Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
Azure
Loading policies...

Policy: Azure > CIS v1 > 4 Database Services

Covers recommendations addressing Database Services.

Targets

This policy targets the following resource types:

  • Azure > Subscription

Primary Policy

This policy is used with the following primary policy:

  • Azure > CIS v1

Related Policies

  • 4.01 Ensure that 'Auditing' is set to 'On' (Scored)
  • 4.02 Ensure that 'AuditActionGroups' in 'auditing' policy for a SQL server is set properly (Scored)
  • 4.03 Ensure that 'Auditing' Retention is 'greater than 90 days' (Scored)
  • 4.04 Ensure that 'Advanced Data Security' on a SQL server is set to 'On' (Scored)
  • 4.05 Ensure that 'Threat Detection types' is set to 'All' (Scored)
  • 4.06 Ensure that 'Send alerts to' is set (Scored)
  • 4.07 Ensure that 'Email service and co-administrators' is 'Enabled' (Scored)
  • 4.08 Ensure that Azure Active Directory Admin is configured (Scored)
  • 4.09 Ensure that 'Data encryption' is set to 'On' on a SQL Database (Scored)
  • 4.10 Ensure SQL server's TDE protector is encrypted with BYOK (Use your own key) (Scored)
  • 4.11 Ensure 'Enforce SSL connection' is set to 'ENABLED' for MySQL Database Server (Scored)
  • 4.12 Ensure server parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Server (Scored)
  • 4.13 Ensure 'Enforce SSL connection' is set to 'ENABLED' for PostgreSQL Database Server (Scored)
  • 4.14 Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Server (Scored)
  • 4.15 Ensure server parameter 'log_disconnections' is set to 'ON' for PostgreSQL Database Server (Scored)
  • 4.16 Ensure server parameter 'log_duration' is set to 'ON' for PostgreSQL Database Server (Scored)
  • 4.17 Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Server (Scored)
  • 4.18 Ensure server parameter 'log_retention_days' is greater than 3 days for PostgreSQL Database Server (Scored)

Policy Specification

Schema Type
string
Default
Skip
Valid Values [YAML]
  • Skip
    
Examples [YAML]
  • Skip
    

Category

  • CIS

In Your Workspace

  • Policy Settings by Type report

Developers

    Category URI
    • tmod:@turbot/cis#/control/categories/cis
  • Policy Type URI
    • tmod:@turbot/azure-cisv1#/policy/types/s04
  • GraphQL
    • query policyType(id: "tmod:@turbot/azure-cisv1#/policy/types/s04") { … }
    • query policySettings(filter: "policyTypeId:'tmod:@turbot/azure-cisv1#/policy/types/s04'") { … }
    • query policyValues(filter: "policyTypeId:'tmod:@turbot/azure-cisv1#/policy/types/s04'") { … }
  • CLI
    • Get Policy Type
    • turbot graphql policy-type --id "tmod:@turbot/azure-cisv1#/policy/types/s04"
    • Get Policy Settings
    • turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv1#/policy/types/s04"
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
50
Mods
161
Resource Types
3,434
Policies
1,802
Controls
103
Quick Actions
107
IAM