--- names: full: "Azure VM Scale Set Instance allows public access to all ports" contextual: "Instance allows public access to all ports" description: > Identify Azure VM Scale Set Instances that are associated with Network Interfaces linked to NSGs containing inbound rules that allow unrestricted traffic from the public internet(0.0.0.0/0, ::/0, Internet, Any, or *) to all destination ports (*, 0-65535, or unspecified). Restrict access to only the specific destination port and/or IP address ranges that require connectivity. categories: - "SECURITY" type: "COMPLIANCE_POLICY" frameworkMappings: - "/frameworks/iso-iec-27001-2013/09/01/02" - "/frameworks/pci-dss-v4.0.1/01/02/01" - "/frameworks/pci-dss-v4.0.1/01/02/05" - "/frameworks/pci-dss-v4.0.1/01/02/06" - "/frameworks/pci-dss-v4.0.1/01/03/01" - "/frameworks/pci-dss-v4.0.1/01/03/02" - "/frameworks/cloudaware/resource-security/network-exposure" similarPolicies: internal: - dec-x-06394dfa