Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Azure Key Vault - Security Baseline 1.1 - ID 3.10 #7

Open
simonec73 opened this issue Jul 21, 2021 · 0 comments
Open

Azure Key Vault - Security Baseline 1.1 - ID 3.10 #7

simonec73 opened this issue Jul 21, 2021 · 0 comments

Comments

@simonec73
Copy link

Hi, I was reviewing the item discussed in the title. It is entitled "Regularly review and reconcile user access" and essentially covers only group membership and role assignment, which is good when the RBAC model is chosen. I wonder if we should be more explicit by referring to Access Policies (see https://docs.microsoft.com/en-us/azure/key-vault/general/assign-access-policy-portal). In fact, they should be revised as well. Do we have a clear guidance on how to revise them, as we have for Azure AD Roles assignment?
FYI: the specific file where I have found the issue is https://github.com/MicrosoftDocs/SecurityBenchmarks/blob/master/Azure%20Offer%20Security%20Baselines/1.1/key-vault-security-baseline-v1.1.xlsx.
Thanks,
Simone Curzi

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant