Skip to content

Commit

Permalink
upd: added comment for all policies
Browse files Browse the repository at this point in the history
  • Loading branch information
Vit-ts committed Aug 30, 2023
1 parent f0681ba commit fb068b2
Show file tree
Hide file tree
Showing 259 changed files with 259 additions and 0 deletions.
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-005-cis_sec_email.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: value
key: properties.emails
value: ""
comment: '0216181500'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
key: properties.alertNotifications
value: "Off"
op: eq
comment: '0216181500'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
key: properties.alertsToAdmins
value: "Off"
op: eq
comment: '0216181500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-011-cis_sa_soft_del.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,4 @@ policies:
- key: delete_retention_policy.enabled
op: eq
value: false
comment: '0249041500'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
key: properties.state
op: ne
value: Enabled
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,4 @@ policies:
op: eq
value_type: integer
value: 0
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: sql-server-security-alert-policies
key: state
value: Disabled
comment: '0232061500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-020-cis_db_sql_va.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: vulnerability-assessments
property: storageContainerPath
value: null
comment: '0216061500'
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,4 @@ policies:
- type: vulnerability-assessments
property: recurringScans.isEnabled
value: false
comment: '0216061500'
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,4 @@ policies:
- type: vulnerability-assessments
property: recurringScans.emails
value: []
comment: '0216061500'
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,4 @@ policies:
- type: vulnerability-assessments
property: recurringScans.emailSubscriptionAdmins
value: false
comment: '0216061500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-025-cis_db_mysql_ssl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.sslEnforcement
value: Disabled
comment: '0244061500'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: server-configuration
property: log_checkpoints
value: "OFF"
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: server-configuration
property: log_connections
value: "OFF"
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: server-configuration
property: log_disconnections
value: "OFF"
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: server-configuration
property: connection_throttling
value: "OFF"
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
property: log_retention_days
value: 4
op: lt
comment: '0219061500'
Original file line number Diff line number Diff line change
Expand Up @@ -23,3 +23,4 @@ policies:
key: uri
value: null
op: eq
comment: '0243061500'
Original file line number Diff line number Diff line change
Expand Up @@ -18,3 +18,4 @@ policies:
key: properties.publicAccess
value: Container
- storage-single-log-profile
comment: '0240011500'
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,4 @@ policies:
value: null
- and:
- single-log-profile
comment: '0243011500'
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,4 @@ policies:
- type: diagnostic-settings
key: length(logs[?category == 'AuditEvent' && enabled == `true` && retention_policy.days > `0` && retention_policy.enabled == `true`])
value: 0
comment: '0219101500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0216011500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-043-cis_log_del_nsg.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-048-cis_net_rdp.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '3389'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242021500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-049-cis_net_ssh.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '22'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242021500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-052-cis_net_udp.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,4 @@ policies:
access: 'Allow'
ipProtocol: 'UDP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242021500'
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,4 @@ policies:
key: properties.enablePurgeProtection
value: true
op: ne
comment: '0249101500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-059-cis_app_auth_set.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.enabled
value: false
comment: '0233171500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0232011500'
Original file line number Diff line number Diff line change
Expand Up @@ -24,3 +24,4 @@ policies:
key: alerts[].scopes[]
value: ^\/[a-z]{13}\/[a-z0-9A-Z]{8}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{4}\-[a-z0-9A-Z]{12}$
op: regex
comment: '0216011500'
Original file line number Diff line number Diff line change
Expand Up @@ -26,3 +26,4 @@ policies:
value: Succeeded
- key: status.value
value: Succeeded
comment: '0229041500'
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,4 @@ policies:
- key: logging.delete
value: false
op: eq
comment: '0219041400'
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,4 @@ policies:
- key: logging.delete
value: false
op: eq
comment: '0219041500'
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,4 @@ policies:
- key: logging.delete
value: false
op: eq
comment: '0219041500'
Original file line number Diff line number Diff line change
Expand Up @@ -18,3 +18,4 @@ policies:
- type: firewall-rules
include:
- '0.0.0.0'
comment: '0233061500'
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,4 @@ policies:
Network Watcher is disabled across the subscription
filters:
- type: network-watcher-filter
comment: '0216021500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-119-nsg_all.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '0-65535'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-120-nsg_dns.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '53'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-121-nsg_ftp.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '21'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-122-cis_nsg_http.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '80'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242021500'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-123-nsg_microsoft_ds.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '445'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-124-nsg_mongo_db.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '27017'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-125-nsg_mysql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '3306'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-126-nsg_netbios.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '139'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-127-nsg_oracle_db.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '1521'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-128-nsg_pop3.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '110'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-129-nsg_postgresql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '5432'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-130-nsg_smtp.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '25'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-131-nsg_telnet.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,3 +16,4 @@ policies:
ports: '23'
ipProtocol: 'TCP'
sourceAddress: ['*', 'Internet', '0.0.0.0/0']
comment: '0242022000'
1 change: 1 addition & 0 deletions non-compatible-policies/ecc-azure-139-snapshots.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
- type: snapshots
exist: true
max-age: 14
comment: '0249032000'
Original file line number Diff line number Diff line change
Expand Up @@ -23,3 +23,4 @@ policies:
- type: value
key: properties.subnets[?name=='AzureFirewallSubnet'].id
value: empty
comment: '0224020000'
Original file line number Diff line number Diff line change
Expand Up @@ -25,3 +25,4 @@ policies:
key: properties.networkInterfaces[].id
value: \/subscriptions.+\/networkInterfaces\/.+
op: regex
comment: '0242020000'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
- type: value
key: properties.networkAcls.defaultAction
value: Deny
comment: '0240100000'
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,4 @@ policies:
resource: azure.vm
filters:
- type: security-jit-policy
comment: '0224030000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.publicNetworkAccess
value: Enabled
comment: '0240060000'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: value
key: properties.publicNetworkAccess
value: null
comment: '0240060000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.privateEndpointConnections
value: absent
comment: '0240020000'
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,4 @@ policies:
key: properties.privateEndpointConnections[].properties.privateLinkServiceConnectionState.status
value: Approved
op: contains
comment: '0240020000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.privateEndpointConnections
value: absent
comment: '0240020000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.privateEndpointConnections
value: absent
comment: '0240110000'
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,4 @@ policies:
key: properties.privateEndpointConnections[].properties.privateLinkServiceConnectionState.status
value: Approved
op: contains
comment: '0240020000'
Original file line number Diff line number Diff line change
Expand Up @@ -18,3 +18,4 @@ policies:
key: properties.networkProfile.serviceRuntimeSubnetId
value: \/.+\/virtualNetworks\/.+\/subnets\/.+
op: regex
comment: '0224020000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: length(properties.privateEndpointConnections)
value: 0
comment: '0240080000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: value
key: properties.privateEndpointConnections
value: absent
comment: '0240100000'
Original file line number Diff line number Diff line change
Expand Up @@ -22,3 +22,4 @@ policies:
key: properties.privateEndpointConnections[].properties.privateLinkServiceConnectionState.status
value: Approved
op: contains
comment: '0240060000'
Original file line number Diff line number Diff line change
Expand Up @@ -22,3 +22,4 @@ policies:
key: properties.privateEndpointConnections[].properties.privateLinkServiceConnectionState.status
value: Approved
op: contains
comment: '0240060000'
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,4 @@ policies:
key: properties.ddosProtectionPlan.id
value: \/.+\/ddosProtectionPlans\/.+
op: regex
comment: '0232020000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: managed-server-security-alert-policies
key: state
value: Disabled
comment: '0232060000'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
key: is_encrypted
value: false
op: eq
comment: '0243090000'
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,4 @@ policies:
- type: value
key: properties.encryption.status
value: Enabled
comment: '0243090000'
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ policies:
- type: encryption-protector
key: kind
value: servicemanaged
comment: '0243060000'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: diagnostic-settings
key: length(logs[?(category == 'Audit' || category == 'Requests') && enabled == `true` && retention_policy.enabled == `true` && retention_policy.days > `0`])
value: 0
comment: '0219010000'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: diagnostic-settings
key: length(logs[?(category == 'Execution' || category == 'Authoring') && enabled == `true` && retention_policy.enabled == `true` && retention_policy.days > `0`])
value: 0
comment: '0219010000'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: diagnostic-settings
key: length(logs[?category == 'ServiceLog' && enabled == `true` && retention_policy.enabled == `true` && retention_policy.days > `0`])
value: 0
comment: '0219010000'
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,4 @@ policies:
- type: diagnostic-settings
key: length(logs[?(category == 'Audit' || category == 'Requests') && enabled == `true` && retention_policy.enabled == `true` && retention_policy.days > `0`])
value: 0
comment: '0219010000'
Loading

0 comments on commit fb068b2

Please sign in to comment.