Policy: Azure > CIS v4.0 > 10 - Storage Services > 10.03 - Storage Accounts > 10.03.01 - Secrets and Keys
This subsection covers security recommendations for managing storage account access keys and secrets. These recommendations focus on enabling key rotation reminders, periodically regenerating access keys, and disabling shared key access in favor of Azure AD authentication.
Primary Policy
This policy is used with the following primary policy:
Related Policies
- 10.03.01.01 - Ensure that 'Enable key rotation reminders' is enabled for each Storage Account
- 10.03.01.02 - Ensure that Storage Account access keys are periodically regenerated
- 10.03.01.03 - Ensure 'Allow storage account key access' for Azure Storage Accounts is 'Disabled'
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/cis
- tmod:@turbot/azure-cisv4-0#/policy/types/s100301
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv4-0#/policy/types/s100301"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv4-0#/policy/types/s100301"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI