Mods

Policy: Azure > CIS v4.0 > 10 - Storage Services > 10.03 - Storage Accounts > 10.03.11 - Ensure Azure Resource Manager ReadOnly locks are considered

Configures auditing against a CIS Benchmark item.

Level: 2

Azure Resource Manager locks provide a way to lock down resources to prevent accidental or malicious modifications. ReadOnly locks prevent users from modifying or deleting resources, which helps protect critical storage accounts from unauthorized changes.

Applying ReadOnly locks to critical storage accounts ensures that they cannot be modified or deleted, providing an additional layer of protection for sensitive data.

Primary Policy

This policy is used with the following primary policy:

Controls

Setting this policy configures this control:

Policy Specification

Schema Type
string
Default
Per Azure > CIS v4.0 > 10 - Storage Services > 10.03 - Storage Accounts
Valid Values [YAML]
  • Per Azure > CIS v4.0 > 10 - Storage Services > 10.03 - Storage Accounts
    
  • Skip
    
  • Check: Benchmark using attestation
    

Category

In Your Workspace

Developers