2.12 Ensure any of the ASC Default policy setting is not set to 'Disabled' - Disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

None of the settings offered by ASC Default policy should be set to effect 'Disabled'.

Rationale:

A security policy defines the desired configuration of your workloads and helps ensure compliance with company or regulatory security requirements. ASC Default policy is associated with every subscription by default. ASC default policy assignment is set of security recommendations based on best practices. Enabling recommendations in ASC default policy ensures that Azure security center provides ability to monitor all of the supported recommendations and allow automated action optionally for few of the supported recommendations.

Solution

From Azure Console

Navigate to Azure Policy

On Policy 'Overview' blade, Click on Policy ASC Default (Subscription:Subscription_ID)

On 'ASC Default' blade, Click on Edit Assignments

In section PARAMETERS, configure the impacted setting to any other available value than Disabled or empty

Click Save

See Also

https://workbench.cisecurity.org/files/3459