--- names: full: Azure Network Security Group allows public access to DNS port contextual: Security Group allows allows public access to DNS port description: > Ensure that Azure Network Security Groups do not allow unrestricted public access to the DNS port 53. Exposing DNS to the internet from a VM can pose security risks, such as participation in DNS amplification attacks or unauthorized DNS resolution. type: COMPLIANCE_POLICY categories: - SECURITY frameworkMappings: - "/frameworks/iso-iec-27001-2013/13/01/01" - "/frameworks/pci-dss-v4.0.1/01/03/01" - "/frameworks/pci-dss-v4.0.1/01/03/02" - "/frameworks/cloudaware/resource-security/network-exposure" - "/frameworks/iso-iec-27001-2013/09/01/02" - "/frameworks/soc-2/cc6/01/07" - "/frameworks/soc-2/cc6/06/01" similarPolicies: internal: - dec-x-b56086e7