Azure Storage Services Benchmark

Ensure 'Public network access' is set to 'Disabled' on Azure Elastic SAN
Profile Applicability: Level 2 Description: Azure Elastic SAN is a high-performance, scalable storage solution in Azure. By default, public network a...
Thu, 15 May, 2025 at 3:11 AM
Ensure Private Endpoints Are Used to Access {service}
Profile Applicability:  Level 2 Description:  Private Endpoints enable secure and private connectivity to Azure services by mapping a private IP address fr...
Thu, 15 May, 2025 at 3:13 AM
Ensure 'Key Encryption Key' Is Set to a Customer-Managed Key for Azure Managed Lustre File Systems
Profile Applicability:  Level 2 Description:  Azure Managed Lustre file systems support encryption at rest using Azure Storage Service Encryption. Configur...
Thu, 15 May, 2025 at 3:17 AM
Ensure Soft Delete on Backup Vaults is Enabled
Profile Applicability:  Level 1 Description:  Soft Delete for Azure Backup Vaults ensures that when backup data or recovery points are deleted, they are re...
Thu, 15 May, 2025 at 3:20 AM
Ensure Soft Delete for Blobs on Azure Blob Storage Accounts Is Enabled
Profile Applicability: Level 1 Description:  Soft Delete for blobs in Azure Blob Storage protects against accidental or malicious deletion by retaining ...
Thu, 15 May, 2025 at 3:23 AM
Ensure Immutability for Backup Vaults is Enabled
Profile Applicability:  Level 1 Description:  Immutability for Azure Backup Vaults ensures that backup data cannot be altered or deleted within a specified...
Thu, 15 May, 2025 at 3:24 AM
Ensure Backup Data in Backup Vaults Is Encrypted Using Customer-Managed Keys (CMK)
Profile Applicability:  Level 2 Description:  Encrypting backup data in Azure Backup Vaults with Customer-Managed Keys (CMK) enables organizations to retai...
Thu, 15 May, 2025 at 3:29 AM
Ensure 'Use infrastructure encryption for this vault' is Enabled on Backup Vaults
Profile Applicability:  Level 2 Description:  Infrastructure encryption adds a second layer of encryption to data stored in Azure Backup Vaults, encrypting...
Thu, 15 May, 2025 at 3:33 AM
Ensure 'Cross Region Restore' is Set to 'Enabled' on Backup Vaults
Profile Applicability:  Level 1 Description:  Cross Region Restore (CRR) allows Azure Backup Vaults to restore backup data to a different Azure region than...
Thu, 15 May, 2025 at 3:38 AM
Ensure 'Encryption Key Source' Is Set to 'Customer Managed Key' for Azure NetApp Files Accounts
 Profile Applicability:  Level 2 Description:  Azure NetApp Files supports encryption of data at rest using either Microsoft-managed keys or Customer Ma...
Thu, 15 May, 2025 at 3:40 AM