Policy: Azure > CIS v1 > 4 Database Services
Covers recommendations addressing Database Services.
Resource Types
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Related Policies
- 4.01 Ensure that 'Auditing' is set to 'On' (Scored)
- 4.02 Ensure that 'AuditActionGroups' in 'auditing' policy for a SQL server is set properly (Scored)
- 4.03 Ensure that 'Auditing' Retention is 'greater than 90 days' (Scored)
- 4.04 Ensure that 'Advanced Data Security' on a SQL server is set to 'On' (Scored)
- 4.05 Ensure that 'Threat Detection types' is set to 'All' (Scored)
- 4.06 Ensure that 'Send alerts to' is set (Scored)
- 4.07 Ensure that 'Email service and co-administrators' is 'Enabled' (Scored)
- 4.08 Ensure that Azure Active Directory Admin is configured (Scored)
- 4.09 Ensure that 'Data encryption' is set to 'On' on a SQL Database (Scored)
- 4.10 Ensure SQL server's TDE protector is encrypted with BYOK (Use your own key) (Scored)
- 4.11 Ensure 'Enforce SSL connection' is set to 'ENABLED' for MySQL Database Server (Scored)
- 4.12 Ensure server parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Server (Scored)
- 4.13 Ensure 'Enforce SSL connection' is set to 'ENABLED' for PostgreSQL Database Server (Scored)
- 4.14 Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Server (Scored)
- 4.15 Ensure server parameter 'log_disconnections' is set to 'ON' for PostgreSQL Database Server (Scored)
- 4.16 Ensure server parameter 'log_duration' is set to 'ON' for PostgreSQL Database Server (Scored)
- 4.17 Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Server (Scored)
- 4.18 Ensure server parameter 'log_retention_days' is greater than 3 days for PostgreSQL Database Server (Scored)
Controls
Policy Specification
Schema Type |
|
---|---|
Default |
|
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/cis
- tmod:@turbot/azure-cisv1#/policy/types/s04
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv1#/policy/types/s04"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv1#/policy/types/s04"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI