Policy Settings
The Azure CIS v2.0.0 - Section 6 - Networking policy pack has 6 policy settings:
Policy | Setting | Note |
---|---|---|
Azure > Network > Network Security Group > Ingress Rules > Approved | Check: Approved | Azure CIS v2.0.0 - Controls: 6.1, 6.2, 6.3, 6.4 |
Azure > Network > Network Security Group > Ingress Rules > Approved > Rules | REJECT $.turbot.cidr:0.0.0.0/0 $.turbot.ports=22,3389,443,80 REJECT $.turbot.cidr:0.0.0.0/0 $.turbot.protocol:udp APPROVE * | Azure CIS v2.0.0 - Controls: 6.1, 6.2, 6.3, 6.4 |
Azure > Network Watcher > Flow Log > Retention Policy | Check: Enabled per `Retention Policy > Days` | Azure CIS v2.0.0 - Controls: 6.5 |
Azure > Network Watcher > Flow Log > Retention Policy > Days | 90 | Azure CIS v2.0.0 - Controls: 6.5 |
Azure > Network Watcher > Network Watcher > Approved | Check: Approved | Azure CIS v2.0.0 - Controls: 6.6 |
Azure > Network Watcher > Network Watcher > Approved > Custom | Calculated | Azure CIS v2.0.0 - Controls: 6.6 |