Control: Azure Monitor Logs clusters should be encrypted with customer-managed key
Description
Create Azure Monitor logs cluster with customer-managed keys encryption. By default, the log data is encrypted with service-managed keys, but customer-managed keys are commonly required to meet regulatory compliance. Customer-managed key in Azure Monitor gives you more control over the access to you data, see https://docs.microsoft.com/azure/azure-monitor/platform/customer-managed-keys.
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.monitor_log_cluster_encrypted_with_cmk
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.monitor_log_cluster_encrypted_with_cmk --share
SQL
This control uses a named query:
manual_control