last sync: 2025-Jul-03 17:22:55 UTC

[Deprecated]: Cognitive Services accounts should enable data encryption

Azure BuiltIn Policy definition

Source Azure Portal
Display name [Deprecated]: Cognitive Services accounts should enable data encryption
Id 2bdd0062-9d75-436e-89df-487dd8e4b3c7
Version 2.0.0-deprecated
Details on versioning
Versioning Versions supported for Versioning: 1
2.0.0 (2.0.0-deprecated)
Built-in Versioning [Preview]
Category Cognitive Services
Microsoft Learn
Description This policy is deprecated. Cognitive Services have data encryption enforced.
Cloud environments AzureCloud = true
AzureUSGovernment = unknown
AzureChinaCloud = unknown
Available in AzUSGov Unknown, no evidence if Policy definition is/not available in AzureUSGovernment
Assessment(s) Assessments count: 1
Assessment Id: cdcf4f71-60d3-540b-91e3-aa19792da364
DisplayName: Cognitive Services accounts should enable data encryption
Description: This policy audits any Cognitive Services account not using data encryption. For each Cognitive Services account with storage, should enable data encryption with either customer managed or Microsoft managed key.
Remediation description: To enable encryption for Cognitive Services: 1. In the Azure portal, open Cognitive Services, 2. Select an item from the list, and open the "encryption" page, 3. Setup encryption using either Microsoft-managed keys or customer-managed keys. Learn more about configuration customer-managed keys for Cognitive Services in https://go.microsoft.com/fwlink/?linkid=2121321.
Categories: Data
Severity: Low
preview: True
Mode Indexed
Type BuiltIn
Preview False
Deprecated True
Effect Default
Disabled
Allowed
Audit, Deny, Disabled
RBAC role(s) none
Rule aliases IF (2)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.CognitiveServices/accounts/encryption Microsoft.CognitiveServices accounts properties.encryption True False
Microsoft.CognitiveServices/accounts/encryption.keySource Microsoft.CognitiveServices accounts properties.encryption.keySource True False
Rule resource types IF (1)
Compliance
The following 4 compliance controls are associated with this Policy definition '[Deprecated]: Cognitive Services accounts should enable data encryption' (2bdd0062-9d75-436e-89df-487dd8e4b3c7)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
DORA_2022_2554 9.3b DORA_2022_2554_9.3b DORA 2022 2554 9.3b 9 Minimize Risks of Data Corruption and Loss in ICT Processes Shared n/a Implement information and communication technology (ICT) processes that minimize the risk of data corruption or loss, unauthorized access, and technical flaws that may disrupt business activities. 36
K_ISMS_P_2018 2.10.1 K_ISMS_P_2018_2.10.1 K ISMS P 2018 2.10.1 2.10 Establish Procedures for Managing the Security of System Operations Shared n/a Establish and implement operating procedures for managing the security of system operations such as designating system administrators, updating policies, changing rulesets, monitoring events, managing policy implementations or exceptions. 455
K_ISMS_P_2018 2.10.2 K_ISMS_P_2018_2.10.2 K ISMS P 2018 2.10.2 2.10 Establish Protective Measures for Administrator Privileges and Security Configurations Shared n/a Establish and implement protective measures with regard to administrator privileges and security configurations to ensure that important information and personal information are not exposed as a result of unauthorized access by service type or misconfigurations. 431
K_ISMS_P_2018 2.7.1b K_ISMS_P_2018_2.7.1b K ISMS P 2018 2.7.1b 2.7 Ensure Data is Encrypted at Rest and In-Transit Shared n/a Ensure data is encrypted when storing and transmitting personal and important information. 70
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
DORA 2022 2554 f9c0485f-da8e-43b5-961e-58ebd54b907c Regulatory Compliance GA BuiltIn unknown
K ISMS P 2018 e0782c37-30da-4a78-9f92-50bfe7aa2553 Regulatory Compliance GA BuiltIn unknown
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-04-21 13:28:46 change Major, new suffix: deprecated (1.0.0 > 2.0.0-deprecated)
2020-06-09 16:25:53 add 2bdd0062-9d75-436e-89df-487dd8e4b3c7
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC