Benchmark: Incident Handling (IR-4)
Description
The organization implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery; coordinates incident handling activities with contingency planning activities; and incorporates lessons learned from ongoing incident handling activities into incident response procedures, training, and testing/exercises, and implements the resulting changes accordingly.
Usage
Install the mod:
mkdir dashboardscd dashboardspowerpipe mod initpowerpipe mod install github.com/turbot/steampipe-mod-azure-complianceStart the Powerpipe server:
steampipe service startpowerpipe serverOpen http://localhost:9033 in your browser and select Incident Handling (IR-4).
Run this benchmark in your terminal:
powerpipe benchmark run azure_compliance.benchmark.nist_sp_800_53_rev_5_ir_4Snapshot and share results via Turbot Pipes:
powerpipe benchmark run azure_compliance.benchmark.nist_sp_800_53_rev_5_ir_4 --shareControls
- Azure Defender for App Service should be enabled
 - Microsoft Defender for Containers should be enabled
 - Azure Defender for DNS should be enabled
 - Azure Defender for Key Vault should be enabled
 - Azure Defender for Resource Manager should be enabled
 - Azure Defender for servers should be enabled
 - Azure Defender for Azure SQL Database servers should be enabled
 - Azure Defender for SQL should be enabled for unprotected SQL Managed Instances
 - Microsoft Defender for Storage (Classic) should be enabled
 - Subscriptions should have a contact email address for security issues
 - Email notification for high severity alerts should be enabled
 - Email notification to subscription owner for high severity alerts should be enabled
 - Azure Defender for SQL should be enabled for unprotected Azure SQL servers