Cloudvisory Release Notes 5.1.0

Prev Next

Cloudvisory Security Platform

Software Changes

Highlights

  • Added support for creation of business units at the Azure subscription level.

  • Implemented open text search on Access and Identity Inspector page.

  • Implemented peak workloads and assets for the overall deployment and individual provider types which can be viewed on the dashboard by a user with administrator privileges.

  • Added Provider Type as a new column and as a filter in the Network Object page.

  • Reporting improvements:

    • Improved the compliance report format.

    • Created and updated template report NIST 800-53 r5 for AWS, Azure, and GCP.

    • Created and updated template report PCI DSS for AWS, Azure, and GCP.

    • Added support for AWS CMMC level 3 compliance template report.

  • Migrated compliance AWS and GCP CIS checks to the latest version.

  • Migrated compliance Azure CIS checks to version 1.3.1.

  • Added support for selecting multiple values from the search filter dropdown when creating a new compliance check.

  • Show port information for Kubernetes Service in Visualization properties.

  • Added support for Port Safeguard in Openstack.

  • Added support for Azure network security group (NSG) flow logs v2.

  • Added ability to send a separate email with only the password for newly created user.

  • Added event-based discovery propagators and handlers for new AWS discoveries.

  • Discover new assets for AWS, Azure, and GCP (See New Asset Types Discovered Section below.)

  • Removed Account ID of the S3 bucket(s) from the Add provider screen.

  • Improved performance for filtering by Attached interface/subnet in Azure security group.

Fixed Issues

  • Performance timeout issue in Compliance reports.

  • Appcontrol stops updating workloads, when license limit reached.

  • Compliance groups of sub-accounts are not automatically created during the creation of an Organization account.

  • Asset Inventory: Null Pointer Exception when viewing the VM that doesn't have a name.

  • Calendar issue on Dashboard and Compliance Checks Inspector.

  • Visualization - No network flow for the specific account(s) that a Business Unit admin manages.

  • Terraform checks are added automatically into the cloud compliance group when it is auto created upon adding cloud provider.

  • Network Group creation fails in a high load environment.

  • Business Unit: A BU user could manage his or her own BU.

  • User passwords show as plain text in the logs.

  • Unable to edit GCP provider account.

  • Unable to edit Azure provider account.

  • Edit Azure provider account: 'FlowStorageResourceGroup:' is not a required field when 'Share Access Signature' is checked.

  • Unable to see Public and Private IPs in the Asset Inventory page.

  • Asset Inventory: filter name was called 'VM with Public IP' instead of 'Asset with Public IP'.

  • Unable to discover GCP SQL database instances.

  • Checks Available page: CheckType is always 'Custom Policy' after cloning check from other check types.

  • Risk Score update message did not consider AssetType (just AssetId) - this caused issues with Azure assets that can have the same AssetId for multiple asset types.

Known Issues

  • Compliance Inspector - view check details: Detail are not showing for deleted check.

  • Openstack VMs do not set flag for IP public address.

  • Business Unit admins are able to see recommendations for provider account(s) that they do not manage.

  • Compliance check details: paging issue for results when using open text search.

  • Network security group: paging issue on open text search.

  • Admins who do not have configuration permissions can see the pulldown menu. (UI issue only - they see an empty page if they select a menu option, and therefore cannot update permissions)

  • Recommendations are not supported for microsegmentation in Openstack network policies.

  • AWS/EKS or Azure/AKS K8S are also exported as provider account(s) when exporting an AWS and Azure provider account.

New Asset Types Discovered

AWS

  • AWS Access Analyzer

  • AWS Account Password Policy

  • AWS Athena Workgroup

  • AWS CloudWatch Metric Alarm

  • AWS CloudWatch Log Group

  • AWS Detective Graph

  • AWS EC2 Account Attribute

  • AWS Glue Crawler

  • AWS Guard Duty Detector

  • AWS Guard Duty Finding

  • AWS Macie Job

  • AWS OpenID Connector Provider

  • AWS Organization Tag Policy

  • AWS BackupPolicy

  • AWS iService Opt Out Policy

  • AWS Round Table

  • AWS Server Certificate

  • AWS SAML Provider

  • AWS Stackset

  • AWS Stackset Instance

  • AWS WAF WebACL

  • Added Public Access Block Configuration field to AWS S3 Bucke

Azure

  • Azure Activity Log Alerts

  • Azure Diagnostic Settings

  • Azure Disk encryption set

  • Azure Spring Cloud

  • Azure Spring App

  • Azure Virtual Network

  • Added Server Vulnerability Assessment property for SQL Servers

  • Added Azure defender pricing bundles in Azure Subscriptions

  • Added Data Export Settings and Alert Sync Settings in Azure Subscription

  • Added Data Table Service properties to Azure Storage Account

GCP

  • GCP Bigquery Table

  • Azure Diagnostic Settings

New Compliance Checks

AWS

  • aws-001-013:1.4.0 Ensure there is only one active access key available for any single IAM user

  • aws-001-019:1.4.0 Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed

  • aws-001-020:1.4.0 Ensure that IAM Access analyzer is enabled for all regions

  • aws-001-021:1.4.0 Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments

  • aws-002-101:1.4.0 Ensure all S3 buckets employ encryption-at-rest

  • aws-002-102:1.4.0 Ensure S3 Bucket Policy is set to deny HTTP requests

  • aws-002-103:1.4.0 Ensure MFA Delete is enable on S3 buckets

  • aws-002-104:1.4.0 Ensure all data in Amazon S3 has been discovered, classified and secured when required

  • aws-002-105:1.4.0 Ensure that Amazon S3 Buckets are configured with 'Block public access (bucket settings)

  • aws-002-201:1.4.0 Ensure EBS volume encryption is enabled

  • aws-003-010:1.4.0 Ensure that Object-level logging for write events is enabled for S3 bucket

  • aws-003-011:1.4.0 Ensure that Object-level logging for read events is enabled for S3 bucket

  • aws-004-015:1.4.0 Ensure a log metric filter and alarm exists for AWS Organizations changes

  • aws-005-001:1.4.0 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports

  • aws-005-004:1.4.0 Ensure routing tables for VPC peering are 'least access'

  • aws-200-170:1.0.0 Ensure AWS Guard Duty Detector is enabled

  • aws-200-169:1.0.0 Ensure AWS WAF is used to protect the web application

  • aws-200-171:1.0.0 Ensure that user does not have excessive privileges

Azure

  • azr-200-039:1.1.0 - Maximum number of rules in a network security group

  • azr-004-308:1.3.1 Ensure 'Allow access to Azure services' for PostgreSQL Database Server is disabled

  • azr-004-205:1.3.1 Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server

  • azr-004-201:1.3.1 Ensure that Advanced Threat Protection (ATP) on a SQL server is set to 'Enabled'

  • azr-004-202:1.3.1 Ensure that Vulnerability Assessment (VA) is enabled on a SQL server by setting a Storage Account

  • azr-004-203:1.3.1 Ensure that VA setting Periodic Recurring Scans is enabled on a SQL server

  • azr-004-204:1.3.1 Ensure that VA setting Send scan reports to is configured for a SQL server

  • azr-002-001:1.3.1 Ensure that Azure Defender is set to On for Servers

  • azr-002-002:1.3.1 Ensure that Azure Defender is set to On for App Service

  • azr-002-003:1.3.1 Ensure that Azure Defender is set to On for Azure SQL database servers

  • azr-002-004:1.3.1 Ensure that Azure Defender is set to On for SQL Servers on machines

  • azr-002-005:1.3.1 Ensure that Azure Defender is set to On for Storage

Copyright © 2021 Cloudvisory Documentation, FireEye Inc.

3

  • azr-002-006:1.3.1 Ensure that Azure Defender is set to On for Kubernetes

  • azr-002-007:1.3.1 Ensure that Azure Defender is set to On for Container Registries

  • azr-002-008:1.3.1 Ensure that Azure Defender is set to On for Key Vault

  • azr-002-009:1.3.1 Ensure that Windows Defender ATP (WDATP) integration with Security Center is selected

  • azr-002-010:1.3.1 Ensure that Microsoft Cloud App Security (MCAS) integration with Security Center is selected

  • azr-002-012:1.3.1 Ensure any of the ASC Default policy setting is not set to Disabled

  • azr-002-015:1.3.1 Ensure that 'All users with the following roles' is set to 'Owner'

  • azr-003-008:1.3.1 Ensure soft delete is enabled for Azure Storage

  • azr-003-009:1.3.1 Ensure storage for critical data are encrypted with Customer Managed Key

  • azr-003-010:1.3.1 Ensure Storage logging is enabled for Blob service for read, write, and delete requests

  • azr-003-011:1.3.1 Ensure Storage logging is enabled for Table service for read, write, and delete requests

  • azr-004-205:1.3.1 Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server

  • azr-005-003:1.3.1 Ensure that Diagnostic Logs are enabled for all services which support it

  • azr-005-101:1.3.1 Ensure that a 'Diagnostics Setting' exists

  • azr-005-102:1.3.1 Ensure Diagnostic Setting captures appropriate categories

  • azr-005-202:1.3.1 Ensure that Activity Log Alert exists for Delete Policy Assignment

  • azr-006-006:1.3.1 Ensure that UDP Services are restricted from the Internet

  • azr-007-001:1.3.1 Ensure Virtual Machines are utilizing Managed Disks

  • azr-007-007:1.3.1 Ensure that VHD's are encrypted

  • azr-009-010:1.3.1 Ensure FTP deployments are disabled

  • azr-001-023:1.3.1 Ensure Custom Role is assigned for Administering Resource Locks

GCP

  • gcp-002-012:1.2.0 Ensure that Cloud DNS logging is enabled for all GCP VPC networks

  • gcp-004-011:1.2.0 Ensure that GCP Compute instances have Confidential Computing enabled

  • gcp-006-303:1.2.0 Ensure 'user connections' database flag for GCP Cloud SQL SQL Server instance is set as appropriate

  • gcp-006-304:1.2.0 Ensure 'user options' database flag for GCP Cloud SQL SQL Server instance is not configured

  • gcp-006-305:1.2.0 Ensure 'remote access' database flag for GCP Cloud SQL SQL Server instance is set to 'off'

  • gcp-006-306:1.2.0 Ensure '3625 (trace flag)' database flag for GCP Cloud SQL SQL Server instance is set to 'off'

  • gcp-007-003:1.2.0 Ensure that a Default Customer-managed encryption key (CMEK) is specified for all GCP BigQuery Data Sets

  • gcp-006-207:1.2.0 Ensure 'log_statement' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately

  • gcp-006-208:1.2.0 Ensure 'log_hostname' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately

  • gcp-006-209:1.2.0 Ensure 'log_parser_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-210:1.2.0 Ensure 'log_planner_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-211:1.2.0 Ensure 'log_executor_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-212:1.2.0 Ensure 'log_statement_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'

  • gcp-006-213:1.2.0 Ensure that the 'log_min_messages' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately

  • gcp-006-214:1.2.0 Ensure 'log_min_error_statement' database flag for GCP Cloud SQL PostgreSQL instance is set to 'Error' or stricter

  • gcp-006-102:1.2.0 Ensure 'skip_show_database' database flag for GCP Cloud SQL Mysql instance is set to 'on'

  • gcp-006-202:1.2.0 Ensure 'log_error_verbosity' database flag for GCP Cloud SQL PostgreSQL instance is set to 'DEFAULT' or stricter

  • gcp-006-205:1.2.0 Ensure 'log_duration' database flag for GCP Cloud SQL PostgreSQL instance is set to 'on'

  • gcp-006-301:1.2.0 Ensure 'external scripts enabled' database flag for GCP Cloud SQL SQL Server instance is set to 'off'

  • gcp-007-002:1.2.0 Ensure that all GCP BigQuery Tables are encrypted with Customer-managed encryption key (CMEK)