Skip to main content

💼 Data Protection and Recovery

  • Contextual name: 💼 Data Protection and Recovery
  • ID: /frameworks/cloudaware/resource-security/data-protection-and-recovery
  • Located in: 💼 Resource Security

Description

Policies for identifying resources that do not protect data from loss or corruption in case of incidents or malicious attacks.

Similar

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (16)

PolicyLogic CountFlags
📝 AWS DynamoDB Table Point In Time Recovery is not enabled 🟢1🟢 x6
📝 AWS S3 Bucket MFA Delete is not enabled 🟠🟢1🟠 x1, 🟢 x6
📝 AWS S3 Bucket Object Lock is not enabled 🟠🟢1🟠 x1, 🟢 x6
📝 AWS S3 Bucket sensitive data is not discovered, classified, and secured 🟢🟢 x3
📝 AWS S3 Bucket Versioning is not enabled 🟢1🟢 x6
📝 Azure Databricks Unity Catalog is not configured 🟢🟢 x3
📝 Azure Key Vault Soft Delete and Purge Protection functions are not enabled 🟢1🟢 x6
📝 Azure Resource Lock is not enabled for mission-critical resources 🟢🟢 x3
📝 Azure Storage Account Blob Service Versioning is not enabled 🟢1🟢 x6
📝 Azure Storage Account Cross Tenant Replication is enabled 🟢1🟢 x6
📝 Azure Storage Account uses Delete lock 🟢🟢 x3
📝 Azure Storage Account uses ReadOnly lock 🟢🟢 x3
📝 Azure Storage Blob Containers Soft Delete is not enabled 🟢1🟢 x6
📝 Azure Storage File Shares Soft Delete is not enabled 🟢1🟢 x6
📝 Google BigQuery Sensitive Data Protection is not in use 🟢🟢 x3
📝 Google Cloud SQL Server Instance 3625 (trace flag) Database Flag is not set to on 🟢1🟢 x6