2.1.12 Ensure Azure Databricks groups are reviewed periodically

Information

Groups are used in Role Based Access Control to apply permissions to users and should be audited.

To ensure accurate privileges for your Azure Databricks implementation, your organization should review all users and permission assignments on a regular interval.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remediate from Azure Portal

- From Azure Home select Azure Databricks.
- Select the Databricks implementation you wish to audit.
- Select Access control (IAM).
- Scroll down and select Add role assignment.
- Search for the role you wish to add. Then select Next.
- Select the group members you wish to add. Then select Next.
- Review the info you have chosen, then select Review + assign.

Impact:

Administrative overhead of user management.

See Also

https://workbench.cisecurity.org/benchmarks/24282

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4)

Plugin: microsoft_azure

Control ID: e0d7e4f0f3a8dd0f0e37d88d866d2af9debfebc797ff4252d3c8e4fef770ad07