Skip to main content

๐Ÿ’ผ 3 Storage Accounts

  • Contextual name: ๐Ÿ’ผ 3 Storage Accounts
  • ID: /frameworks/cis-azure-v1.1.0/03
  • Located in: ๐Ÿ’ผ CIS Azure v1.1.0

Descriptionโ€‹

This section covers security recommendations to follow to set storage account policies on an Azure Subscription. An Azure storage account provides a unique namespace to store and access Azure Storage data objects.

Similarโ€‹

  • Internal
    • ID: dec-b-f53c0b05

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 3.1 Ensure that 'Secure transfer required' is set to 'Enabled'11
๐Ÿ’ผ 3.2 Ensure that storage account access keys are periodically regenerated
๐Ÿ’ผ 3.3 Ensure Storage logging is enabled for Queue service for read, write, and delete requests11
๐Ÿ’ผ 3.4 Ensure that shared access signature tokens expire within an hour
๐Ÿ’ผ 3.5 Ensure that shared access signature tokens are allowed only over https
๐Ÿ’ผ 3.6 Ensure that 'Public access level' is set to Private for blob containers11
๐Ÿ’ผ 3.7 Ensure default network access rule for Storage Accounts is set to deny
๐Ÿ’ผ 3.8 Ensure 'Trusted Microsoft Services' is enabled for Storage Account access11