turbot/azure_compliance

Control: Saved-queries in Azure Monitor should be saved in customer storage account for logs encryption

Description

Link storage account to Log Analytics workspace to protect saved-queries with storage account encryption. Customer-managed keys are commonly required to meet regulatory compliance and for more control over the access to your saved-queries in Azure Monitor. For more details on the above, see https://docs.microsoft.com/azure/azure-monitor/platform/customer-managed-keys?tabs=portal\#customer-managed-key-for-saved-queries.

Usage

Run the control in your terminal:

powerpipe control run azure_compliance.control.monitor_log_analytics_workspace_integrated_with_encrypted_storage_account

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run azure_compliance.control.monitor_log_analytics_workspace_integrated_with_encrypted_storage_account --share

SQL

This control uses a named query:

manual_control

Tags