cis-azure-foundations-9.3.8
Ensure 'Allow Blob Anonymous Access' is set to 'Disabled'
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure 'Allow Blob Anonymous Access' is set to 'Disabled'
Ensure Azure Resource Manager Delete locks are applied to Azure Storage Accounts
Ensure 'Encryption key source' is set to 'Customer Managed Key' for Azure NetApp Files accounts
Ensure that shared access signature (SAS) tokens expire within an hour
Ensure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled
Ensure 'Versioning' is set to 'Enabled' on Azure Blob Storage storage accounts
Ensure locked immutability policies are used for containers storing business-critical blob data
Ensure double encryption is used for Azure Data Box in high-security environments
Ensure customer-managed keys (CMK) are used to encrypt data at rest on Azure Elastic SAN volume groups
Ensure 'Allowed Protocols' for shared access signature (SAS) tokens is set to 'HTTPS Only'