Skip to main content

💼 7.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴

Stats​

not available

Description​

Network security groups should be periodically evaluated for port misconfigurations. Where certain ports and protocols may be exposed to the Internet, they should be evaluated for necessity and restricted wherever they are not explicitly required and narrowly configured.

Similar​

  • Sections
    • /frameworks/cis-azure-v2.1.0/06/04
    • /frameworks/cis-azure-v4.0.0/08/04

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS Azure v2.1.0 → 💼 6.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted - Level 1 (Automated)🔴13🔴 x1no data
💼 CIS Azure v4.0.0 → 💼 8.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴3🔴 x1no data

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS Azure v2.1.0 → 💼 6.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted - Level 1 (Automated)🔴13🔴 x1no data
💼 CIS Azure v4.0.0 → 💼 8.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴3🔴 x1no data
💼 CIS Azure v5.0.0 → 💼 7.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴3🔴 x1no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (3)​

PolicyLogic CountFlagsCompliance
🛡️ Azure Network Security Group allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to HTTP(S) ports🟢1🟢 x6no data