| 2.1.1 Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet) | CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.2 Ensure that Network Security Groups are Configured for Databricks Subnets | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.4 Ensure that Users and Groups are Synced from Microsoft Entra ID to Azure Databricks | ACCESS CONTROL |
| 2.1.5 Ensure that Unity Catalog is Configured for Azure Databricks | ACCESS CONTROL |
| 2.1.6 Ensure that Usage is Restricted and Expiry is Enforced for Databricks Personal Access Tokens | ACCESS CONTROL |
| 2.1.7 Ensure that Diagnostic Log Delivery is Configured for Azure Databricks | AUDIT AND ACCOUNTABILITY |
| 2.1.9 Ensure 'No Public IP' is Set to 'Enabled' | ACCESS CONTROL, MEDIA PROTECTION |
| 2.1.10 Ensure 'Allow Public Network Access' is set to 'Disabled' | ACCESS CONTROL, MEDIA PROTECTION |
| 2.1.12 Ensure Azure Databricks groups are reviewed periodically | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.1 Ensure that 'security defaults' is Enabled in Microsoft Entra ID | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.2 Ensure that 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes' | IDENTIFICATION AND AUTHENTICATION |
| 5.1.3 Ensure that 'multifactor authentication' is 'enabled' For All Users | IDENTIFICATION AND AUTHENTICATION |
| 5.1.4 Ensure that 'Allow users to remember multifactor authentication on devices they trust' is Disabled | IDENTIFICATION AND AUTHENTICATION |
| 5.3.1 Ensure that Azure Admin Accounts Are Not Used for Daily Operations | ACCESS CONTROL |
| 5.3.2 Ensure that Guest Users are Reviewed on a Regular Basis | ACCESS CONTROL |
| 5.3.3 Ensure That Use of the 'User Access Administrator' Role is Restricted | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.3.4 Ensure that All 'Privileged' Role Assignments are Periodically Reviewed | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.3.5 Ensure Disabled User Accounts do not Have Read, Write, or Owner Permissions | ACCESS CONTROL |
| 5.3.6 Ensure 'Tenant Creator' Role Assignments are Periodically Reviewed | ACCESS CONTROL |
| 5.3.7 Ensure All Non-privileged Role Assignments are Periodically Reviewed | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.4 Ensure that No Custom Subscription Administrator Roles Exist | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.7 Ensure there are between 2 and 3 Subscription Owners | ACCESS CONTROL |
| 6.1.1.1 Ensure that a 'Diagnostic Setting' Exists for Subscription Activity Logs | AUDIT AND ACCOUNTABILITY |
| 6.1.1.2 Ensure Diagnostic Setting Captures Appropriate Categories | AUDIT AND ACCOUNTABILITY |
| 6.1.1.4 Ensure that Logging for Azure Key Vault is 'Enabled' | AUDIT AND ACCOUNTABILITY |
| 6.1.2.1 Ensure that Activity Log Alert Exists for Create Policy Assignment | AUDIT AND ACCOUNTABILITY |
| 6.1.2.2 Ensure that Activity Log Alert exists for Delete Policy Assignment | AUDIT AND ACCOUNTABILITY |
| 6.1.2.3 Ensure that Activity Log Alert Exists for Create or Update Network Security Group | AUDIT AND ACCOUNTABILITY |
| 6.1.2.4 Ensure that Activity Log Alert Exists for Delete Network Security Group | AUDIT AND ACCOUNTABILITY |
| 6.1.2.5 Ensure that Activity Log Alert Exists for Create or Update Security Solution | AUDIT AND ACCOUNTABILITY |
| 6.1.2.6 Ensure that Activity Log Alert Exists for Delete Security Solution | AUDIT AND ACCOUNTABILITY |
| 6.1.2.7 Ensure that Activity Log Alert Exists for Create or Update SQL Server Firewall Rule | AUDIT AND ACCOUNTABILITY |
| 6.1.2.8 Ensure that Activity Log Alert Exists for Delete SQL Server Firewall Rule | AUDIT AND ACCOUNTABILITY |
| 6.1.2.9 Ensure that Activity Log Alert Exists for Create or Update Public IP Address rule | AUDIT AND ACCOUNTABILITY |
| 6.1.2.10 Ensure that Activity Log Alert Exists for Delete Public IP Address rule | AUDIT AND ACCOUNTABILITY |
| 6.1.2.11 Ensure that an Activity Log Alert Exists for Service Health | AUDIT AND ACCOUNTABILITY |
| 6.1.4 Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support it | AUDIT AND ACCOUNTABILITY |
| 7.1 Ensure that RDP Access from the Internet is Evaluated and Restricted | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.2 Ensure that SSH Access from the Internet is Evaluated and Restricted | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.3 Ensure that UDP Port Access from the Internet is Evaluated and Restricted | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.4 Ensure that HTTP(S) Access from the Internet is Evaluated and Restricted | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.7 Ensure that Public IP Addresses are Evaluated on a Periodic Basis | CONFIGURATION MANAGEMENT |
| 7.11 Ensure Subnets Are Associated with Network Security Groups | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.12 Ensure the SSL Policy's 'Min protocol version' is Set to 'TLSv1_2' or Higher on Azure Application Gateway | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.13 Ensure 'HTTP2' is Set to 'Enabled' on Azure Application Gateway | SYSTEM AND SERVICES ACQUISITION |
| 8.1.10 Ensure that Microsoft Defender for Cloud is Configured to Check VM Operating Systems for Updates | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 8.1.11 Ensure that non-deprecated Microsoft Cloud Security Benchmark policies are not set to 'Disabled' | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 8.1.12 Ensure That 'All users with the following roles' is Set to 'Owner' | INCIDENT RESPONSE |
| 8.1.13 Ensure 'Additional email addresses' is Configured with a Security Contact Email | INCIDENT RESPONSE |
| 8.1.14 Ensure that 'Notify about alerts with the following severity (or higher)' is Enabled | SYSTEM AND INFORMATION INTEGRITY |