Skip to content

Commit 4156aa4

Browse files
authored
Merge pull request #191377 from georgewallace/policy-regcomp-2022-03-10-5
POLICY: REGCOMP FOR 2022-03-10 - 5
2 parents c20d7c5 + e8e7c2c commit 4156aa4

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

45 files changed

+784
-193
lines changed

articles/governance/policy/samples/pci-dss-3-2-1.md

Lines changed: 348 additions & 0 deletions
Large diffs are not rendered by default.

articles/governance/policy/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,8 @@
116116
href: ./samples/irs-1075-sept2016.md
117117
- name: ISO 27001:2013
118118
href: ./samples/iso-27001.md
119+
- name: PCI DSS 3.2.1
120+
href: ./samples/pci-dss-3-2-1.md
119121
- name: RMIT Malaysia
120122
href: ./samples/rmit-malaysia.md
121123
- name: New Zealand ISM Restricted

includes/policy/standards/byrp/microsoft.containerregistry.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

@@ -47,7 +47,7 @@ To review how the available Azure Policy built-ins for all Azure services map to
4747
standard, see
4848
[Azure Policy Regulatory Compliance - CMMC Level 3](../../../../articles/governance/policy/samples/cmmc-l3.md).
4949
For more information about this compliance standard, see
50-
[Cybersecurity Maturity Model Certification (CMMC)](https://www.acq.osd.mil/cmmc/docs/CMMC_Model_Main_20200203.pdf).
50+
[Cybersecurity Maturity Model Certification (CMMC)](https://www.acq.osd.mil/cmmc/documentation.html).
5151

5252
|Domain |Control ID |Control title |Policy<br /><sub>(Azure portal)</sub> |Policy version<br /><sub>(GitHub)</sub> |
5353
|---|---|---|---|---|

includes/policy/standards/byrp/microsoft.containerservice.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

@@ -23,8 +23,8 @@ standard, see
2323
|Network Security |NS-2 |Secure cloud services with network controls |[Authorized IP ranges should be defined on Kubernetes Services](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2F0e246bcf-5f6f-4f87-bc6f-775d4712c7ea) |[2.0.1](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Security%20Center/ASC_EnableIpRanges_KubernetesService_Audit.json) |
2424
|Privileged Access |PA-7 |Follow just enough administration (least privilege) principle |[Role-Based Access Control (RBAC) should be used on Kubernetes Services](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fac4a19c2-fa67-49b4-8ae5-0b2e78c49457) |[1.0.2](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Security%20Center/ASC_EnableRBAC_KubernetesService_Audit.json) |
2525
|Data Protection |DP-3 |Encrypt sensitive data in transit |[Kubernetes clusters should be accessible only over HTTPS](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2F1a5b4dca-0b6f-4cf5-907c-56316bc1bf3d) |[6.0.1](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/IngressHttpsOnly.json) |
26-
|Logging and Threat Detection |LT-1 |Enable threat detection capabilities |[[Preview]: Azure Kubernetes Service clusters should have Defender profile enabled](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fa1840de2-8088-4ea8-b153-b4c723e9cb01) |[1.0.1-preview](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/ASC_Azure_Defender_Kubernetes_AKS_SecurityProfile_Audit.json) |
27-
|Logging and Threat Detection |LT-2 |Enable threat detection for identity and access management |[[Preview]: Azure Kubernetes Service clusters should have Defender profile enabled](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fa1840de2-8088-4ea8-b153-b4c723e9cb01) |[1.0.1-preview](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/ASC_Azure_Defender_Kubernetes_AKS_SecurityProfile_Audit.json) |
26+
|Logging and Threat Detection |LT-1 |Enable threat detection capabilities |[[Preview]: Azure Kubernetes Service clusters should have Defender profile enabled](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fa1840de2-8088-4ea8-b153-b4c723e9cb01) |[1.0.2-preview](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/ASC_Azure_Defender_Kubernetes_AKS_SecurityProfile_Audit.json) |
27+
|Logging and Threat Detection |LT-2 |Enable threat detection for identity and access management |[[Preview]: Azure Kubernetes Service clusters should have Defender profile enabled](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fa1840de2-8088-4ea8-b153-b4c723e9cb01) |[1.0.2-preview](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/ASC_Azure_Defender_Kubernetes_AKS_SecurityProfile_Audit.json) |
2828
|Posture and Vulnerability Management |PV-2 |Audit and enforce secure configurations |[[Preview]: Kubernetes clusters should gate deployment of vulnerable images](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2F13cd7ae3-5bc0-4ac4-a62d-4f7c120b9759) |[1.0.2-preview](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/BlockVulnerableImages.json) |
2929
|Posture and Vulnerability Management |PV-2 |Audit and enforce secure configurations |[Azure Policy Add-on for Kubernetes service (AKS) should be installed and enabled on your clusters](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2F0a15ec92-a229-4763-bb14-0ea34a568f8d) |[1.0.2](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/AKS_AzurePolicyAddOn_Audit.json) |
3030
|Posture and Vulnerability Management |PV-2 |Audit and enforce secure configurations |[Kubernetes cluster containers CPU and memory resource limits should not exceed the specified limits](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fe345eecc-fa47-480f-9e88-67dcc122b164) |[7.0.1](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/Kubernetes/ContainerResourceLimits.json) |
@@ -92,7 +92,7 @@ To review how the available Azure Policy built-ins for all Azure services map to
9292
standard, see
9393
[Azure Policy Regulatory Compliance - CMMC Level 3](../../../../articles/governance/policy/samples/cmmc-l3.md).
9494
For more information about this compliance standard, see
95-
[Cybersecurity Maturity Model Certification (CMMC)](https://www.acq.osd.mil/cmmc/docs/CMMC_Model_Main_20200203.pdf).
95+
[Cybersecurity Maturity Model Certification (CMMC)](https://www.acq.osd.mil/cmmc/documentation.html).
9696

9797
|Domain |Control ID |Control title |Policy<br /><sub>(Azure portal)</sub> |Policy version<br /><sub>(GitHub)</sub> |
9898
|---|---|---|---|---|

includes/policy/standards/byrp/microsoft.databox.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

@@ -13,7 +13,7 @@ To review how the available Azure Policy built-ins for all Azure services map to
1313
standard, see
1414
[Azure Policy Regulatory Compliance - CMMC Level 3](../../../../articles/governance/policy/samples/cmmc-l3.md).
1515
For more information about this compliance standard, see
16-
[Cybersecurity Maturity Model Certification (CMMC)](https://www.acq.osd.mil/cmmc/docs/CMMC_Model_Main_20200203.pdf).
16+
[Cybersecurity Maturity Model Certification (CMMC)](https://www.acq.osd.mil/cmmc/documentation.html).
1717

1818
|Domain |Control ID |Control title |Policy<br /><sub>(Azure portal)</sub> |Policy version<br /><sub>(GitHub)</sub> |
1919
|---|---|---|---|---|

includes/policy/standards/byrp/microsoft.databoxedge.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

includes/policy/standards/byrp/microsoft.datafactory.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

includes/policy/standards/byrp/microsoft.datalakeanalytics.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

includes/policy/standards/byrp/microsoft.datalakestore.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

includes/policy/standards/byrp/microsoft.dbformariadb.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
---
2-
author: georgewallace
2+
author: timwarner-msft
33
ms.service: azure-policy
44
ms.topic: include
5-
ms.date: 02/15/2022
6-
ms.author: gwallace
5+
ms.date: 03/10/2022
6+
ms.author: timwarner
77
ms.custom: generated
88
---
99

@@ -169,3 +169,4 @@ For more information about this compliance standard, see
169169
|Control Measures on Cybersecurity |RMiT Appendix 5.6 |Control Measures on Cybersecurity - Appendix 5.6 |[MariaDB server should use a virtual network service endpoint](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Fdfbd9a64-6114-48de-a47d-90574dc2e489) |[1.0.2](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/SQL/MariaDB_VirtualNetworkServiceEndpoint_Audit.json) |
170170
|Control Measures on Cybersecurity |RMiT Appendix 5.6 |Control Measures on Cybersecurity - Appendix 5.6 |[Public network access should be disabled for MariaDB servers](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2Ffdccbe47-f3e3-4213-ad5d-ea459b2fa077) |[1.0.2](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/SQL/MariaDB_DisablePublicNetworkAccess_Audit.json) |
171171
|Control Measures on Cybersecurity |RMiT Appendix 5.7 |Control Measures on Cybersecurity - Appendix 5.7 |[Private endpoint should be enabled for MariaDB servers](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2Fproviders%2FMicrosoft.Authorization%2FpolicyDefinitions%2F0a1302fb-a631-4106-9753-f3d494733990) |[1.0.2](https://github.com/Azure/azure-policy/blob/master/built-in-policies/policyDefinitions/SQL/MariaDB_EnablePrivateEndPoint_Audit.json) |
172+

0 commit comments

Comments
 (0)