Mods

Policy: Azure > CIS v5.0 > 9 - Storage Services > 9.03 - Storage Accounts > 9.03.10 - Ensure Azure Resource Manager ReadOnly locks are considered for Azure Storage Accounts

Configures auditing against a CIS Benchmark item.

Level: 2

While a Delete lock is useful to prevent accidental deletion, a Read-only lock can provide additional protection by preventing modifications to the storage account configuration.

Targets

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Setting this policy configures this control:

Policy Specification

Schema Type
string
Default
Per Azure > CIS v5.0 > 09 - Storage Services
Valid Values [YAML]
  • Per Azure > CIS v5.0 > 09 - Storage Services
    
  • Skip
    
  • Check: Benchmark using attestation
    

Category

In Your Workspace

Developers