View a markdown version of this page

設定 Security Hub CSPM 以與 Microsoft Azure 整合 - AWS Security Hub

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

設定 Security Hub CSPM 以與 Microsoft Azure 整合

完成先決條件任務設定 Microsoft Azure 環境後,您可以將 AWS Security Hub CSPM 設定為與 Azure 整合。若要設定 Security Hub CSPM 與 Azure 整合,您可以建立連接器。建立連接器之後,會發生下列事件:

  1. Security Hub CSPM 會驗證 Azure 憑證和 Azure 環境的連線。此程序需要幾分鐘的時間。

  2. AWS Config 開始探索和記錄 Azure 資源的組態資料。

  3. Security Hub CSPM 會在資源資料收集完成後開始為您的 Azure 資源產生狀態管理問題清單。

注意

如果您已在 Security Hub 中建立連接器,服務連結連接器會自動在 Security Hub CSPM 中建立。您不需要建立單獨的客戶受管連接器,除非您需要不同的範圍。

建立 Azure 連接器

若要為您的環境建立 Microsoft Azure 連接器,請使用 AWS Security Hub CSPM 主控台或 API 完成下列步驟。

  1. 開啟 Security Hub CSPM 主控台。

  2. 在導覽窗格中選擇整合

  3. 選擇建立 Azure 連接器

  4. 針對 Azure 租用戶 ID,輸入您的 Azure Active Directory 租用戶識別符。

  5. 針對應用程式 (用戶端 ID),輸入您建立之 Azure 應用程式註冊的應用程式 ID。

  6. 執行下列動作來設定其他設定和連接器的範圍:

    • 名稱中,輸入連接器的唯一名稱。名稱最多可包含 50 個英數字元,且可包含連字號 (‐)。

      重要

      名稱和描述用於識別您的內容,我們建議您不要在其中包含敏感、機密或個人身分識別資訊 (PII)。

    • 描述中,選擇性地輸入連接器的簡短描述。描述最多可包含 200 個字元。

    • 對於訂閱,請選擇所有訂閱以監控租用戶中的所有目前和未來訂閱,或選擇特定訂閱以僅監控您指定的訂閱。如果您選擇只監控特定訂閱,請輸入每個訂閱的 ID。

    • 針對區域,選擇部署資源的 Azure 區域。

      注意

      評估 Microsoft Entra ID 和 Microsoft Graph 資源的控制項需要將全域區域範圍包含在整合組態中。如果您只選取特定的 Azure 區域,這些控制項將不會產生問題清單。

  7. 檢閱您的組態,然後選擇建立連接器

建立連接器後,Security Hub CSPM 會驗證您的 Azure 憑證並開始資源探索。連接器應該會在 2-5 分鐘內顯示作用中狀態。

啟用標準和控制

建立連接器之後,您必須啟用 Azure 安全標準,才能開始產生問題清單。如需啟用標準和管理控制項的一般資訊,請參閱啟用標準啟用和停用控制項

可用的標準
  • CIS Microsoft Azure Foundations Benchmark v4.0 - 廣泛採用的安全基準,定義保護 Azure 環境的最佳實務。每個控制項都會評估 Azure 組態的特定層面 (例如,儲存帳戶加密、網路安全群組規則、身分和存取設定)。

  • Azure 基礎最佳實務 - 透過關聯網路連線能力、公開存取和敏感資料指標,評估 Azure 資源的暴露風險。產生暴露類型調查結果,以強調風險較高的資源。

Azure 標準有自己的一組控制項,與 AWS 控制項分開。沒有可在單一檢查中評估 AWS 和 Azure 資源的跨雲端控制項。

啟用標準

您可以透過 Security Hub CSPM 主控台或透過 API/CLI 啟用 Azure 標準。導覽至 Security Hub CSPM 主控台中的標準,並啟用所需的標準。或者,使用 CLI:

$ aws securityhub batch-enable-standards \ --standards-subscription-requests '[{"StandardsArn": "Standard-ARN"}]' \ --region your-aws-region
注意

您可以在建立連接器之前或之後啟用 Azure 標準 - 它們不會耦合。不過,只有在連接器和標準都處於作用中狀態且已收集資源資料時,才會產生問題清單。

管理個別控制項

啟用標準後 (通常在幾秒鐘內),您可以檢視和管理個別控制項:

  • 檢視控制項:使用 Security Hub CSPM 主控台 (標準 > 選取標準 > 控制項) 或 list-standards-control-associations API。

  • 停用控制項:如果特定控制項不適用於您的環境,您可以停用它。

  • 設定自訂參數:某些控制項接受自訂輸入參數 (例如,密碼長度閾值)。這些可以透過 update-security-control API 設定。

重要說明
  • Azure 標準會在整個連接器範圍內統一套用。您無法為相同連接器中的不同 Azure 訂閱啟用不同的標準或控制項。

  • 控制項取決於資源資料可用性。每個控制項都會評估特定的 Azure 資源類型。如果 AWS Config 尚未收集特定資源類型的組態資料,控制項將為這些資源產生預設 PASS 調查結果。這些預設 PASS 調查結果會在資源資料送達時自動更新為準確的評估。在資源資料收集完成之前,請勿將初始合規分數視為準確。

  • 即使在建立連接器之前,也可以設定安全控制的自訂輸入參數 - 它們會獨立保留。

  • 控制評估訂閱層級設定 (例如 Microsoft Defender 計劃、活動日誌提醒) 為每個 Azure 訂閱產生一個問題清單,而不是每個個別資源。

  • 多雲端標準不能包含在中央組態政策中。您必須在每個 AWS 帳戶 和 中獨立管理 Azure 標準啟用 AWS 區域。

調整 Azure 連接器的範圍

建立 Microsoft Azure 連接器之後,您可以透過變更其監控的 Azure 訂閱或 Azure 區域來調整連接器的範圍。如果您調整範圍,大多數類型的變更會在大約 15 分鐘內生效。

調整範圍之前,請注意下列事項:

  • 客戶受管連接器的範圍不能超過相同帳戶和區域中任何現有服務連結連接器的範圍。

  • 當您擴展範圍時,Security Hub CSPM 會在 AWS Config 收集其組態資料後開始產生新資源的問題清單。

  • 當您縮小範圍時,已移除資源的現有問題清單會轉換為封存狀態。

驗證 Azure 連接器的運作狀態

您可以隨時檢查 Microsoft Azure 連接器的運作狀態。導覽至 Security Hub CSPM 主控台中的整合,並確認連接器顯示作用中狀態。

初始問題清單通常會在資源資料收集完成的 15-30 分鐘內顯示。

注意

連接器運作狀態最終一致。當許可或組態問題發生時,連接器狀態會快速變更為降級,並顯示可採取動作的訊息。不過,在您修正問題之後,狀態最多可能需要 24 小時才能返回已連線

  • 最近修正後的降級狀態不一定表示問題持續發生。

  • 如需記錄失敗的即時可見性,請檢查 命名空間中的 CloudWatch 指標。

故障診斷 Azure 連接器

如果連接器發生問題,請使用下列資訊來診斷和解決常見問題。

連接器狀態為運作狀態不良

如果未在 Azure 中正確設定聯合登入資料,通常會發生此問題。

若要解決此問題,請確認 Azure 聯合憑證中的字符發行者 URL 和主體 ARN 與您的 相符 AWS 帳戶。

30 分鐘後沒有問題清單

如果 Event Hub 未收到活動日誌或未啟用標準,可能會發生此問題。

若要解決此問題,請確認 Event Hub 命名空間已正確標記 (AWSConfig-account-id-region=activitylog)、AWSConfig存在取用者群組、指派資料接收者角色,且至少啟用一個 Azure 標準。

無法記錄一些 Azure 資源

錯誤可能因下列任何原因發生:

  • Azure 環境不符合資源記錄的先決條件。

  • 應用程式註冊沒有 Microsoft Graph API 許可的管理員同意。

  • Reader 角色指派未涵蓋所有必要的範圍。

  • Microsoft Entra ID 租用戶沒有所需的日誌資料。

若要解決錯誤,請執行下列動作:

  1. 若要確認您的環境符合所有需求,請檢閱 Microsoft Azure 的先決條件

  2. 確認應用程式註冊具有管理員同意的必要 Microsoft Graph API 許可。

  3. 確認服務主體在租用戶根管理群組範圍內具有讀取器角色。

連接器保持待定狀態

如果 Azure 應用程式註冊設定錯誤,可能會發生此問題。

若要解決此問題,請確認聯合身分憑證發行者 URL 和主體識別符與您的 相符 AWS 帳戶。同時確認已針對所有必要的 Microsoft Graph API 許可授予管理員同意。

Security Hub CSPM 如何處理資源識別符

透過啟用 AWS Security Hub CSPM 的 Azure 整合,其他雲端提供者的資源識別符會存放在 AWS Config、 AWS Security Hub CSPM 和其他 AWS 服務 (視需要) 中,做為從其他雲端提供者收集之對應資源組態資料的管理相關中繼資料。這類資源識別符不會構成您的內容,我們建議您不要在其中包含敏感、機密或個人身分識別資訊。

您連線雲端環境的下列識別符由 存放和使用 AWS ,以提供多雲端安全功能:

  • 資源識別符:Azure 租戶 ID、訂閱 ID、位置 (區域)、資源 ID (資源群組 IDs或名稱、資源提供者、資源類型)

這些識別符之間的關係 - 包括資源彼此的關係,以及問題清單與資源的關係 - 也會儲存為服務中繼資料。 AWS 使用這些識別符進行資源相互關聯、將問題清單與資源建立關聯、服務操作記錄和刪除重複。

Azure 的可用控制項

啟用 Azure 標準後,以下 122 個控制項會評估您的 Azure 資源。控制項分佈在兩個標準中:

  • CIS Microsoft Azure Foundations Benchmark v4.0 – 映射至特定 CIS 區段的 96 控制項

  • Azure 基礎最佳實務 – 涵蓋其他安全最佳實務的 26 個控制項

注意

評估 Microsoft Entra ID 和 Microsoft Graph 資源的控制項需要將全域區域範圍包含在整合組態中。

可用的 Azure 控制項
控制項標題 Resource Type (資源類型) 標準
啟用受管身分的 Azure Container 應用程式應遵循最低權限 microsoft.app/containerapps Azure 基礎最佳實務
Azure Container Apps 不應傳遞 Azure SDK 登入資料做為環境變數 microsoft.app/containerapps Azure 基礎最佳實務
Azure Container Apps 不應啟用外部輸入 microsoft.app/containerapps Azure 基礎最佳實務
Azure Container App 環境不應具有不受限制的 NSG 存取 microsoft.app/containerapps Azure 基礎最佳實務
Azure Container App 受管環境不應啟用公有 IP microsoft.app/managedenvironments Azure 基礎最佳實務
Azure 角色指派不應授予訂閱範圍內廣泛的管理員存取權 microsoft.authorization/roleassignments Azure 基礎最佳實務
Azure 角色指派不應授予使用者存取管理員角色 microsoft.authorization/roleassignments CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 自訂角色定義不應具有萬用字元管理許可 microsoft.authorization/roledefinitions CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Cloud Security Benchmark 政策指派應該啟用強制執行模式 microsoft.authorization/policyassignments CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Kubernetes Service (AKS) 叢集不應具有沒有 IP 限制的可公開存取 API 伺服器 microsoft.containerservice/managedclusters Azure 基礎最佳實務
Azure Kubernetes Service (AKS) 叢集應該加密靜態 Kubernetes 秘密 microsoft.containerservice/managedclusters Azure 基礎最佳實務
Azure Kubernetes Service (AKS) 叢集應執行支援的 Kubernetes 版本 microsoft.containerservice/managedclusters Azure 基礎最佳實務
Azure Cosmos 資料庫帳戶應該啟用持續備份 microsoft.documentdb/databaseaccounts Azure 基礎最佳實務
適用於 MySQL 彈性伺服器的 Azure Database 應停用公有網路存取 microsoft.dbformysql/flexibleservers Azure 基礎最佳實務
Azure Databricks 工作區應部署在客戶管理的虛擬網路中 microsoft.databricks/workspaces CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Databricks 工作區應設定診斷日誌交付 microsoft.databricks/workspaces CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Databricks 工作區應使用客戶受管金鑰進行受管磁碟加密 microsoft.databricks/workspaces CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra ID 授權政策應禁止預設使用者註冊應用程式 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Entra ID 應該啟用安全預設值 microsoft.graph/policies/identitysecuritydefaultsenforcementpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 租用戶應具有條件式存取政策,封鎖來自不允許地理位置的存取 microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 租用戶應具有條件式存取政策,封鎖裝置程式碼身分驗證流程 microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 條件式存取政策應要求所有使用者使用 MFA microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 租用戶應要求透過條件式存取政策對有風險的登入進行多重要素驗證 microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 租用戶應透過 Azure Service Management API 的條件式存取要求 MFA microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
至少應該有一個條件式存取政策需要 Microsoft Admin Portal 的 MFA microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 授權政策應限制非管理員使用者建立租用戶 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra ID 身分驗證方法政策應將重新確認期間設定為非零值 microsoft.graph/policies/authenticationmethodspolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 授權政策應限制使用者對應用程式的同意 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 授權政策應限制使用者對已驗證發佈者應用程式的同意 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 授權政策應限制訪客使用者存取自己的目錄物件 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 授權政策應僅將訪客邀請限制為管理員角色 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 授權政策應將安全群組建立限制為管理員 microsoft.graph/policies/authorizationpolicy CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra 租用戶應該需要多重驗證才能註冊或加入裝置 microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Entra ID 目錄角色應該具有 2 到 4 個全域管理員 microsoft.graph/directoryrole CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Entra ID 群組設定應將群組建立限制為管理員 microsoft.graph/organization CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應為活動日誌設定診斷設定 microsoft.insights/diagnosticsettings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有建立政策指派的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有政策指派刪除的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有活動日誌提醒,以建立或更新網路安全群組操作 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有刪除網路安全群組的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有建立或更新安全解決方案的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有安全解決方案刪除的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有活動日誌提醒,以建立或更新 SQL Server 防火牆規則 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有刪除 SQL Server 防火牆規則的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應針對建立或更新公有 IP 地址操作設定活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應有公有 IP 地址刪除的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應具有 Service Health 事件的活動日誌提醒 microsoft.insights/activitylogalerts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應至少設定一個 Application Insights 元件 microsoft.insights/components CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Key Vault 應該啟用軟刪除和清除保護 microsoft.keyvault/vaults CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Key Vault 應該啟用角色型存取控制 microsoft.keyvault/vaults CIS Microsoft Azure Foundations Benchmark 4.0 版
使用私有端點時,Azure Key Vault 應該停用公有網路存取 microsoft.keyvault/vaults CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 金鑰保存庫應使用私有端點 microsoft.keyvault/vaults CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Key Vault 應該已啟用清除保護 microsoft.keyvault/vaults Azure 基礎最佳實務
Azure 金鑰保存庫應限制網路存取 microsoft.keyvault/vaults Azure 基礎最佳實務
Azure Key Vault 應該啟用 AuditEvent 記錄 microsoft.keyvault/vaults CIS Microsoft Azure Foundations Benchmark 4.0 版
RBAC 保存庫中的 Azure Key Vault 金鑰應設定過期日期 microsoft.keyvault/vaults/keys CIS Microsoft Azure Foundations Benchmark 4.0 版
非 RBAC 保存庫中的 Azure Key Vault 金鑰應設定過期日期 microsoft.keyvault/vaults/keys CIS Microsoft Azure Foundations Benchmark 4.0 版
已啟用 RBAC 的保存庫中的 Azure Key Vault 秘密應設定過期日期 microsoft.keyvault/vaults/secrets CIS Microsoft Azure Foundations Benchmark 4.0 版
非 RBAC 保存庫中的 Azure 金鑰保存庫秘密應設定過期日期 microsoft.keyvault/vaults/secrets CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Key Vault 金鑰應該已啟用自動輪換 microsoft.keyvault/vaults/keys CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 網路安全群組應限制來自網際網路的傳入 RDP 存取 microsoft.network/networksecuritygroups CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 網路安全群組應限制來自網際網路的傳入 UDP 存取 microsoft.network/networksecuritygroups CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 網路安全群組應限制來自網際網路的傳入 HTTP 存取 microsoft.network/networksecuritygroups CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Application Gateway 子網路不應具有不受限制的 NSG 存取 microsoft.network/networksecuritygroups Azure 基礎最佳實務
Azure 網路安全群組應具有明確拒絕所有規則 microsoft.network/networksecuritygroups Azure 基礎最佳實務
Azure 網路安全群組不應允許不受限制的傳入存取受限制的連接埠 microsoft.network/networksecuritygroups Azure 基礎最佳實務
Azure Network Watcher 流程日誌應啟用虛擬網路流程記錄,並將流量分析傳送至 Log Analytics microsoft.network/networkwatchers/flowlogs CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 網路安全群組應限制從網際網路存取 SSH microsoft.network/networksecuritygroups CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應至少有一個 Azure Bastion 主機 microsoft.network/bastionhosts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for Servers microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
機器應該在 Microsoft Defender for Cloud 中部署運作狀態良好的漏洞評估解決方案 microsoft.security/assessments CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該已啟用與 Microsoft Defender for Cloud 的端點保護整合 microsoft.security/settings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該在 Microsoft Defender for Servers 中啟用機器的無代理程式掃描 microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應在 Defender for Servers 中啟用檔案完整性監控 microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for Containers microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for Storage microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應啟用 Microsoft Defender for App Service microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for Azure Cosmos 資料庫 microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用開放原始碼關聯式資料庫的 Microsoft Defender microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for Azure SQL Databases microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for SQL Servers on Machines microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應啟用 Microsoft Defender for Key Vault microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應啟用 Microsoft Defender for Resource Manager microsoft.security/pricings CIS Microsoft Azure Foundations Benchmark 4.0 版
虛擬機器應讓 Microsoft Defender for Cloud 將系統更新評估報告為正常運作 microsoft.security/assessments CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Defender for Cloud 安全聯絡人應通知擁有者角色提醒 microsoft.security/securitycontacts CIS Microsoft Azure Foundations Benchmark 4.0 版
Microsoft Defender for Cloud 安全聯絡人應設定額外的電子郵件地址 microsoft.security/securitycontacts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 安全聯絡人應啟用警示電子郵件通知,並具有足夠包含的最低嚴重性 microsoft.security/securitycontacts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 安全聯絡人應啟用攻擊路徑電子郵件通知,並設定風險層級 microsoft.security/securitycontacts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 訂閱應該啟用 Microsoft Defender for IoT microsoft.security/iotsecuritysolutions CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure SQL 伺服器應停用公有網路存取 microsoft.sql/servers Azure 基礎最佳實務
SQL 伺服器應設定 Azure Active Directory 管理員 microsoft.sql/servers Azure 基礎最佳實務
Azure SQL 資料庫應該啟用地理備援備份 microsoft.sql/servers/databases Azure 基礎最佳實務
Azure SQL 伺服器不應使用預設管理員帳戶名稱 microsoft.sql/servers Azure 基礎最佳實務
Azure SQL 受管執行個體應啟用自動次要版本升級 microsoft.sql/managedinstances Azure 基礎最佳實務
Azure Storage 帳戶應使用客戶受管金鑰進行加密 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶檔案服務應為檔案共用啟用軟刪除 microsoft.storage/storageaccounts/fileservices CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶檔案共享應將 SMB 通訊協定版本限制為 SMB 3.1.1 microsoft.storage/storageaccounts/fileservices CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應針對檔案共用使用安全的 SMB 頻道加密演算法 microsoft.storage/storageaccounts/fileservices CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應設定金鑰輪換提醒 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應該停用共用金鑰存取 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應使用私有端點進行存取 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應停用公有網路存取 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶的預設網路存取應設定為拒絕 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
儲存體帳戶應該預設為 Azure 入口網站中的 Microsoft Entra 授權 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應該需要安全傳輸 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應允許受信任的 Azure 服務繞過網路規則 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應設定為所需的最低 TLS 版本 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應停用跨租用戶複寫 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應停用匿名 Blob 存取 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應限制永久 Blob 刪除 microsoft.storage/storageaccounts/blobservices Azure 基礎最佳實務
包含活動日誌的 Azure 儲存體帳戶應使用客戶受管金鑰加密 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶 Blob 服務應該啟用 Blob 軟刪除 microsoft.storage/storageaccounts/blobservices CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶 Blob 服務應該已啟用版本控制 microsoft.storage/storageaccounts/blobservices CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶 Blob 服務應該啟用 Blob 和容器軟刪除 microsoft.storage/storageaccounts/blobservices CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應已套用 Azure Resource Manager 刪除鎖定 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Storage 帳戶應該具有 ReadOnly 資源管理員鎖定 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure 儲存體帳戶應使用地理備援儲存體 microsoft.storage/storageaccounts CIS Microsoft Azure Foundations Benchmark 4.0 版
Azure Function 應用程式應限制管理存取 microsoft.web/sites/config Azure 基礎最佳實務
Azure 函數不應允許匿名 HTTP 觸發叫用 microsoft.web/sites/functions Azure 基礎最佳實務
Azure App Service Web 應用程式和函數應用程式不應使用不支援的執行時間版本 microsoft.web/sites Azure 基礎最佳實務
Premium 或專用計劃上的 Azure Function 應用程式應與虛擬網路整合 microsoft.web/sites Azure 基礎最佳實務
Azure App Service Web 應用程式應在診斷設定中啟用 HTTP 日誌 microsoft.web/sites CIS Microsoft Azure Foundations Benchmark 4.0 版