete on an S3 bucket.\n\nNote:\n-You cannot enable MFA Delete using the AWS Management Console. You must use the AWS CLI or API.\n-You must use your \'root\' account to enable MFA Delete on S3 buckets.\n\n**From Command line:**\n\n1. Run the s3api put-bucket-versioning command\n\n```\naws s3api put-bucket-versioning --profile my-root-profile --bucket Bucket_Name --versioning-configuration Status=Enabled,MFADelete=Enabled --mfa “arn:aws:iam::aws_account_id:mfa/root-account-mfa-device passcode”\n```";"Perform the steps below to confirm MFA delete is configured on an S3 Bucket\n\n**From Console:**\n\n1. Login to the S3 console at `https://console.aws.amazon.com/s3/`\n\n2. Click the `Check` box next to the Bucket name you want to confirm\n\n3. In the window under `Properties`\n\n4. Confirm that Versioning is `Enabled`\n\n5. Confirm that MFA Delete is `Enabled`\n\n**From Command Line:**\n\n1. Run the `get-bucket-versioning`\n```\naws s3api get-bucket-versioning --bucket my-bucket\n```\n\nOutput example:\n```\n \n Enabled\n Enabled \n\n```\n\nIf the Console or the CLI output does not show Versioning and MFA Delete `enabled` refer to the remediation below.";;https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete:https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingMFADelete.html:https://aws.amazon.com/blogs/security/securing-access-to-aws-using-mfa-part-3/:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html;PASS;;;;test-check-id;False\r\naws;The CIS Benchmark for CIS Amazon Web Services Foundations Benchmark, v1.4.0, Level 1 and 2 provides prescriptive guidance for configuring security options for a subset of Amazon Web Services. It has an emphasis on foundational, testable, and architecture agnostic settings;;;{datetime.now()};2.1.4;Ensure MFA Delete is enabled on S3 buckets;2. Storage;2.1. Simple Storage Service (S3);Level 1;Automated;Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.;Adding MFA delete to an S3 bucket, requires additional authentication when you change the version state of your bucket or you delete and object version adding another layer of security in the event your security credentials are compromised or unauthorized access is granted.;;"Perform the steps below to enable MFA delete on an S3 bucket.\n\nNote:\n-You cannot enable MFA Delete using the AWS Management Console. You must use the AWS CLI or API.\n-You must use your \'root\' account to enable MFA Delete on S3 buckets.\n\n**From Command line:**\n\n1. Run the s3api put-bucket-versioning command\n\n```\naws s3api put-bucket-versioning --profile my-root-profile --bucket Bucket_Name --versioning-configuration Status=Enabled,MFADelete=Enabled --mfa “arn:aws:iam::aws_account_id:mfa/root-account-mfa-device passcode”\n```";"Perform the steps below to confirm MFA delete is configured on an S3 Bucket\n\n**From Console:**\n\n1. Login to the S3 console at `https://console.aws.amazon.com/s3/`\n\n2. Click the `Check` box next to the Bucket name you want to confirm\n\n3. In the window under `Properties`\n\n4. Confirm that Versioning is `Enabled`\n\n5. Confirm that MFA Delete is `Enabled`\n\n**From Command Line:**\n\n1. Run the `get-bucket-versioning`\n```\naws s3api get-bucket-versioning --bucket my-bucket\n```\n\nOutput example:\n```\n \n Enabled\n Enabled \n\n```\n\nIf the Console or the CLI output does not show Versioning and MFA Delete `enabled` refer to the remediation below.";;https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete:https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingMFADelete.html:https://aws.amazon.com/blogs/security/securing-access-to-aws-using-mfa-part-3/:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_lost-or-broken.html;MANUAL;Manual check;manual_check;Manual check;manual;False\r\n'
assert content == expected_csv
diff --git a/tests/lib/outputs/compliance/cis/cis_azure_test.py b/tests/lib/outputs/compliance/cis/cis_azure_test.py
index ce5ce6651b..f2b3719aa5 100644
--- a/tests/lib/outputs/compliance/cis/cis_azure_test.py
+++ b/tests/lib/outputs/compliance/cis/cis_azure_test.py
@@ -42,6 +42,10 @@ class TestAzureCIS:
output_data.Requirements_Attributes_Section
== CIS_2_0_AZURE.Requirements[0].Attributes[0].Section
)
+ assert (
+ output_data.Requirements_Attributes_SubSection
+ == CIS_2_0_AZURE.Requirements[0].Attributes[0].SubSection
+ )
assert (
output_data.Requirements_Attributes_Profile
== CIS_2_0_AZURE.Requirements[0].Attributes[0].Profile
@@ -103,6 +107,10 @@ class TestAzureCIS:
output_data_manual.Requirements_Attributes_Section
== CIS_2_0_AZURE.Requirements[1].Attributes[0].Section
)
+ assert (
+ output_data.Requirements_Attributes_SubSection
+ == CIS_2_0_AZURE.Requirements[0].Attributes[0].SubSection
+ )
assert (
output_data_manual.Requirements_Attributes_Profile
== CIS_2_0_AZURE.Requirements[1].Attributes[0].Profile
@@ -171,5 +179,5 @@ class TestAzureCIS:
mock_file.seek(0)
content = mock_file.read()
- expected_csv = f"PROVIDER;DESCRIPTION;SUBSCRIPTIONID;LOCATION;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_DEFAULTVALUE;REQUIREMENTS_ATTRIBUTES_REFERENCES;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\nazure;The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.;{AZURE_SUBSCRIPTION_ID};;{datetime.now()};2.1.3;Ensure That Microsoft Defender for Databases Is Set To 'On';2.1 Microsoft Defender for Cloud;Level 2;Manual;Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.;Enabling Microsoft Defender for Azure SQL Databases allows your organization more granular control of the infrastructure running your database software. Instead of waiting on Microsoft release updates or other similar processes, you can manage them yourself. Threat detection is provided by the Microsoft Security Response Center (MSRC).;Running Defender on Infrastructure as a service (IaaS) may incur increased costs associated with running the service and the instance it is on. Similarly, you will need qualified personnel to maintain the operating system and software updates. If it is not maintained, security patches will not be applied and it may be open to vulnerabilities.;From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Set Databases Status to On 6. Select Save Review the chosen pricing tier. For the Azure Databases resource review the different plan information and choose one that fits the needs of your organization. From Azure CLI Run the following commands: az security pricing create -n 'SqlServers' --tier 'Standard' az security pricing create -n 'SqlServerVirtualMachines' --tier 'Standard' az security pricing create -n 'OpenSourceRelationalDatabases' --tier 'Standard' az security pricing create -n 'CosmosDbs' --tier 'Standard' From Azure PowerShell Run the following commands: Set-AzSecurityPricing -Name 'SqlServers' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'SqlServerVirtualMachines' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'OpenSourceRelationalDatabases' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard';From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Ensure Databases Status is set to On 6. Review the chosen pricing tier From Azure CLI Ensure the output of the below commands is Standard az security pricing show -n 'SqlServers' az security pricing show -n 'SqlServerVirtualMachines' az security pricing show -n 'OpenSourceRelationalDatabases' az security pricing show -n 'CosmosDbs' If the output of any of the above commands shows pricingTier with a value of Free, the setting is out of compliance. From PowerShell Connect-AzAccount Get-AzSecurityPricing |select-object Name,PricingTier |where-object {{$_.Name -match 'Sql' -or $_.Name -match 'Cosmos' -or $_.Name -match 'OpenSource'}} Ensure the output shows Standard for each database type under the PricingTier column. Any that show Free are considered out of compliance.;;By default, Microsoft Defender plan is off.;https://docs.microsoft.com/en-us/azure/azure-sql/database/azure-defender-for-sql?view=azuresql:https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-enable-database-protections:https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-databases-usage:https://docs.microsoft.com/en-us/azure/security-center/security-center-detection-capabilities:https://docs.microsoft.com/en-us/rest/api/securitycenter/pricings/list:https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-logging-threat-detection#lt-1-enable-threat-detection-capabilities;PASS;;;;test-check-id;False\r\nazure;The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.;;;{datetime.now()};2.1.4;Ensure That Microsoft Defender for Databases Is Set To 'On';2.1 Microsoft Defender for Cloud;Level 2;Manual;Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.;Enabling Microsoft Defender for Azure SQL Databases allows your organization more granular control of the infrastructure running your database software. Instead of waiting on Microsoft release updates or other similar processes, you can manage them yourself. Threat detection is provided by the Microsoft Security Response Center (MSRC).;Running Defender on Infrastructure as a service (IaaS) may incur increased costs associated with running the service and the instance it is on. Similarly, you will need qualified personnel to maintain the operating system and software updates. If it is not maintained, security patches will not be applied and it may be open to vulnerabilities.;From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Set Databases Status to On 6. Select Save Review the chosen pricing tier. For the Azure Databases resource review the different plan information and choose one that fits the needs of your organization. From Azure CLI Run the following commands: az security pricing create -n 'SqlServers' --tier 'Standard' az security pricing create -n 'SqlServerVirtualMachines' --tier 'Standard' az security pricing create -n 'OpenSourceRelationalDatabases' --tier 'Standard' az security pricing create -n 'CosmosDbs' --tier 'Standard' From Azure PowerShell Run the following commands: Set-AzSecurityPricing -Name 'SqlServers' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'SqlServerVirtualMachines' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'OpenSourceRelationalDatabases' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard';From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Ensure Databases Status is set to On 6. Review the chosen pricing tier From Azure CLI Ensure the output of the below commands is Standard az security pricing show -n 'SqlServers' az security pricing show -n 'SqlServerVirtualMachines' az security pricing show -n 'OpenSourceRelationalDatabases' az security pricing show -n 'CosmosDbs' If the output of any of the above commands shows pricingTier with a value of Free, the setting is out of compliance. From PowerShell Connect-AzAccount Get-AzSecurityPricing |select-object Name,PricingTier |where-object {{$_.Name -match 'Sql' -or $_.Name -match 'Cosmos' -or $_.Name -match 'OpenSource'}} Ensure the output shows Standard for each database type under the PricingTier column. Any that show Free are considered out of compliance.;;By default, Microsoft Defender plan is off.;https://docs.microsoft.com/en-us/azure/azure-sql/database/azure-defender-for-sql?view=azuresql:https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-enable-database-protections:https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-databases-usage:https://docs.microsoft.com/en-us/azure/security-center/security-center-detection-capabilities:https://docs.microsoft.com/en-us/rest/api/securitycenter/pricings/list:https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-logging-threat-detection#lt-1-enable-threat-detection-capabilities;MANUAL;Manual check;manual_check;Manual check;manual;False\r\n"
+ expected_csv = f"PROVIDER;DESCRIPTION;SUBSCRIPTIONID;LOCATION;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_SUBSECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_DEFAULTVALUE;REQUIREMENTS_ATTRIBUTES_REFERENCES;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\nazure;The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.;{AZURE_SUBSCRIPTION_ID};;{datetime.now()};2.1.3;Ensure That Microsoft Defender for Databases Is Set To 'On';2. Defender;2.1 Microsoft Defender for Cloud;Level 2;Manual;Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.;Enabling Microsoft Defender for Azure SQL Databases allows your organization more granular control of the infrastructure running your database software. Instead of waiting on Microsoft release updates or other similar processes, you can manage them yourself. Threat detection is provided by the Microsoft Security Response Center (MSRC).;Running Defender on Infrastructure as a service (IaaS) may incur increased costs associated with running the service and the instance it is on. Similarly, you will need qualified personnel to maintain the operating system and software updates. If it is not maintained, security patches will not be applied and it may be open to vulnerabilities.;From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Set Databases Status to On 6. Select Save Review the chosen pricing tier. For the Azure Databases resource review the different plan information and choose one that fits the needs of your organization. From Azure CLI Run the following commands: az security pricing create -n 'SqlServers' --tier 'Standard' az security pricing create -n 'SqlServerVirtualMachines' --tier 'Standard' az security pricing create -n 'OpenSourceRelationalDatabases' --tier 'Standard' az security pricing create -n 'CosmosDbs' --tier 'Standard' From Azure PowerShell Run the following commands: Set-AzSecurityPricing -Name 'SqlServers' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'SqlServerVirtualMachines' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'OpenSourceRelationalDatabases' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard';From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Ensure Databases Status is set to On 6. Review the chosen pricing tier From Azure CLI Ensure the output of the below commands is Standard az security pricing show -n 'SqlServers' az security pricing show -n 'SqlServerVirtualMachines' az security pricing show -n 'OpenSourceRelationalDatabases' az security pricing show -n 'CosmosDbs' If the output of any of the above commands shows pricingTier with a value of Free, the setting is out of compliance. From PowerShell Connect-AzAccount Get-AzSecurityPricing |select-object Name,PricingTier |where-object {{$_.Name -match 'Sql' -or $_.Name -match 'Cosmos' -or $_.Name -match 'OpenSource'}} Ensure the output shows Standard for each database type under the PricingTier column. Any that show Free are considered out of compliance.;;By default, Microsoft Defender plan is off.;https://docs.microsoft.com/en-us/azure/azure-sql/database/azure-defender-for-sql?view=azuresql:https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-enable-database-protections:https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-databases-usage:https://docs.microsoft.com/en-us/azure/security-center/security-center-detection-capabilities:https://docs.microsoft.com/en-us/rest/api/securitycenter/pricings/list:https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-logging-threat-detection#lt-1-enable-threat-detection-capabilities;PASS;;;;test-check-id;False\r\nazure;The CIS Azure Foundations Benchmark provides prescriptive guidance for configuring security options for a subset of Azure with an emphasis on foundational, testable, and architecture agnostic settings.;;;{datetime.now()};2.1.4;Ensure That Microsoft Defender for Databases Is Set To 'On';2. Defender;2.1 Microsoft Defender for Cloud;Level 2;Manual;Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.;Enabling Microsoft Defender for Azure SQL Databases allows your organization more granular control of the infrastructure running your database software. Instead of waiting on Microsoft release updates or other similar processes, you can manage them yourself. Threat detection is provided by the Microsoft Security Response Center (MSRC).;Running Defender on Infrastructure as a service (IaaS) may incur increased costs associated with running the service and the instance it is on. Similarly, you will need qualified personnel to maintain the operating system and software updates. If it is not maintained, security patches will not be applied and it may be open to vulnerabilities.;From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Set Databases Status to On 6. Select Save Review the chosen pricing tier. For the Azure Databases resource review the different plan information and choose one that fits the needs of your organization. From Azure CLI Run the following commands: az security pricing create -n 'SqlServers' --tier 'Standard' az security pricing create -n 'SqlServerVirtualMachines' --tier 'Standard' az security pricing create -n 'OpenSourceRelationalDatabases' --tier 'Standard' az security pricing create -n 'CosmosDbs' --tier 'Standard' From Azure PowerShell Run the following commands: Set-AzSecurityPricing -Name 'SqlServers' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'SqlServerVirtualMachines' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'OpenSourceRelationalDatabases' -PricingTier 'Standard' Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard';From Azure Portal 1. Go to Microsoft Defender for Cloud 2. Select Environment Settings 3. Click on the subscription name 4. Select Defender plans 5. Ensure Databases Status is set to On 6. Review the chosen pricing tier From Azure CLI Ensure the output of the below commands is Standard az security pricing show -n 'SqlServers' az security pricing show -n 'SqlServerVirtualMachines' az security pricing show -n 'OpenSourceRelationalDatabases' az security pricing show -n 'CosmosDbs' If the output of any of the above commands shows pricingTier with a value of Free, the setting is out of compliance. From PowerShell Connect-AzAccount Get-AzSecurityPricing |select-object Name,PricingTier |where-object {{$_.Name -match 'Sql' -or $_.Name -match 'Cosmos' -or $_.Name -match 'OpenSource'}} Ensure the output shows Standard for each database type under the PricingTier column. Any that show Free are considered out of compliance.;;By default, Microsoft Defender plan is off.;https://docs.microsoft.com/en-us/azure/azure-sql/database/azure-defender-for-sql?view=azuresql:https://docs.microsoft.com/en-us/azure/defender-for-cloud/quickstart-enable-database-protections:https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-databases-usage:https://docs.microsoft.com/en-us/azure/security-center/security-center-detection-capabilities:https://docs.microsoft.com/en-us/rest/api/securitycenter/pricings/list:https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-logging-threat-detection#lt-1-enable-threat-detection-capabilities;MANUAL;Manual check;manual_check;Manual check;manual;False\r\n"
assert content == expected_csv
diff --git a/tests/lib/outputs/compliance/cis/cis_gcp_test.py b/tests/lib/outputs/compliance/cis/cis_gcp_test.py
index 383efeb1c4..e6473d9495 100644
--- a/tests/lib/outputs/compliance/cis/cis_gcp_test.py
+++ b/tests/lib/outputs/compliance/cis/cis_gcp_test.py
@@ -39,6 +39,10 @@ class TestGCPCIS:
output_data.Requirements_Attributes_Section
== CIS_2_0_GCP.Requirements[0].Attributes[0].Section
)
+ assert (
+ output_data.Requirements_Attributes_SubSection
+ == CIS_2_0_GCP.Requirements[0].Attributes[0].SubSection
+ )
assert (
output_data.Requirements_Attributes_Profile
== CIS_2_0_GCP.Requirements[0].Attributes[0].Profile
@@ -96,6 +100,13 @@ class TestGCPCIS:
output_data_manual.Requirements_Attributes_Section
== CIS_2_0_GCP.Requirements[1].Attributes[0].Section
)
+ assert (
+ output_data_manual.Requirements_Attributes_SubSection
+ == CIS_2_0_GCP.Requirements[1].Attributes[0].SubSection
+ )
+ assert (
+ not output_data_manual.Requirements_Attributes_SubSection
+ ) # SubSection is empty
assert (
output_data_manual.Requirements_Attributes_Profile
== CIS_2_0_GCP.Requirements[1].Attributes[0].Profile
@@ -160,5 +171,5 @@ class TestGCPCIS:
mock_file.seek(0)
content = mock_file.read()
- expected_csv = f"PROVIDER;DESCRIPTION;PROJECTID;LOCATION;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\ngcp;This CIS Benchmark is the product of a community consensus process and consists of secure configuration guidelines developed for Google Cloud Computing Platform;123456789012;;{datetime.now()};2.13;Ensure That Microsoft Defender for Databases Is Set To 'On';2. Logging and Monitoring;Level 1;Automated;GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.;The GCP resources and IAM policies captured by GCP Cloud Asset Inventory enables security analysis, resource change tracking, and compliance auditing. It is recommended GCP Cloud Asset Inventory be enabled for all GCP projects.;;**From Google Cloud Console** Enable the Cloud Asset API: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Click the `ENABLE` button. **From Google Cloud CLI** Enable the Cloud Asset API: 1. Enable the Cloud Asset API through the services interface: ``` gcloud services enable cloudasset.googleapis.com ```;**From Google Cloud Console** Ensure that the Cloud Asset API is enabled: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Ensure that `API Enabled` is displayed. **From Google Cloud CLI** Ensure that the Cloud Asset API is enabled: 1. Query enabled services: ``` gcloud services list --enabled --filter=name:cloudasset.googleapis.com ``` If the API is listed, then it is enabled. If the response is `Listed 0 items` the API is not enabled.;Additional info - Cloud Asset Inventory only keeps a five-week history of Google Cloud asset metadata. If a longer history is desired, automation to export the history to Cloud Storage or BigQuery should be evaluated.;https://cloud.google.com/asset-inventory/docs;PASS;;;;test-check-id;False\r\ngcp;This CIS Benchmark is the product of a community consensus process and consists of secure configuration guidelines developed for Google Cloud Computing Platform;;;{datetime.now()};2.14;Ensure That Microsoft Defender for Databases Is Set To 'On';2. Logging and Monitoring;Level 1;Automated;GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.;The GCP resources and IAM policies captured by GCP Cloud Asset Inventory enables security analysis, resource change tracking, and compliance auditing. It is recommended GCP Cloud Asset Inventory be enabled for all GCP projects.;;**From Google Cloud Console** Enable the Cloud Asset API: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Click the `ENABLE` button. **From Google Cloud CLI** Enable the Cloud Asset API: 1. Enable the Cloud Asset API through the services interface: ``` gcloud services enable cloudasset.googleapis.com ```;**From Google Cloud Console** Ensure that the Cloud Asset API is enabled: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Ensure that `API Enabled` is displayed. **From Google Cloud CLI** Ensure that the Cloud Asset API is enabled: 1. Query enabled services: ``` gcloud services list --enabled --filter=name:cloudasset.googleapis.com ``` If the API is listed, then it is enabled. If the response is `Listed 0 items` the API is not enabled.;Additional info - Cloud Asset Inventory only keeps a five-week history of Google Cloud asset metadata. If a longer history is desired, automation to export the history to Cloud Storage or BigQuery should be evaluated.;https://cloud.google.com/asset-inventory/docs;MANUAL;Manual check;manual_check;Manual check;manual;False"
+ expected_csv = f"PROVIDER;DESCRIPTION;PROJECTID;LOCATION;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_SUBSECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\ngcp;This CIS Benchmark is the product of a community consensus process and consists of secure configuration guidelines developed for Google Cloud Computing Platform;123456789012;;{datetime.now()};2.13;Ensure That Microsoft Defender for Databases Is Set To 'On';2. Logging;2.1. Logging and Monitoring;Level 1;Automated;GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.;The GCP resources and IAM policies captured by GCP Cloud Asset Inventory enables security analysis, resource change tracking, and compliance auditing. It is recommended GCP Cloud Asset Inventory be enabled for all GCP projects.;;**From Google Cloud Console** Enable the Cloud Asset API: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Click the `ENABLE` button. **From Google Cloud CLI** Enable the Cloud Asset API: 1. Enable the Cloud Asset API through the services interface: ``` gcloud services enable cloudasset.googleapis.com ```;**From Google Cloud Console** Ensure that the Cloud Asset API is enabled: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Ensure that `API Enabled` is displayed. **From Google Cloud CLI** Ensure that the Cloud Asset API is enabled: 1. Query enabled services: ``` gcloud services list --enabled --filter=name:cloudasset.googleapis.com ``` If the API is listed, then it is enabled. If the response is `Listed 0 items` the API is not enabled.;Additional info - Cloud Asset Inventory only keeps a five-week history of Google Cloud asset metadata. If a longer history is desired, automation to export the history to Cloud Storage or BigQuery should be evaluated.;https://cloud.google.com/asset-inventory/docs;PASS;;;;test-check-id;False\r\ngcp;This CIS Benchmark is the product of a community consensus process and consists of secure configuration guidelines developed for Google Cloud Computing Platform;;;{datetime.now()};2.14;Ensure That Microsoft Defender for Databases Is Set To 'On';2. Logging;;Level 1;Automated;GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.;The GCP resources and IAM policies captured by GCP Cloud Asset Inventory enables security analysis, resource change tracking, and compliance auditing. It is recommended GCP Cloud Asset Inventory be enabled for all GCP projects.;;**From Google Cloud Console** Enable the Cloud Asset API: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Click the `ENABLE` button. **From Google Cloud CLI** Enable the Cloud Asset API: 1. Enable the Cloud Asset API through the services interface: ``` gcloud services enable cloudasset.googleapis.com ```;**From Google Cloud Console** Ensure that the Cloud Asset API is enabled: 1. Go to `API & Services/Library` by visiting https://console.cloud.google.com/apis/library(https://console.cloud.google.com/apis/library) 2. Search for `Cloud Asset API` and select the result for _Cloud Asset API_ 3. Ensure that `API Enabled` is displayed. **From Google Cloud CLI** Ensure that the Cloud Asset API is enabled: 1. Query enabled services: ``` gcloud services list --enabled --filter=name:cloudasset.googleapis.com ``` If the API is listed, then it is enabled. If the response is `Listed 0 items` the API is not enabled.;Additional info - Cloud Asset Inventory only keeps a five-week history of Google Cloud asset metadata. If a longer history is desired, automation to export the history to Cloud Storage or BigQuery should be evaluated.;https://cloud.google.com/asset-inventory/docs;MANUAL;Manual check;manual_check;Manual check;manual;False"
assert expected_csv in content
diff --git a/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py b/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py
index 22993e64a4..b6e4a4d4f9 100644
--- a/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py
+++ b/tests/lib/outputs/compliance/cis/cis_kubernetes_test.py
@@ -42,6 +42,10 @@ class TestKubernetesCIS:
output_data.Requirements_Attributes_Section
== CIS_1_8_KUBERNETES.Requirements[0].Attributes[0].Section
)
+ assert (
+ output_data.Requirements_Attributes_SubSection
+ == CIS_1_8_KUBERNETES.Requirements[0].Attributes[0].SubSection
+ )
assert (
output_data.Requirements_Attributes_Profile
== CIS_1_8_KUBERNETES.Requirements[0].Attributes[0].Profile
@@ -105,6 +109,10 @@ class TestKubernetesCIS:
output_data_manual.Requirements_Attributes_Section
== CIS_1_8_KUBERNETES.Requirements[1].Attributes[0].Section
)
+ assert (
+ output_data.Requirements_Attributes_SubSection
+ == CIS_1_8_KUBERNETES.Requirements[0].Attributes[0].SubSection
+ )
assert (
output_data_manual.Requirements_Attributes_Profile
== CIS_1_8_KUBERNETES.Requirements[1].Attributes[0].Profile
@@ -173,5 +181,5 @@ class TestKubernetesCIS:
mock_file.seek(0)
content = mock_file.read()
- expected_csv = f"PROVIDER;DESCRIPTION;CONTEXT;NAMESPACE;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;REQUIREMENTS_ATTRIBUTES_DEFAULTVALUE;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;test-cluster;test-namespace;{datetime.now()};1.1.3;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1.1 Control Plane Node Configuration Files;Level 1 - Master Node;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;PASS;;;;test-check-id;False\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;;;{datetime.now()};1.1.4;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1.1 Control Plane Node Configuration Files;Level 1 - Master Node;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;MANUAL;Manual check;manual_check;Manual check;manual;False\r\n"
+ expected_csv = f"PROVIDER;DESCRIPTION;CONTEXT;NAMESPACE;ASSESSMENTDATE;REQUIREMENTS_ID;REQUIREMENTS_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_SECTION;REQUIREMENTS_ATTRIBUTES_SUBSECTION;REQUIREMENTS_ATTRIBUTES_PROFILE;REQUIREMENTS_ATTRIBUTES_ASSESSMENTSTATUS;REQUIREMENTS_ATTRIBUTES_DESCRIPTION;REQUIREMENTS_ATTRIBUTES_RATIONALESTATEMENT;REQUIREMENTS_ATTRIBUTES_IMPACTSTATEMENT;REQUIREMENTS_ATTRIBUTES_REMEDIATIONPROCEDURE;REQUIREMENTS_ATTRIBUTES_AUDITPROCEDURE;REQUIREMENTS_ATTRIBUTES_ADDITIONALINFORMATION;REQUIREMENTS_ATTRIBUTES_REFERENCES;REQUIREMENTS_ATTRIBUTES_DEFAULTVALUE;STATUS;STATUSEXTENDED;RESOURCEID;RESOURCENAME;CHECKID;MUTED\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;test-cluster;test-namespace;{datetime.now()};1.1.3;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1. Control Plane;1.1 Control Plane Node Configuration Files;Level 1 - Master Node;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;PASS;;;;test-check-id;False\r\nkubernetes;This CIS Kubernetes Benchmark provides prescriptive guidance for establishing a secure configuration posture for Kubernetes v1.27.;;;{datetime.now()};1.1.4;Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive;1.1 Control Plane Node Configuration Files;;Level 1 - Master Node;Automated;Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.;The controller manager pod specification file controls various parameters that set the behavior of the Controller Manager on the master node. You should restrict its file permissions to maintain the integrity of the file. The file should be writable by only the administrators on the system.;;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` chmod 600 /etc/kubernetes/manifests/kube-controller-manager.yaml ```;Run the below command (based on the file location on your system) on the Control Plane node. For example, ``` stat -c %a /etc/kubernetes/manifests/kube-controller-manager.yaml ``` Verify that the permissions are `600` or more restrictive.;;https://kubernetes.io/docs/admin/kube-apiserver/;By default, the `kube-controller-manager.yaml` file has permissions of `640`.;MANUAL;Manual check;manual_check;Manual check;manual;False\r\n"
assert content == expected_csv
diff --git a/tests/lib/outputs/compliance/fixtures.py b/tests/lib/outputs/compliance/fixtures.py
index 8b35860c33..f20cf6de85 100644
--- a/tests/lib/outputs/compliance/fixtures.py
+++ b/tests/lib/outputs/compliance/fixtures.py
@@ -28,7 +28,8 @@ CIS_1_4_AWS = Compliance(
Description="Ensure MFA Delete is enabled on S3 buckets",
Attributes=[
CIS_Requirement_Attribute(
- Section="2.1. Simple Storage Service (S3)",
+ Section="2. Storage",
+ SubSection="2.1. Simple Storage Service (S3)",
Profile="Level 1",
AssessmentStatus="Automated",
Description="Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.",
@@ -47,7 +48,8 @@ CIS_1_4_AWS = Compliance(
Description="Ensure MFA Delete is enabled on S3 buckets",
Attributes=[
CIS_Requirement_Attribute(
- Section="2.1. Simple Storage Service (S3)",
+ Section="2. Storage",
+ SubSection="2.1. Simple Storage Service (S3)",
Profile="Level 1",
AssessmentStatus="Automated",
Description="Once MFA Delete is enabled on your sensitive and classified S3 bucket it requires the user to have two forms of authentication.",
@@ -75,7 +77,8 @@ CIS_2_0_AZURE = Compliance(
Description="Ensure That Microsoft Defender for Databases Is Set To 'On'",
Attributes=[
CIS_Requirement_Attribute(
- Section="2.1 Microsoft Defender for Cloud",
+ Section="2. Defender",
+ SubSection="2.1 Microsoft Defender for Cloud",
Profile="Level 2",
AssessmentStatus="Manual",
Description="Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.",
@@ -95,7 +98,8 @@ CIS_2_0_AZURE = Compliance(
Description="Ensure That Microsoft Defender for Databases Is Set To 'On'",
Attributes=[
CIS_Requirement_Attribute(
- Section="2.1 Microsoft Defender for Cloud",
+ Section="2. Defender",
+ SubSection="2.1 Microsoft Defender for Cloud",
Profile="Level 2",
AssessmentStatus="Manual",
Description="Turning on Microsoft Defender for Databases enables threat detection for the instances running your database software. This provides threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Instead of being enabled on services like Platform as a Service (PaaS), this implementation will run within your instances as Infrastructure as a Service (IaaS) on the Operating Systems hosting your databases.",
@@ -124,7 +128,8 @@ CIS_2_0_GCP = Compliance(
Description="Ensure That Microsoft Defender for Databases Is Set To 'On'",
Attributes=[
CIS_Requirement_Attribute(
- Section="2. Logging and Monitoring",
+ Section="2. Logging",
+ SubSection="2.1. Logging and Monitoring",
Profile="Level 1",
AssessmentStatus="Automated",
Description="GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.",
@@ -143,7 +148,7 @@ CIS_2_0_GCP = Compliance(
Description="Ensure That Microsoft Defender for Databases Is Set To 'On'",
Attributes=[
CIS_Requirement_Attribute(
- Section="2. Logging and Monitoring",
+ Section="2. Logging",
Profile="Level 1",
AssessmentStatus="Automated",
Description="GCP Cloud Asset Inventory is services that provides a historical view of GCP resources and IAM policies through a time-series database. The information recorded includes metadata on Google Cloud resources, metadata on policies set on Google Cloud projects or resources, and runtime information gathered within a Google Cloud resource.",
@@ -171,7 +176,8 @@ CIS_1_8_KUBERNETES = Compliance(
Description="Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive",
Attributes=[
CIS_Requirement_Attribute(
- Section="1.1 Control Plane Node Configuration Files",
+ Section="1. Control Plane",
+ SubSection="1.1 Control Plane Node Configuration Files",
Profile="Level 1 - Master Node",
AssessmentStatus="Automated",
Description="Ensure that the controller manager pod specification file has permissions of `600` or more restrictive.",