Skip to main content

πŸ’Ό Data Protection and Recovery

  • Contextual name: πŸ’Ό Data Protection and Recovery
  • ID: /frameworks/cloudaware/resource-security/data-protection-and-recovery
  • Located in: πŸ’Ό Resource Security

Description​

Policies for identifying resources that do not protect data from loss or corruption in case of incidents or malicious attacks.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (10)​

PolicyLogic CountFlags
πŸ“ AWS S3 Bucket MFA Delete is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ AWS S3 Bucket Object Lock is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ AWS S3 Bucket sensitive data is not discovered, classified, and secured 🟒🟒 x3
πŸ“ AWS S3 Bucket Versioning is not enabled 🟒1🟒 x6
πŸ“ Azure Key Vault Soft Delete and Purge Protection functions are not enabled 🟒1🟒 x6
πŸ“ Azure Storage Account Cross Tenant Replication is enabled 🟒1🟒 x6
πŸ“ Azure Storage Blob Containers Soft Delete is not enabled 🟒1🟒 x6
πŸ“ Google BigQuery Sensitive Data Protection is not in use 🟒🟒 x3
πŸ“ Google Cloud SQL Server Instance 3625 (trace flag) Database Flag is not set to on 🟒1🟒 x6
πŸ“ Mission-Critical Azure Resources do not use Resource Locks 🟒🟒 x3