Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
Azure
Loading controls...

Control: Azure > CIS v4.0 > 09 - Security Services > 09.01 - Microsoft Defender for Cloud > 09.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates

Configures auditing against a CIS Benchmark item.

Level: 1

Ensure that the latest OS patches for all virtual machines are applied.

Windows and Linux virtual machines should be kept updated to address specific bugs or flaws, improve OS or application general stability, and fix security vulnerabilities.

Microsoft Defender for Cloud retrieves a list of available security and critical updates from Windows Update or Windows Server Update Services (WSUS), depending on which service is configured on a Windows VM. If a VM is missing a system update, the security center will recommend system updates be applied.

By default, patches are not automatically deployed.

Resource Types

This control targets the following resource types:

  • Azure > Security Center > Security Center

Policies

This control type relies on these other policies when running actions:

  • Azure > CIS v4.0 > 09 - Security Services > 09.01 - Microsoft Defender for Cloud > 09.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates
  • Azure > CIS v4.0 > 09 - Security Services > 09.01 - Microsoft Defender for Cloud > 09.01.10 - Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates > Attestation
  • Azure > CIS v4.0 > Maximum Attestation Duration
  • Azure > CIS v4.0
  • Azure > CIS v4.0 > 09 - Security Services
  • Azure > CIS v4.0 > 09 - Security Services > Maximum Attestation Duration

Category

  • CIS > Controls v7 > 03 Continuous Vulnerability Management > 3.04 Deploy Automated Operating System Patch Management Tools

In Your Workspace

  • Controls by Resource report
  • Controls by Control Type report

Developers

    Control Type URI
    • tmod:@turbot/azure-cisv4-0#/control/types/r090110
  • Category URI
    • tmod:@turbot/cis#/control/categories/v070304
  • GraphQL
    • query controlType(id: "tmod:@turbot/azure-cisv4-0#/control/types/r090110") { … }
    • query controls(filter: "controlTypeId:'tmod:@turbot/azure-cisv4-0#/control/types/r090110'") { … }
  • CLI
    • Get Controls
    • turbot graphql controls --filter "controlTypeId:tmod:@turbot/azure-cisv4-0#/control/types/r090110"
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
50
Mods
207
Resource Types
3,612
Policies
1,957
Controls
103
Quick Actions
114
IAM