CIS Snowflake Foundations v1.0.0 L1

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Snowflake Foundations v1.0.0 L1

Updated: 8/7/2026

Authority: CIS

Plugin: Snowflake

Revision: 1.1

Estimated Item Count: 30

File Details

Filename: CIS_Snowflake_Foundations_v1.0.0_L1.audit

Size: 70.9 kB

MD5: d0a4c30f5adc781935dba00093c33b26
SHA256: 369ab10ea0d98c91a3e5401926f0e547fae93f56218bfb10e1d66d8bcf9aaad9

Audit Items

DescriptionCategories
1.1 Ensure single sign-on (SSO) is configured for your account / organization
1.3 Ensure that Snowflake password is unset for SSO users
1.4 Ensure multi-factor authentication (MFA) is turned on for all human users with password-based authentication
1.5 Ensure minimum password length is set to 14 characters or more
1.6 Ensure that service accounts use key pair authentication
1.7 Ensure authentication key pairs are rotated every 180 days
1.8 Ensure that users who did not log in for 90 days are disabled
1.9 Ensure that the idle session timeout is set to 15 minutes or less for users with the ACCOUNTADMIN and SECURITYADMIN roles
1.10 Limit the number of users with ACCOUNTADMIN and SECURITYADMIN
1.11 Ensure that all users granted the ACCOUNTADMIN role have an email address assigned
1.12 Ensure that no users have ACCOUNTADMIN or SECURITYADMIN as the default role
1.13 Ensure that the ACCOUNTADMIN or SECURITYADMIN role is not granted to any custom role
1.14 Ensure that Snowflake tasks are not owned by the ACCOUNTADMIN or SECURITYADMIN roles
1.15 Ensure that Snowflake tasks do not run with the ACCOUNTADMIN or SECURITYADMIN role privileges
1.16 Ensure that Snowflake stored procedures are not owned by the ACCOUNTADMIN or SECURITYADMIN roles
1.17 Ensure Snowflake stored procedures do not run with ACCOUNTADMIN or SECURITYADMIN role privileges
2.1 Ensure monitoring and alerting exist for ACCOUNTADMIN and SECURITYADMIN role grants
2.2 Ensure monitoring and alerting exist for MANAGE GRANTS privilege grants
2.3 Ensure monitoring and alerting exist for password sign-ins of SSO users
2.4 Ensure monitoring and alerting exist for password sign-in without MFA
2.5 Ensure monitoring and alerting exist for creation, update and deletion of security integrations
2.6 Ensure monitoring and alerting exist for changes to network policies and associated objects
2.7 Ensure monitoring and alerting exist for SCIM token creation
2.8 Ensure monitoring and alerting exists for new share exposures
3.2 Ensure that user-level network policies have been configured for service accounts
4.2 Ensure AES encryption key size used to encrypt files stored in internal stages is set to 256 bits
4.5 Ensure that the REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_CREATION account parameter is set to true
4.6 Ensure that the REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_OPERATION account parameter is set to true
4.7 Ensure that all external stages have storage integrations
4.8 Ensure that the PREVENT_UNLOAD_TO_INLINE_URL account parameter is set to true