Skip to content

Azure Key Vault - Security Baseline 1.1 - ID 3.10 #7

Description

@simonec73

Hi, I was reviewing the item discussed in the title. It is entitled "Regularly review and reconcile user access" and essentially covers only group membership and role assignment, which is good when the RBAC model is chosen. I wonder if we should be more explicit by referring to Access Policies (see https://docs.microsoft.com/en-us/azure/key-vault/general/assign-access-policy-portal). In fact, they should be revised as well. Do we have a clear guidance on how to revise them, as we have for Azure AD Roles assignment?
FYI: the specific file where I have found the issue is https://github.com/MicrosoftDocs/SecurityBenchmarks/blob/master/Azure%20Offer%20Security%20Baselines/1.1/key-vault-security-baseline-v1.1.xlsx.
Thanks,
Simone Curzi

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions