Skip to main content

💼 7.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴

Stats​

not available

Description​

Network security groups should be periodically evaluated for port misconfigurations. Where HTTP(S) is not explicitly required and narrowly configured for resources attached to a network security group, Internet-level access to Azure resources should be restricted or eliminated.

Similar​

  • Sections
    • /frameworks/cis-azure-v3.0.0/07/04
    • /frameworks/cis-azure-v4.0.0/08/04
    • /frameworks/cis-azure-v6.0.0/07/04

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS Azure v3.0.0 → 💼 7.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴3🔴 x1no data
💼 CIS Azure v4.0.0 → 💼 8.4 Ensure that HTTP(S) access from the Internet is evaluated and restricted (Automated)🔴3🔴 x1no data
💼 CIS Azure v6.0.0 → 💼 7.4 Ensure that HTTP(S) Access from the Internet is Evaluated and Restricted (Automated)🔴3🔴 x1no data

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS Azure v6.0.0 → 💼 7.4 Ensure that HTTP(S) Access from the Internet is Evaluated and Restricted (Automated)🔴3🔴 x1no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (3)​

PolicyLogic CountFlagsCompliance
🛡️ Azure Network Security Group allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to HTTP(S) ports🟢1🟢 x6no data