last sync: 2024-Dec-05 18:53:22 UTC

App Service apps that use Java should use a specified 'Java version'

Azure BuiltIn Policy definition

Source Azure Portal
Display name App Service apps that use Java should use a specified 'Java version'
Id 496223c3-ad65-4ecd-878a-bae78737e9ed
Version 3.1.0
Details on versioning
Versioning Versions supported for Versioning: 1
3.1.0
Built-in Versioning [Preview]
Category App Service
Microsoft Learn
Description Periodically, newer versions are released for Java software either due to security flaws or to include additional functionality. Using the latest Java version for App Service apps is recommended in order to take advantage of security fixes, if any, and/or new functionalities of the latest version. This policy only applies to Linux apps. This policy requires you to specify a Java version that meets your requirements.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
AuditIfNotExists
Allowed
AuditIfNotExists, Disabled
RBAC role(s) none
Rule aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Web/sites/config/web.linuxFxVersion Microsoft.Web sites/config properties.linuxFxVersion True False
Rule resource types IF (1)
Microsoft.Web/sites
Compliance
The following 7 compliance controls are associated with this Policy definition 'App Service apps that use Java should use a specified 'Java version'' (496223c3-ad65-4ecd-878a-bae78737e9ed)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
C.04.3 - Timelines C.04.3 - Timelines 404 not found n/a n/a 21
C.04.6 - Timelines C.04.6 - Timelines 404 not found n/a n/a 21
C.04.7 - Evaluated C.04.7 - Evaluated 404 not found n/a n/a 40
New_Zealand_ISM 14.5.8.C.01 New_Zealand_ISM_14.5.8.C.01 New_Zealand_ISM_14.5.8.C.01 14. Software security 14.5.8.C.01 Web applications n/a Agencies SHOULD follow the documentation provided in the Open Web Application Security Project guide to building secure Web applications and Web services. 18
NL_BIO_Cloud_Theme C.04.3(2) NL_BIO_Cloud_Theme_C.04.3(2) NL_BIO_Cloud_Theme_C.04.3(2) C.04 Technical Vulnerability Management Technical vulnerabilities n/a The malware protection is carried out on various environments, such as on mail servers, (desktop) computers and when accessing the organization's network. The scan for malware includes: all files received over networks or through any form of storage medium, even before use; all attachments and downloads even before use; virtual machines; network traffic. 22
NL_BIO_Cloud_Theme C.04.6(2) NL_BIO_Cloud_Theme_C.04.6(2) NL_BIO_Cloud_Theme_C.04.6(2) C.04 Technical Vulnerability Management Technical vulnerabilities n/a Technical weaknesses can be remedied by performing patch management in a timely manner, which includes: identifying, registering and acquiring patches; the decision-making around the use of patches; testing patches; performing patches; registering implemented patches. 22
NL_BIO_Cloud_Theme C.04.7(2) NL_BIO_Cloud_Theme_C.04.7(2) NL_BIO_Cloud_Theme_C.04.7(2) C.04 Technical Vulnerability Management Evaluated n/a Evaluations of technical vulnerabilities are recorded and reported. 43
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: Control the use of App Service in a Virtual Enclave 528d78c5-246c-4f26-ade6-d30798705411 VirtualEnclaves Preview BuiltIn
New Zealand ISM 4f5b1359-4f8e-4d7c-9733-ea47fcde891e Regulatory Compliance GA BuiltIn
NL BIO Cloud Theme 6ce73208-883e-490f-a2ac-44aac3b3687f Regulatory Compliance GA BuiltIn
NL BIO Cloud Theme V2 d8b2ffbe-c6a8-4622-965d-4ade11d1d2ee Regulatory Compliance GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2023-05-01 17:41:52 change Minor (3.0.0 > 3.1.0)
2022-07-01 16:32:34 change Major (2.0.0 > 3.0.0)
2020-10-20 13:29:33 change Major (1.0.0 > 2.0.0)
2019-11-12 19:11:12 add 496223c3-ad65-4ecd-878a-bae78737e9ed
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC