Skip to content

Azure Key Vault - Security Baseline 1.1 - ID 3.10 #7

@simonec73

Description

@simonec73

Hi, I was reviewing the item discussed in the title. It is entitled "Regularly review and reconcile user access" and essentially covers only group membership and role assignment, which is good when the RBAC model is chosen. I wonder if we should be more explicit by referring to Access Policies (see https://docs.microsoft.com/en-us/azure/key-vault/general/assign-access-policy-portal). In fact, they should be revised as well. Do we have a clear guidance on how to revise them, as we have for Azure AD Roles assignment?
FYI: the specific file where I have found the issue is https://github.com/MicrosoftDocs/SecurityBenchmarks/blob/master/Azure%20Offer%20Security%20Baselines/1.1/key-vault-security-baseline-v1.1.xlsx.
Thanks,
Simone Curzi

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions