Azure Storage Accounts Security Checks
All security checks Aether365 performs for Azure Storage Accounts.
| ID | Title | Severity | Framework |
|---|---|---|---|
| AZURE.183 | Ensure that 'Allow Blob Anonymous Access' is set to 'Disabled' | Medium | CIS Microsoft Azure Foundations |
| AZURE.184 | Ensure 'Cross Tenant Replication' is not enabled | Medium | CIS Microsoft Azure Foundations |
| AZURE.185 | Ensure Default Network Access Rule for Storage Accounts is Set to Deny | Medium | CIS Microsoft Azure Foundations |
| AZURE.186 | Ensure Storage logging is Enabled for Blob Service for 'Read', 'Write', and 'Delete' requests | Medium | CIS Microsoft Azure Foundations |
| AZURE.187 | Ensure Storage Logging is Enabled for Table Service for 'Read', 'Write', and 'Delete' Requests | Medium | CIS Microsoft Azure Foundations |
| AZURE.188 | Ensure Private Endpoints are used to access Storage Accounts | Medium | CIS Microsoft Azure Foundations |
| AZURE.189 | Ensure that Shared Access Signature Tokens Expire Within an Hour | Medium | CIS Microsoft Azure Foundations |
| AZURE.190 | Ensure that storage account access keys are periodically regenerated | Medium | CIS Microsoft Azure Foundations |
| AZURE.191 | Ensure that 'Enable Infrastructure Encryption' for Each Storage Account in Azure Storage is Set to 'enabled' | Medium | CIS Microsoft Azure Foundations |
| AZURE.192 | Ensure that 'Enable key rotation reminders' is enabled for each Storage Account | Medium | CIS Microsoft Azure Foundations |
| AZURE.193 | Ensure storage for critical data are encrypted with Customer Managed Key | Medium | CIS Microsoft Azure Foundations |
| AZURE.194 | Ensure the 'Minimum TLS version' for storage accounts is set to 'Version 1.2' | Medium | CIS Microsoft Azure Foundations |
| AZURE.195 | Ensure that 'Public Network Access' is 'Disabled' for storage accounts | Medium | CIS Microsoft Azure Foundations |
| AZURE.196 | Ensure Storage Logging is Enabled for Queue Service for 'Read', 'Write', and 'Delete' requests | Medium | CIS Microsoft Azure Foundations |
| AZURE.197 | Ensure that 'Secure transfer required' is set to 'Enabled' | Medium | CIS Microsoft Azure Foundations |
| AZURE.198 | Ensure Soft Delete is Enabled for Azure Containers and Blob Storage | Medium | CIS Microsoft Azure Foundations |
| AZURE.199 | Ensure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Access | Medium | CIS Microsoft Azure Foundations |