Skip to content

Set default values to a secure value - Storage Account #770

Closed
@elbatane

Description

All default values should comply with a security baseline, e.g. NIST 800

The build-in policies of Azure can be used as a reference.

The task would be to scan over each of the following policies and make sure, that the module is per default complying to them.

The following policies are the NIST 800 ones:

\built-in-policies\policyDefinitions\Storage\ASC_Storage_DisallowPublicBlobAccess_Audit.json
\built-in-policies\policyDefinitions\Storage\Classic_AuditForClassicStorages_Audit.json
\built-in-policies\policyDefinitions\Storage\GeoRedundant_StorageAccounts_Audit.json
\built-in-policies\policyDefinitions\Storage\StorageAccountCustomerManagedKeyEnabled_Audit.json
\built-in-policies\policyDefinitions\Storage\StorageAccountInfrastructureEncryptionEnabled_Audit.json
\built-in-policies\policyDefinitions\Storage\StorageAccountOnlyVnetRulesEnabled_Audit.json
\built-in-policies\policyDefinitions\Storage\StorageAccountPrivateEndpointEnabled_Audit.json
\built-in-policies\policyDefinitions\Storage\StorageCache_CMKEnabled.json
\built-in-policies\policyDefinitions\Storage\StorageSync_PrivateEndpoint_AuditIfNotExists.json
\built-in-policies\policyDefinitions\Storage\Storage_AuditForHTTPSEnabled_Audit.json
\built-in-policies\policyDefinitions\Storage\Storage_EncryptionScopesShouldUseCMK_Audit.json
\built-in-policies\policyDefinitions\Storage\Storage_NetworkAcls_Audit.json
\built-in-policies\policyDefinitions\Azure Government\Storage\Storage_EncryptionScopesShouldUseCMK_Audit.json

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Labels

[cat] modulescategory: modules[prio] highimportance of the issue: high priorityenhancementNew feature or request

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions