Policy Changes as per Release
Release 2502
Policies with Changed Descriptions
Following is the list of policies with changed descriptions:
- Azure Audit Snapshots Public Access Prohibited
- Azure Audit Security Monitoring Agent Installed On Linux VMSS
- Azure Audit Load Balancer Deletion Protection Enabled
- Azure Audit CDN Enabled
- Azure Audit Activitylog Delete NSG Event
- Azure Audit MySQLServers Public Access Check
- Azure Audit FunctionApp using Latest Java
- Azure Audit Activitylog CreateorUpdate NSG Event
- Azure Audit HTTPS Port Unrestricted
- Azure Audit Managed Disks Should Use A Specific Set Of Disk Encryption Sets For The CME
- Azure Audit Storage Blob Service Diagnostic Settings Enabled
- Azure Audit KeyVault Enabled For All Subscriptions
- Azure Audit FunctionApp using Latest DotNetFramework
- Azure Audit Disk Snapshot
- Azure Audit IAM Availability
- Azure Audit Virtual Machine osType
- Azure Audit Enable Locking Storage Account
- Azure Audit SignalR Service Should Use Private Link
- Azure Audit WebApp using Latest Java
- Azure Audit Age of Snapshot
- Azure Audit Auto Registration Enabled In DNS Zone
- Azure Audit Deprecated Account
- Azure Audit WebApp using Latest Python
- Azure Audit Managed Disks Should Be Double Encrypted With Both Platform Managed And Customer Managed Keys
- Azure Audit Hybrid Enabled
- Azure Audit RDP Port Unrestricted
- Azure Audit Workspace in Operation
- Azure Audit WebApp FTPS Enforcement
- Azure Audit Network Security Group Attached To Network Interface
- Azure Audit Budget Enabled At Subscription
- Azure Audit Disk not having Snapshot
- Azure Audit Image By BlobUri
- Azure Audit MSSQL Port Unrestricted
- Azure Audit Activitylog Delete NSGrule Event
- Azure Audit Virtual Machine Using IAM Role
- Azure Audit Allowlist Rules In Your Adaptive Application Control Policy Should Be Updated
- Azure Audit FunctionApp using Latest Python
- Azure Audit Application Gateway Health Probe Required
- Azure Audit Unused Ssh Key
- Azure Audit Defender Set On Container Registries
- Azure Audit Patch mode of Linux Virtual Machine
- Azure Audit Resource Logs In Azure Key Vault Managed HSM Should Be Enabled
- Azure Audit PublicIP Address Attached To Network Interface
- Azure Audit Virtual Machine Without Spot Feature
- Azure Audit Defender Set On For Kubernetes Cluster
- Azure Audit Ensure That UDP Services Are Restricted From The Internet
- Azure Audit Activitylog CreateorUpdate NSGrule Event
- Azure Audit Virtual Machine Tenancy
- Azure Audit Virtual Machine CPU Credit Consumed
- Azure Audit Unattached Storage Disk Encrypted With CMK
- Azure Audit WebApp using Latest TLS
- Azure Audit Adaptive Application Controls Defining Safe Applications Should Be Enabled On Your VirtualMachines
- Azure Audit Key Vault Managed HSM Should Disable Public Network Access
- Azure Audit Storage Account Replication Enabled
- Azure Audit Image Encryption
- Azure Audit Key Vault Not Scheduled For Deletion
- Azure Audit Virtual Machine Applications Required
- Azure Audit IAM Role Storage Account
- Azure Audit Storage Policy Grantee Check
- Azure Audit Optimised Virtual Machine
- Azure Audit Versioning enabled in Storage Account
- Azure Audit RPC Port Unrestricted
- Azure Audit Network Data Collection Linux
- Azure Audit MySQL Port Unrestricted
- Azure Audit Oracle Database port unrestricted
- Azure Audit Log Monitoring Enabled in Virtual Machine
- Azure Audit AutoScaling Enabled Integrated With Azure Monitor In VirtualMachine Scaleset
- Azure Audit Virtual Machine Association Compliance Status Check
- Azure Audit HTTP Port Unrestricted
- Azure Audit Automation Settings Check
- Azure Audit Port 9200 ElasticSearch Unrestricted
- Azure Audit Ensure That StorageAccount AccessKeys Are Periodically Regenerated
- Azure Audit Site Recovery Enabled On Virtual Machine
- Azure Audit WebApp using Latest DotNetFramework
- Azure Audit Ensure That VHDs Are Encrypted
- Azure Audit Automation Public Network Access Allowed
- Azure Audit Key Vault Should Disable Public Network Access
- Azure Audit Storage Table Service Diagnostic Settings Enabled
- Azure Audit Diagonisticlogs ServiceFabric VMSS
- Azure Audit Untagged Automation
- Azure Audit Virtual Machine CPU Credit Remaining 0
- Azure Audit MongoDB port Unrestricted
- Azure Audit Availability Zones Enabled In Virtual Machine
- Azure Audit WebApp using Latest PHP
- Azure Audit Patch mode of Windows Virtual Machine
- Azure Audit Automation Connected To Virtual Network
- Azure Network SecurityGroup Inbound Port Violation
- Azure Monitor Unencrypted SQLdb
- Azure Monitor Missing Endpoint Protection On VM
- Azure Audit Windows VirtualMachine does not have EndpointProtectionInstalled
Deprecated Policies
The following set of policies are disabled since they were found to be duplicate of already existing policy:
- Azure Audit Storage Accounts Should Use A Virtual Network Service Endpoint CS Policy
- Azure Advisor Consider AzureDataexplorer reserved capacity CS Policy
- Azure Advisor Inherit Tag From The ResourceGroup Using AzurePolicy. CS Policy
- Azure Audit Interfaces PublicIP CS Policy
- Azure Audit Web Application Firewall WAF should be enabled for Application Gateway
- Azure Audit SCP Log Analytics Custom Workspace
- Azure Audit APIService using Virtual Network ServiceEndPt
- Azure Audit Log Analytics Agent Deployed VM Image OS Unlisted
- Azure Audit Webports Restricted NSG
- AWS Audit API CloudWatch Logs
- AWS Audit EBS Snapshots Not Accessible All
- AWS Audit EC2 Security Group Rules Count Within limits
- AWS Audit ElasticSearch Domain Encryption Enabled
- Azure Audit Virtual Machine SKUs
- Azure Monitor Unencrypted SQLdb
- Azure Audit SQL managed instances without Advanced Data Security
- Azure Audit Enable GeoRedundant Backup MariaDB
- Azure Audit Restrict NetworkPorts on NetworkSecurityGroups VM
Release 2404
Please refer to the table below for a comprehensive list of any display name changes that have been applied to platform policies.
This list can be considered as up-to-date with the latest release version.
Former Policy Display Name | Current Display Name |
---|---|
AWS Amazon DocumentDB Audit DBInstance Encrypted CS Policy | AWS Audit DocumentDB Instance Encryption Enabled |
AWS Amazon DocumentDB Audit DB Cluster Encrypted CS Policy | AWS Audit DocumentDB DB Cluster Storage Encryption Enabled |
AWS Athena Audit WorkGroup Encrypted CS Policy | AWS Audit Athena WorkGroup Query Results Encryption Enabled |
AWS DMS Audit ReplicationInstances Encrypted CS Policy | AWS Audit DMS Replication Instances Encryption Enabled |
AWS Lambda Audit Functions Encrypted CS Policy | AWS Audit Lambda Functions Environment Variables Encryption Enabled |
AWS Storage Gateway Audit CachedISCSIVolume Encrypted CS Policy | AWS Audit Storage Gateway Cached ISCSI Volume Encryption Enabled |
AWS ALB Http to Https Redirection Check | AWS Audit ELBv2 ALB HTTP to HTTPS Redirection |
AWS Audit ACM Cert Renew 30days before Expiration | AWS Audit ACM Certificate Not Expiring Before 30 Days |
AWS Audit ACM Cert Renew 45days before Expiration | AWS Audit ACM Certificate Not Expiring Before 45 Days |
AWS Audit ACM Certificates with Wildcard Domain Names | AWS Audit ACM Certificate With Wildcard Domain Names Not Used |
AWS Audit API Detailed CloudWatch Metrics | AWS Audit API Gateway CloudWatch Metrics Enabled |
AWS Audit API Gateway Without WAF | AWS Audit API Gateway Integrated With WAF |
AWS Audit API Gateway Cache Encryption | AWS Audit API Gateway Cache Encryption Enabled |
AWS Audit API Gateway Integrated With AWS WAF | AWS Audit API Gateway Integrated With WAF |
AWS Audit AWS CloudWatch Events In Use | AWS Audit CloudWatch Events Configured |
AWS Audit AWS Organizations Changes Alarm | AWS Audit Organizations Changes Alarm Configured |
AWS Audit Add SSL TLS Server Certificates to App-Tier ELBs | AWS Audit ELB App-Tier Uses SSL/TLS Certificates |
AWS Audit Add SSL TLS Server Certificates to Web-Tier ELBs | AWS Audit ELB Web-Tier Uses SSL/TLS Certificates |
AWS Audit App-Tier ELB Security Policy | AWS Audit ELB App-Tier Uses Security Policy |
AWS Audit AppTier AutoScaling Group Associated ELB | AWS Audit Auto Scaling Group Of App-tier Associated With ELB |
AWS Audit App Tier EBS Encrypted | AWS Audit EBS Volume App-Tier Encryption Enabled |
AWS Audit App Tier ELB Listener Security | AWS Audit ELB App-Tier Listeners HTTPS/SSL Protocol Enabled |
AWS Audit App Tier Publicly Shared AMI | AWS Audit AMI Of App-Tier Not Publicly Shared |
AWS Audit Auto Scaling Group Cooldown Period | AWS Audit Auto Scaling Group Cooldown Period Utilized |
AWS Audit Auto Scaling Group Referencing Missing ELB | AWS Audit Auto Scaling Group Referencing Active ELB |
AWS Audit CMK Should Be Created For Lambda Env Varibles | AWS Audit Lambda Environment Variables Encrypted with CMK |
AWS Audit Check for ASG with integrated ELB | AWS Audit Auto Scaling Group Associated With ELB |
AWS Audit ELB Without WAF | AWS Audit ELBv2 ALB Integrated With WAF |
AWS Audit ELB Security Policy | AWS Audit ELB Uses Security Policy |
AWS Audit ELB With HTTPS Redirect | AWS Audit ELBv2 ALB HTTP to HTTPS Redirection |
AWS Audit ELB With Valid Security Groups | AWS Audit ELB With Valid Security Group |
AWS Audit ELBv2 ALB Listener Security | AWS Audit ELBv2 ALB Listeners HTTPS/SSL Protocol Enabled |
AWS Audit ELBv2 ALB Security Group | AWS Audit ELBv2 ALB With Valid Security Group |
AWS Audit ELBv2 ALB Security Policy | AWS Audit ELBv2 ALB Uses Security Policy |
AWS Audit ELBv2 Access Log | AWS Audit ELBv2 Access Logging Enabled |
AWS Audit ElasticSearch Encryption At Rest | AWS Audit ElasticSearch Domain Encryption Enabled |
AWS Audit ElasticSearch NodeToNode Encryption | AWS Audit ElasticSearch NodeToNode Encryption Enabled |
AWS Audit Internet Facing ELBs | AWS Audit ELB Non Internet Facing |
AWS Audit KMS Customer Master Key for EFS Encryption | AWS Audit EFS Encrypted With KMS CMK |
AWS Audit Queue Server Side Encryption | AWS Audit SQS Server Side Encryption Enabled |
AWS Audit RDS Encrypted With KMS Customer Master Keys | AWS Audit RDS Instance Encrypted With KMS CMK |
AWS Audit S3 Buckets Encrypted with Customer Provided CMKs | AWS Audit S3 Bucket Encrypted With KMS CMK |
AWS Audit S3 Default Encryption KMS | AWS Audit S3 Bucket Encrypted With KMS |
AWS Audit SNS Encrypted KMS | AWS Audit SNS Topic KMS Encryption Enabled |
AWS Audit SNS Topic Encrypted | AWS Audit SNS Topic Encryption Enabled |
AWS Audit SNS Topic Encrypted KMS CustomerMasterKeys | AWS Audit SNS Topic Encrypted With KMS CMK |
AWS Audit SQS Dead Letter Queue | AWS Audit SQS Dead Letter Queue Enabled |
AWS Audit SQS Encrypted With KMS Customer MasterKeys | AWS Audit SQS Encrypted With KMS CMK |
AWS Audit SQS Queue Exposed | AWS Audit SQS Queue Public Access Disabled |
AWS Audit SSL TLS Certificate Expiry 30 Days | AWS Audit IAM Server Certificate Not Expiring Before 30 Days |
AWS Audit SSL TLS Certificate Expiry 45 Days | AWS Audit IAM Server Certificate Not Expiring Before 45 Days |
AWS Audit SSL TLS Certificate Expiry 7 Days | AWS Audit IAM Server Certificate Not Expiring Before 7 Days |
AWS Audit SSM Parameter Encryption | AWS Audit SSM Parameter Encryption Enabled |
AWS Audit Sagemaker Endpoint Configuration KMS Key Configured | AWS Audit SageMaker Endpoint configured with KMS |
AWS Audit SecurityHub Enabled | AWS Audit Security Hub Enabled |
AWS Audit Security Group Rules Counts | AWS Audit EC2 Security Group Rules Count Within limits |
AWS Audit Support Plan | AWS Audit Support Plan Enabled |
AWS Audit Suspende Auto Scaling Groups | AWS Audit Auto Scaling Group Without Suspended Processes |
AWS Audit Unrestricted MsSQL Access | AWS Audit Security Group Has No Unrestricted Access To MSSQL |
AWS Audit Unrestricted MySQL Access | AWS Audit Security Group Has No Unrestricted Access To MYSQL |
AWS Audit Web-Tier ELB Listener Security | AWS Audit ELB Web-Tier Listeners HTTPS/SSL Protocol Enabled |
AWS Audit Web-Tier ELB Security Policy | AWS Audit ELB Web-Tier Uses Security Policy |
AWS Audit Web Tier Auto Scaling Group associated ELB | AWS Audit Auto Scaling Group Associated With ELB |
AWS Audit WorkSpaces Storage Encryption | AWS Audit WorkSpaces Storage Encryption Enabled |
AWS Autoscaling Group ELB Healthcheck Required | AWS Audit Auto Scaling Group ELB Health Check Enabled |
AWS EC2 Instance Detailed Monitoring Enabled | AWS Audit EC2 Instance Detailed Monitoring Enabled |
AWS ELB ACM Certificate Required | AWS Audit ELB Uses ACM Certificate |
AWS ELB Custom Security Policy SSL Check | AWS Audit ELB With No Custom Security Policy |
AWS RDS Storage Encrypted | AWS Audit RDS Storage Encryption Enabled |
AWS S3 BUCKET REPLICATION ENABLED | AWS Audit S3 Bucket Replication Enabled |
AWS Audit ACM Cert Validate CS Policy | AWS Audit ACM Certificate Not Expired Or Pending Validation |
AWS Aduit Check High Vulnerability Exists In A Virtual Machine CS Policy | AWS Audit EC2 Instance With No High Vulnerabilities |
AWS Audit EBS Not Encrypted With CMK CS Policy | AWS Audit EBS Volume Encrypted With KMS CMK |
AWS Audit ELB Listeners HTTPS SSL CS Policy | AWS Audit ELB Listener HTTPS/SSL Protocol Enabled |
AWS Audit SNS Topics Exposed CS Policy | AWS Audit SNS Topics Exposed CS Policy |
AWS Advisor_ELB Listener Security CS Policy | AWS Advisor Audit ELB Listener With Security Configurations |
AWS Advisor ELB Security Groups CS Policy | AWS Advisor Audit ELB With Valid Security Group |
AWS Audit ACM Cert Renew 45days before Expiration CS Policy | AWS Audit ACM Certificate Not Expiring Before 45 Days |
AWS Audit ACM Cert Renew 7days before Expiration CS Policy | AWS Audit ACM Certificate Not Expiring Before 7 Days |
AWS Audit ALB Http to Https Redirection Check CS Policy | AWS Audit ELBv2 ALB HTTP to HTTPS Redirection |
AWS Audit API CloudWatch Logs CS Policy | AWS Audit API Gateway CloudWatch Logging Enabled |
AWS Audit API Detailed CloudWatch Metrics CS Policy | AWS Audit API Gateway CloudWatch Metrics Enabled |
AWS Audit Alert Configuration For IAM Policy Changes CS Policy | AWS Audit IAM Policy Alert Configuration Enabled |
AWS Audit Alert Configuration For Unauthorized API Call CS Policy | AWS Audit Cloudwatch Alarm Configured For Unauthorized API Calls |
AWS Audit App-Tier ELB Security Policy CS Policy | AWS Audit ELB App-Tier Uses Security Policy |
AWS Audit App Tier ELB Listener Security CS Policy | AWS Audit ELB App-Tier Listener HTTPS/SSL Protocol Enabled |
AWS AUDIT AUTOSCALING GROUP ELB HEALTHCHECK REQUIRED CS POLICY | AWS Audit Auto Scaling Group ELB Health Check Enabled |
AWS Audit Check EMR Data Encryption AtRest CS Policy | AWS Audit EMR Cluster Data Encryption Enabled |
AWS Audit Check EMR Data Encryption At Transit CS Policy | AWS Audit EMR Cluster Data Encryption In Transit Enabled |
AWS Audit Check ElastiCache Encryption CS Policy | AWS Audit ElastiCache Redis Cluster Encryption Enabled |
AWS Audit Check RDS Cluster Encryption CS Policy | AWS Audit RDS Cluster Encryption Enabled |
AWS Audit Check RDS Snapshot Encryption CS Policy | AWS Audit RDS Snapshot Encryption Enabled |
AWS Audit DynamoDB Table Encryption Enabled CS Policy | AWS Audit DynamoDB Table Encryption Enabled |
AWS Audit EC2 EBS Encryption by Default CS Policy | AWS Audit EBS Volume Default Encryption Enabled |
AWS Audit EFS Encryption CS Policy | AWS Audit EFS Encryption Enabled |
AWS Audit ELB Insecure SSL Protocols CS Policy | AWS Audit ELB Uses Security Policy |
AWS Audit ELB With Valid Security Groups CS Policy | AWS Audit ELB With Valid Security Group |
AWS Audit ELBv2 ALB Listener Security CS Policy | AWS Audit ELBv2 ALB Listeners HTTPS/SSL Protocol Enabled |
AWS Audit ELBv2 ALB Security Group CS Policy | AWS Audit ELBv2 ALB With Valid Security Group |
AWS Audit ELBv2 Access Log CS Policy | AWS Audit ELBv2 Access Logging Enabled |
AWS Audit ElasticSearch Encryption In Transit CS Policy | AWS Audit ElasticSearch NodeToNode Encryption At Transit Enabled |
AWS Audit ElasticSearch NodeToNode Encryption CS Policy | AWS Audit ElasticSearch NodeToNode Encryption Enabled |
AWS Audit Encrypted Volumes CS Policy | AWS Audit EBS Volume Encryption Enabled |
AWS Audit Fsx For Lustre Rest Encrypted Using Kms Cmks CS Policy | AWS Audit FSx Lustre Encrypted With KMS CMK |
AWS Audit Fsx For Ontap Rest Encrypted Using Kms Cmks CS Policy | AWS Audit FSx Ontap Encrypted With KMS CMK |
AWS Audit Fsx For Openzfs Rest Encrypted Using Kms Cmks CS Policy | AWS Audit FSx OpenZFS Encrypted With KMS CMK |
AWS Audit Fsx For Windows Fs Date At Rest Encrypted With Kms Cmks CS Policy | AWS Audit FSx Windows File System Encrypted With KMS CMK |
AWS RDS Storage Encrypted CS Policy | AWS Audit RDS Storage Encryption Enabled |
AWS Audit SNS Cross Account Access CS Policy | AWS Audit SNS With No Cross Account Access |
AWS Audit SSM Parameter Encryption CS Policy | AWS Audit SSM Parameter Encryption Enabled |
AWS Audit Sg Virtual Tapes Encrypted By Kms Cmks CS Policy | AWS Audit Storage Gateway Virtual Tapes Encrypted With KMS CMK |
AWS Audit VPC Endpoints Encryption CS Policy | AWS Audit VPC Endpoints Encryption Enabled |
AWS Audit Web-Tier ELB Security Policy CS Policy | AWS Audit ELB Web-Tier Uses Security Policy |
AWS Audit Web-Tier ELB Listener Security CS Policy | AWS Audit ELB Web-Tier Listener HTTPS/SSL Protocol Enabled |
Updated 1 day ago