Skip to content

Commit b9ec780

Browse files
committed
Update for SQL policy change
1 parent f50cad8 commit b9ec780

File tree

5 files changed

+16
-16
lines changed

5 files changed

+16
-16
lines changed

articles/governance/blueprints/samples/iso27001-ase-sql-workload/control-mapping.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -172,13 +172,13 @@ unencrypted Service Fabric communication.
172172
- \[Preview\]: Deploy VM extension to audit Windows VM should not store passwords using reversible
173173
encryption
174174
- \[Preview\]: Audit Windows VM should not store passwords using reversible encryption
175-
- \[Preview\]: Monitor unencrypted SQL database in Azure Security Center
176175
- \[Preview\]: Monitor unencrypted VM Disks in Azure Security Center
177176
- Audit enablement of encryption of Automation account variables
178177
- Audit enabling of only secure connections to your Redis Cache
179178
- Audit secure transfer to storage accounts
180179
- Audit the setting of ClusterProtectionLevel property to EncryptAndSign in Service Fabric
181180
- Audit transparent data encryption status
181+
- Transparent Data Encryption on SQL databases should be enabled
182182

183183
## A.12.4.1 Event logging
184184

@@ -190,9 +190,9 @@ Diagnostic logs provide insight into operations that were performed within Azure
190190
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
191191
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
192192
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
193-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
194193
- Audit diagnostic setting
195194
- Audit SQL server level Auditing settings
195+
- Auditing should be enabled on advanced data security settings on SQL Server
196196

197197
## A.12.4.3 Administrator and operator logs
198198

@@ -204,9 +204,9 @@ operations that were performed within Azure resources.
204204
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
205205
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
206206
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
207-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
208207
- Audit diagnostic setting
209208
- Audit SQL server level Auditing settings
209+
- Auditing should be enabled on advanced data security settings on SQL Server
210210

211211
## A.12.4.4 Clock synchronization
212212

@@ -218,9 +218,9 @@ internal clocks to create a time-correlated record of events across resources.
218218
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
219219
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
220220
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
221-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
222221
- Audit diagnostic setting
223222
- Audit SQL server level Auditing settings
223+
- Auditing should be enabled on advanced data security settings on SQL Server
224224

225225
## A.12.5.1 Installation of software on operational systems
226226

articles/governance/blueprints/samples/iso27001-shared/control-mapping.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -172,13 +172,13 @@ unencrypted Service Fabric communication.
172172
- \[Preview\]: Deploy VM extension to audit Windows VM should not store passwords using reversible
173173
encryption
174174
- \[Preview\]: Audit Windows VM should not store passwords using reversible encryption
175-
- \[Preview\]: Monitor unencrypted SQL database in Azure Security Center
176175
- \[Preview\]: Monitor unencrypted VM Disks in Azure Security Center
177176
- Audit enablement of encryption of Automation account variables
178177
- Audit enabling of only secure connections to your Redis Cache
179178
- Audit secure transfer to storage accounts
180179
- Audit the setting of ClusterProtectionLevel property to EncryptAndSign in Service Fabric
181180
- Audit transparent data encryption status
181+
- Transparent Data Encryption on SQL databases should be enabled
182182

183183
## A.12.4.1 Event logging
184184

@@ -190,9 +190,9 @@ Diagnostic logs provide insight into operations that were performed within Azure
190190
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
191191
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
192192
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
193-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
194193
- Audit diagnostic setting
195194
- Audit SQL server level Auditing settings
195+
- Auditing should be enabled on advanced data security settings on SQL Server
196196

197197
## A.12.4.3 Administrator and operator logs
198198

@@ -204,9 +204,9 @@ operations that were performed within Azure resources.
204204
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
205205
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
206206
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
207-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
208207
- Audit diagnostic setting
209208
- Audit SQL server level Auditing settings
209+
- Auditing should be enabled on advanced data security settings on SQL Server
210210

211211
## A.12.4.4 Clock synchronization
212212

@@ -218,9 +218,9 @@ internal clocks to create a time-correlated record of events across resources.
218218
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
219219
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
220220
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
221-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
222221
- Audit diagnostic setting
223222
- Audit SQL server level Auditing settings
223+
- Auditing should be enabled on advanced data security settings on SQL Server
224224

225225
## A.12.5.1 Installation of software on operational systems
226226

articles/governance/blueprints/samples/iso27001/control-mapping.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -172,13 +172,13 @@ unencrypted Service Fabric communication.
172172
- \[Preview\]: Deploy VM extension to audit Windows VM should not store passwords using reversible
173173
encryption
174174
- \[Preview\]: Audit Windows VM should not store passwords using reversible encryption
175-
- \[Preview\]: Monitor unencrypted SQL database in Azure Security Center
176175
- \[Preview\]: Monitor unencrypted VM Disks in Azure Security Center
177176
- Audit enablement of encryption of Automation account variables
178177
- Audit enabling of only secure connections to your Redis Cache
179178
- Audit secure transfer to storage accounts
180179
- Audit the setting of ClusterProtectionLevel property to EncryptAndSign in Service Fabric
181180
- Audit transparent data encryption status
181+
- Transparent Data Encryption on SQL databases should be enabled
182182

183183
## A.12.4.1 Event logging
184184

@@ -190,9 +190,9 @@ Diagnostic logs provide insight into operations that were performed within Azure
190190
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
191191
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
192192
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
193-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
194193
- Audit diagnostic setting
195194
- Audit SQL server level Auditing settings
195+
- Auditing should be enabled on advanced data security settings on SQL Server
196196

197197
## A.12.4.3 Administrator and operator logs
198198

@@ -204,9 +204,9 @@ operations that were performed within Azure resources.
204204
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
205205
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
206206
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
207-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
208207
- Audit diagnostic setting
209208
- Audit SQL server level Auditing settings
209+
- Auditing should be enabled on advanced data security settings on SQL Server
210210

211211
## A.12.4.4 Clock synchronization
212212

@@ -218,9 +218,9 @@ internal clocks to create a time-correlated record of events across resources.
218218
- \[Preview\]: Audit Dependency Agent Deployment in VMSS - VM Image (OS) unlisted
219219
- \[Preview\]: Audit Log Analytics Agent Deployment - VM Image (OS) unlisted
220220
- \[Preview\]: Audit Log Analytics Agent Deployment in VMSS - VM Image (OS) unlisted
221-
- \[Preview\]: Monitor unaudited SQL database in Azure Security Center
222221
- Audit diagnostic setting
223222
- Audit SQL server level Auditing settings
223+
- Auditing should be enabled on advanced data security settings on SQL Server
224224

225225
## A.12.5.1 Installation of software on operational systems
226226

articles/governance/blueprints/samples/pci-dss-3.2.1/control-mapping.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ Fabric communication.
4848
- Function App should only be accessible over HTTPS
4949
- Web Application should only be accessible over HTTPS
5050
- API App should only be accessible over HTTPS
51-
- Monitor unencrypted SQL database in Azure Security Center
51+
- Transparent Data Encryption on SQL databases should be enabled
5252
- Disk encryption should be applied on virtual machines
5353
- Automation account variables should be encrypted
5454
- Only secure connections to your Redis Cache should be enabled
@@ -156,7 +156,7 @@ Diagnostic logs provide insight into operations that were performed within Azure
156156
logs rely on synchronized internal clocks to create a time-correlated record of events across
157157
resources.
158158

159-
- Monitor unaudited SQL servers in Azure Security Center
159+
- Auditing should be enabled on advanced data security settings on SQL Server
160160
- Audit diagnostic setting
161161
- Audit SQL server level Auditing settings
162162
- Deploy Auditing on SQL servers

articles/governance/blueprints/samples/ukofficial/control-mapping.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ encryption on storage accounts, SQL databases, virtual machine disks, and automa
4141
variables; audit insecure connections to storage accounts and Redis Cache; audit weak virtual
4242
machine password encryption; and audit unencrypted Service Fabric communication.
4343

44-
- Monitor unencrypted SQL databases in Azure Security Center
44+
- Transparent Data Encryption on SQL databases should be enabled
4545
- Disk encryption should be applied on virtual machines
4646
- Automation account variables should be encrypted
4747
- Secure transfer to storage accounts should be enabled
@@ -208,7 +208,7 @@ This blueprint helps you ensure system events are logged by assigning [Azure Pol
208208
definitions that audit log settings on Azure resources. An assigned policy also audits if virtual
209209
machines aren't sending logs to a specified log analytics workspace.
210210

211-
- Monitor unaudited SQL servers in Azure Security Center
211+
- Auditing should be enabled on advanced data security settings on SQL Server
212212
- Audit diagnostic setting
213213
- Audit SQL server level Auditing settings
214214
- \[Preview\]: Deploy Log Analytics Agent for Linux VMs

0 commit comments

Comments
 (0)