last sync: 2024-Jul-26 18:17:39 UTC

Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption

Azure BuiltIn Policy definition

Source Azure Portal
Display name Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption
Id d461a302-a187-421a-89ac-84acdb4edc04
Version 2.0.0
Details on versioning
Category Compute
Microsoft Learn
Description Requiring a specific set of disk encryption sets to be used with managed disks give you control over the keys used for encryption at rest. You are able to select the allowed encrypted sets and all others are rejected when attached to a disk. Learn more at https://aka.ms/disks-cmk.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
Audit
Allowed
Audit, Deny, Disabled
RBAC role(s) none
Rule aliases IF (12)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.Compute/disks/encryption.diskEncryptionSetId Microsoft.Compute disks properties.encryption.diskEncryptionSetId True True
Microsoft.Compute/disks/managedBy Microsoft.Compute disks managedBy True False
Microsoft.Compute/galleries/images/versions/publishingProfile.targetRegions[*].encryption.dataDiskImages[*].diskEncryptionSetId Microsoft.Compute galleries/images/versions properties.publishingProfile.targetRegions[*].encryption.dataDiskImages[*].diskEncryptionSetId True False
Microsoft.Compute/galleries/images/versions/publishingProfile.targetRegions[*].encryption.osDiskImage.diskEncryptionSetId Microsoft.Compute galleries/images/versions properties.publishingProfile.targetRegions[*].encryption.osDiskImage.diskEncryptionSetId True False
Microsoft.Compute/galleries/images/versions/storageProfile.dataDiskImages[*] Microsoft.Compute galleries/images/versions properties.storageProfile.dataDiskImages[*] True False
Microsoft.Compute/images/storageProfile.dataDisks[*] Microsoft.Compute images properties.storageProfile.dataDisks[*] True False
Microsoft.Compute/images/storageProfile.dataDisks[*].diskEncryptionSet.id Microsoft.Compute images properties.storageProfile.dataDisks[*].diskEncryptionSet.id True False
Microsoft.Compute/images/storageProfile.osDisk.diskEncryptionSet.id Microsoft.Compute images properties.storageProfile.osDisk.diskEncryptionSet.id True False
Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk.diskEncryptionSet.id Microsoft.Compute virtualMachines properties.storageProfile.osDisk.managedDisk.diskEncryptionSet.id True True
Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.dataDisks[*] Microsoft.Compute virtualMachineScaleSets properties.virtualMachineProfile.storageProfile.dataDisks[*] True False
Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.dataDisks[*].managedDisk.diskEncryptionSet.id Microsoft.Compute virtualMachineScaleSets properties.virtualMachineProfile.storageProfile.dataDisks[*].managedDisk.diskEncryptionSet.id True False
Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.osDisk.managedDisk.diskEncryptionSet.id Microsoft.Compute virtualMachineScaleSets properties.virtualMachineProfile.storageProfile.osDisk.managedDisk.diskEncryptionSet.id True False
Rule resource types IF (5)
Microsoft.Compute/disks
Microsoft.Compute/galleries/images/versions
Microsoft.Compute/images
Microsoft.Compute/virtualMachines
Microsoft.Compute/virtualMachineScaleSets
Compliance
The following 3 compliance controls are associated with this Policy definition 'Managed disks should use a specific set of disk encryption sets for the customer-managed key encryption' (d461a302-a187-421a-89ac-84acdb4edc04)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
RBI_ITF_NBFC_v2017 3.1.h RBI_ITF_NBFC_v2017_3.1.h RBI IT Framework 3.1.h Information and Cyber Security Public Key Infrastructure (PKI)-3.1 n/a The IS Policy must provide for a IS framework with the following basic tenets: Public Key Infrastructure (PKI) - NBFCs may increase the usage of PKI to ensure confidentiality of data, access control, data integrity, authentication and nonrepudiation. link 31
RMiT_v1.0 10.53 RMiT_v1.0_10.53 RMiT 10.53 Cloud Services Cloud Services - 10.53 Shared n/a A financial institution must implement appropriate safeguards on customer and counterparty information and proprietary data when using cloud services to protect against unauthorised disclosure and access. This shall include retaining ownership, control and management of all data pertaining to customer and counterparty information, proprietary data and services hosted on the cloud, including the relevant cryptographic keys management. link 14
RMiT_v1.0 11.15 RMiT_v1.0_11.15 RMiT 11.15 Data Loss Prevention (DLP) Data Loss Prevention (DLP) - 11.15 Shared n/a A financial institution must design internal control procedures and implement appropriate technology in all applications and access points to enforce DLP policies and trigger any policy violations. The technology deployed must cover the following: (a) data in-use - data being processed by IT resources; (b) data in-motion - data being transmitted on the network; and (c) data at-rest - data stored in storage mediums such as servers, backup media and databases. link 14
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
[Preview]: Reserve Bank of India - IT Framework for NBFC 7f89f09c-48c1-f28d-1bd5-84f3fb22f86c Regulatory Compliance Preview BuiltIn
RMIT Malaysia 97a6d4f1-3bed-4cf4-ac5b-0e444c0408d6 Regulatory Compliance GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-03-09 14:37:41 change Major (1.0.0 > 2.0.0)
2021-03-02 15:11:40 add d461a302-a187-421a-89ac-84acdb4edc04
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC