3.1.5 Ensure that Unity Catalog is configured for Azure Databricks

Information

Unity Catalog is a centralized governance model for managing and securing data in Azure Databricks. It provides fine-grained access control to databases, tables, and views using Microsoft Entra ID identities. Unity Catalog also enhances data lineage, audit logging, and compliance monitoring, making it a critical component for security and governance.

- Enforces centralized access control policies and reduces data security risks.
- Enables identity-based authentication via Microsoft Entra ID.
- Improves compliance with industry regulations (e.g. GDPR, HIPAA, SOC 2) by providing audit logs and access visibility.
- Prevents unauthorized data access through table-, row-, and column-level security (RLS & CLS).

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use the remediation procedure written in this article:

https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/get-started

.

Impact:

- Improperly configured permissions may lead to data exfiltration or unauthorized access.
- Unity Catalog requires structured governance policies to be effective and prevent overly permissive access.

See Also

https://workbench.cisecurity.org/benchmarks/19304

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(1), 800-53|AC-3, CSCv7|16.2

Plugin: microsoft_azure

Control ID: 070868ac9fc2d50f976e7b855779f21d20e0f1531bdd8938d88df4fd347e1f9b