Policy: Azure > CIS v2.0 > 03 - Storage Accounts
Covers security recommendations to follow to set storage account policies on an Azure Subscription. An Azure storage account provides a unique namespace to store and access Azure Storage data objects.
Resource Types
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Related Policies
- 3.01 - Ensure that 'Secure transfer required' is set to 'Enabled'
- 3.02 - Ensure that `Enable Infrastructure Encryption` for Each Storage Account in Azure Storage is Set to `enabled`
- 3.03 - Ensure that 'Enable key rotation reminders' is enabled for each Storage Account
- 3.04 - Ensure that Storage Account Access Keys are Periodically Regenerated
- 3.05 - Ensure Storage Logging is Enabled for Queue Service for 'Read', 'Write', and 'Delete' requests
- 3.06 - Ensure that Shared Access Signature Tokens Expire Within an Hour
- 3.08 - Ensure Default Network Access Rule for Storage Accounts is Set to Deny
- 3.09 - Ensure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Access
- 3.10 - Ensure Private Endpoints are used to access Storage Accounts
- 3.11 - Ensure Soft Delete is Enabled for Azure Containers and Blob Storage
- 3.12 - Ensure Storage for Critical Data are Encrypted with Customer Managed Keys
- 3.13 - Ensure Storage logging is Enabled for Blob Service for 'Read', 'Write', and 'Delete' requests
- 3.15 - Ensure the "Minimum TLS version" for storage accounts is set to "Version 1.2"
- Maximum Attestation Duration
Controls
Policy Specification
Schema Type |
|
---|---|
Default |
|
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/cis
- tmod:@turbot/azure-cisv2-0#/policy/types/s03
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv2-0#/policy/types/s03"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv2-0#/policy/types/s03"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI