Policy: Azure > CIS v4.0 > 10 - Storage Services > 10.01 - Azure Files > 10.01.03 - Ensure 'SMB channel encryption' is set to 'AES-256-GCM' or higher for SMB file shares
Configures auditing against a CIS Benchmark item.
Level: 1
SMB channel encryption provides data encryption in transit for Azure Files. AES-256-GCM is a strong encryption algorithm that provides both confidentiality and integrity for data in transit. Requiring AES-256-GCM encryption ensures that data cannot be intercepted or tampered with during transmission.
Using AES-256-GCM or higher encryption for SMB channels ensures the highest level of protection for data in transit.
Primary Policy
This policy is used with the following primary policy:
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/v070302
- tmod:@turbot/azure-cisv4-0#/policy/types/r100103
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv4-0#/policy/types/r100103"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv4-0#/policy/types/r100103"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI