last sync: 2023-Jun-09 17:46:13 UTC

Azure Policy definition

Application Insights components should block log ingestion and querying from public networks

Name Application Insights components should block log ingestion and querying from public networks
Azure Portal
Id 1bc02227-0cb6-4e11-8f53-eb0b22eab7e8
Version 1.1.0
details on versioning
Category Monitoring
Microsoft docs
Description Improve Application Insights security by blocking log ingestion and querying from public networks. Only private-link connected networks will be able to ingest and query logs of this component. Learn more at https://aka.ms/AzMonPrivateLink#configure-application-insights.
Mode Indexed
Type BuiltIn
Preview FALSE
Deprecated FALSE
Effect Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
RBAC
Role(s)
none
Rule
Aliases
IF (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Insights/components/publicNetworkAccessForIngestion microsoft.insights components properties.publicNetworkAccessForIngestion true
Microsoft.Insights/components/publicNetworkAccessForQuery microsoft.insights components properties.publicNetworkAccessForQuery true
Rule
ResourceTypes
IF (1)
Microsoft.Insights/components
Compliance The following 2 compliance controls are associated with this Policy definition 'Application Insights components should block log ingestion and querying from public networks' (1bc02227-0cb6-4e11-8f53-eb0b22eab7e8)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
RBI_CSF_Banks_v2016 6.4 RBI_CSF_Banks_v2016_6.4 Application Security Life Cycle (Aslc) Application Security Life Cycle (Aslc)-6.4 n/a Besides business functionalities, security requirements relating to system access control, authentication, transaction authorization, data integrity, system activity logging, audit trail, session management, security event tracking and exception handling are required to be clearly specified at the initial and ongoing stages of system development/acquisition/implementation. 13
RBI_ITF_NBFC_v2017 3.1.g RBI_ITF_NBFC_v2017_3.1.g RBI IT Framework 3.1.g Information and Cyber Security Trails-3.1 n/a The IS Policy must provide for a IS framework with the following basic tenets: Trails- NBFCs shall ensure that audit trails exist for IT assets satisfying its business requirements including regulatory and legal requirements, facilitating audit, serving as forensic evidence when required and assisting in dispute resolution. If an employee, for instance, attempts to access an unauthorized section, this improper activity should be recorded in the audit trail. link 40
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-04-01 20:29:14 change Minor (1.0.0 > 1.1.0)
2021-05-11 14:06:18 add 1bc02227-0cb6-4e11-8f53-eb0b22eab7e8
Initiatives
usage
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: Reserve Bank of India - IT Framework for Banks d0d5578d-cc08-2b22-31e3-f525374f235a Regulatory Compliance Preview BuiltIn
[Preview]: Reserve Bank of India - IT Framework for NBFC 7f89f09c-48c1-f28d-1bd5-84f3fb22f86c Regulatory Compliance Preview BuiltIn
Audit Public Network Access f1535064-3294-48fa-94e2-6e83095a5c08 SDN GA BuiltIn
JSON