Skip to main content

πŸ’Ό Data Protection and Recovery

  • Contextual name: πŸ’Ό Data Protection and Recovery
  • ID: /frameworks/cloudaware/resource-security/data-protection-and-recovery
  • Located in: πŸ’Ό Resource Security

Description​

Policies for identifying resources that do not protect data from loss or corruption in case of incidents or malicious attacks.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (16)​

PolicyLogic CountFlags
πŸ“ AWS DynamoDB Table Point In Time Recovery is not enabled 🟒1🟒 x6
πŸ“ AWS S3 Bucket MFA Delete is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ AWS S3 Bucket Object Lock is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ AWS S3 Bucket sensitive data is not discovered, classified, and secured 🟒🟒 x3
πŸ“ AWS S3 Bucket Versioning is not enabled 🟒1🟒 x6
πŸ“ Azure Databricks Unity Catalog is not configured 🟒🟒 x3
πŸ“ Azure Key Vault Soft Delete and Purge Protection functions are not enabled 🟒1🟒 x6
πŸ“ Azure Resource Lock is not enabled for mission-critical resources 🟒🟒 x3
πŸ“ Azure Storage Account Blob Service Versioning is not enabled 🟒1🟒 x6
πŸ“ Azure Storage Account Cross Tenant Replication is enabled 🟒1🟒 x6
πŸ“ Azure Storage Account uses Delete lock 🟒🟒 x3
πŸ“ Azure Storage Account uses ReadOnly lock 🟒🟒 x3
πŸ“ Azure Storage Blob Containers Soft Delete is not enabled 🟒1🟒 x6
πŸ“ Azure Storage File Shares Soft Delete is not enabled 🟒1🟒 x6
πŸ“ Google BigQuery Sensitive Data Protection is not in use 🟒🟒 x3
πŸ“ Google Cloud SQL Server Instance 3625 (trace flag) Database Flag is not set to on 🟒1🟒 x6