ssc-spc-ccoe-cei / azure-guardrails-solution-accelerator

This implementation automates reporting to verify compliance with GC Cloud Guardrails. SSC and TBS review the results. Cette mise en œuvre automatise la production de rapports afin de vérifier la conformité aux mesures de sécurité infonuagique du GC. SPC et SCT examinent les résultats.
Other
7 stars 4 forks source link

GR1 | Validation 6 | Cloud Administrators are using Native Accounts Check (M) #141

Closed MathesonSho closed 1 month ago

MathesonSho commented 2 months ago

ItemName: “Cloud Administrators are using Native Accounts (M)” ItemName FR : « Les administrateurs infonuagiques utilisent des comptes natifs (M) »

Description: This is a new control for the validation “ Provide evidence that there are dedicated user accounts for administration (for example, privileged access)”

Option 1: • If any “highly privileged roles” have been assigned to a guest account or to a synced account the environment would fail this control.

Option 2: • Client provides privileged UPN account list of Cloud Admins and CaC verifies that all of the provided accounts are native.

Comments ENG If Compliant : "All Cloud Administrators are using native accounts." If Non-compliant: "Non-compliant – review cloud administrators assignments and permissions for guest users or synced accounts with privileged roles."

Comments FR If Compliant : « Tous les administrateurs infonuagiques utilisent des comptes natifs. » If Non-compliant: « Non conforme – examinez les affectations et les autorisations des administrateurs infonuagiques pour les utilisateurs invités ou les comptes synchronisés avec des rôles privilégiés. »

MathesonSho commented 1 month ago

After team evaluation this ticket for enhancement has been replaced with https://github.com/ssc-spc-ccoe-cei/azure-guardrails-solution-accelerator/issues/157