Skip to main content

๐Ÿ’ผ 4 Database Services

  • Contextual name: ๐Ÿ’ผ 4 Database Services
  • ID: /frameworks/cis-azure-v1.1.0/04
  • Located in: ๐Ÿ’ผ CIS Azure v1.1.0

Descriptionโ€‹

This section covers security recommendations to follow to set general database services policies on an Azure Subscription. Subsections will address specific database types.

Similarโ€‹

  • Internal
    • ID: dec-b-f24d8b34

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 4.1 Ensure that 'Auditing' is set to 'On'11
๐Ÿ’ผ 4.2 Ensure that 'AuditActionGroups' in 'auditing' policy for a SQL server is set properly
๐Ÿ’ผ 4.3 Ensure that 'Auditing' Retention is 'greater than 90 days'11
๐Ÿ’ผ 4.4 Ensure that 'Advanced Data Security' on a SQL server is set to 'On'
๐Ÿ’ผ 4.5 Ensure that 'Threat Detection types' is set to 'All'
๐Ÿ’ผ 4.6 Ensure that 'Send alerts to' is set
๐Ÿ’ผ 4.7 Ensure that 'Email service and co-administrators' is 'Enabled'
๐Ÿ’ผ 4.8 Ensure that Azure Active Directory Admin is configured11
๐Ÿ’ผ 4.9 Ensure that 'Data encryption' is set to 'On' on a SQL Database
๐Ÿ’ผ 4.10 Ensure SQL server's TDE protector is encrypted with BYOK (Use your own key)11
๐Ÿ’ผ 4.11 Ensure 'Enforce SSL connection' is set to 'ENABLED' for MySQL Database Server11
๐Ÿ’ผ 4.12 Ensure server parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Server11
๐Ÿ’ผ 4.13 Ensure 'Enforce SSL connection' is set to 'ENABLED' for PostgreSQL Database Server11
๐Ÿ’ผ 4.14 Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Server11
๐Ÿ’ผ 4.15 Ensure server parameter 'log_disconnections' is set to 'ON' for PostgreSQL Database Server11
๐Ÿ’ผ 4.16 Ensure server parameter 'log_duration' is set to 'ON' for PostgreSQL Database Server
๐Ÿ’ผ 4.17 Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Server11
๐Ÿ’ผ 4.18 Ensure server parameter 'log_retention_days' is greater than 3 days for PostgreSQL Database Server
๐Ÿ’ผ 4.19 Ensure that Azure Active Directory Admin is configured