5.3.7 Ensure all non-privileged role assignments are periodically reviewed

Information

Perform a periodic review of non-privileged role assignments to ensure that the non-privileged roles assigned to users are appropriate.

Note: Determining 'appropriate' assignments requires a clear understanding of your organization's personnel, systems, policies, and security requirements. This cannot be effectively prescribed in a procedure.

To ensure the principle of least privilege is followed, non-privileged role assignments should be reviewed periodically to confirm that users are granted only the minimum level of permissions they need to perform their tasks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remediate from Azure Portal

- Go to Subscriptions.
- Click the name of a subscription.
- Click Access control (IAM).
- Click Role assignments.
- Click Job function roles.
- Check the box next to any inappropriate assignments.
- Click Delete.
- Click Yes.
- Repeat steps 1-8 for each subscription.

Impact:

Increased administrative effort to manage and remove role assignments appropriately.

See Also

https://workbench.cisecurity.org/benchmarks/21611

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4), CSCv7|16.6

Plugin: microsoft_azure

Control ID: 303a8433987314a7fc5e8f4fada7b821d22ee512ee90836a4076754ef6f8b3c0