last sync: 2024-Jul-26 18:17:39 UTC

Application Insights components should block log ingestion and querying from public networks

Azure BuiltIn Policy definition

Source Azure Portal
Display name Application Insights components should block log ingestion and querying from public networks
Id 1bc02227-0cb6-4e11-8f53-eb0b22eab7e8
Version 1.1.0
Details on versioning
Category Monitoring
Microsoft Learn
Description Improve Application Insights security by blocking log ingestion and querying from public networks. Only private-link connected networks will be able to ingest and query logs of this component. Learn more at https://aka.ms/AzMonPrivateLink#configure-application-insights.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
Audit
Allowed
audit, Audit, deny, Deny, disabled, Disabled
RBAC role(s) none
Rule aliases IF (2)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Insights/components/publicNetworkAccessForIngestion microsoft.insights components properties.publicNetworkAccessForIngestion True True
Microsoft.Insights/components/publicNetworkAccessForQuery microsoft.insights components properties.publicNetworkAccessForQuery True True
Rule resource types IF (1)
Microsoft.Insights/components
Compliance
The following 2 compliance controls are associated with this Policy definition 'Application Insights components should block log ingestion and querying from public networks' (1bc02227-0cb6-4e11-8f53-eb0b22eab7e8)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
RBI_CSF_Banks_v2016 6.4 RBI_CSF_Banks_v2016_6.4 Application Security Life Cycle (Aslc) Application Security Life Cycle (Aslc)-6.4 n/a Besides business functionalities, security requirements relating to system access control, authentication, transaction authorization, data integrity, system activity logging, audit trail, session management, security event tracking and exception handling are required to be clearly specified at the initial and ongoing stages of system development/acquisition/implementation. 13
RBI_ITF_NBFC_v2017 3.1.g RBI_ITF_NBFC_v2017_3.1.g RBI IT Framework 3.1.g Information and Cyber Security Trails-3.1 n/a The IS Policy must provide for a IS framework with the following basic tenets: Trails- NBFCs shall ensure that audit trails exist for IT assets satisfying its business requirements including regulatory and legal requirements, facilitating audit, serving as forensic evidence when required and assisting in dispute resolution. If an employee, for instance, attempts to access an unauthorized section, this improper activity should be recorded in the audit trail. link 37
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: Reserve Bank of India - IT Framework for Banks d0d5578d-cc08-2b22-31e3-f525374f235a Regulatory Compliance Preview BuiltIn
[Preview]: Reserve Bank of India - IT Framework for NBFC 7f89f09c-48c1-f28d-1bd5-84f3fb22f86c Regulatory Compliance Preview BuiltIn
Audit Public Network Access f1535064-3294-48fa-94e2-6e83095a5c08 SDN GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-04-01 20:29:14 change Minor (1.0.0 > 1.1.0)
2021-05-11 14:06:18 add 1bc02227-0cb6-4e11-8f53-eb0b22eab7e8
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC