turbot/steampipe-mod-azure-compliance

Benchmark: 10.2 Azure Blob Storage

Overview

This section covers security best practice recommendations for Azure Blob Storage. Azure Blob Storage is a core storage service type for Azure Storage Accounts. Azure Data Lake services depend on the Azure Blob Service.

NOTE: If your organization is using Shared Access Signature (SAS) tokens, please review the CIS Microsoft Azure Storage Services Benchmark for best practice guidance on the configuration and use of those tokens.

Help us improve this Benchmark! If you notice a needed correction, want to provide feedback, or wish to contribute security best practice guidance please join our community and create a ticket, propose a change, or start a discussion so we can improve this guidance!

The CIS Microsoft Azure Community is here: https://workbench.cisecurity.org/communities/72


Resources for Azure Blob Storage

Azure Product Page:

Azure Blob Storage service overview:

Microsoft Cloud Security Baseline for Storage:

Usage

Install the mod:

mkdir dashboards
cd dashboards
powerpipe mod init
powerpipe mod install github.com/turbot/steampipe-mod-azure-compliance

Start the Powerpipe server:

steampipe service start
powerpipe server

Open http://localhost:9033 in your browser and select 10.2 Azure Blob Storage.

Run this benchmark in your terminal:

powerpipe benchmark run azure_compliance.benchmark.cis_v400_10_2

Snapshot and share results via Turbot Pipes:

powerpipe benchmark run azure_compliance.benchmark.cis_v400_10_2 --share

Controls

Tags