Policy: Azure > CIS v4.0 > 03 - Analytics Services > 03.01 - Azure Databricks
This subsection covers security recommendations for Azure Databricks workspaces.
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Related Policies
- 03.01.01 - Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)
- 03.01.02 - Ensure that network security groups are configured for Databricks subnets
- 03.01.03 - Ensure that traffic is encrypted between cluster worker nodes
- 03.01.04 - Ensure that users and groups are synced from Microsoft Entra ID to Azure Databricks
- 03.01.05 - Ensure that Unity Catalog is configured for Azure Databricks
- 03.01.06 - Ensure that usage is restricted and expiry is enforced for Databricks personal access tokens
- 03.01.07 - Ensure that diagnostic log delivery is configured for Azure Databricks
- 03.01.08 - Ensure that data at rest and in transit is encrypted in Azure Databricks using customer managed keys (CMK)
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/cis
- tmod:@turbot/azure-cisv4-0#/policy/types/s0301
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv4-0#/policy/types/s0301"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv4-0#/policy/types/s0301"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI