Cloudvisory Security Platform
Software Changes
Highlights
Added support for creation of business units at the Azure subscription level.
Implemented open text search on Access and Identity Inspector page.
Implemented peak workloads and assets for the overall deployment and individual provider types which can be viewed on the dashboard by a user with administrator privileges.
Added Provider Type as a new column and as a filter in the Network Object page.
Reporting improvements:
Improved the compliance report format.
Created and updated template report NIST 800-53 r5 for AWS, Azure, and GCP.
Created and updated template report PCI DSS for AWS, Azure, and GCP.
Added support for AWS CMMC level 3 compliance template report.
Migrated compliance AWS and GCP CIS checks to the latest version.
Migrated compliance Azure CIS checks to version 1.3.1.
Added support for selecting multiple values from the search filter dropdown when creating a new compliance check.
Show port information for Kubernetes Service in Visualization properties.
Added support for Port Safeguard in Openstack.
Added support for Azure network security group (NSG) flow logs v2.
Added ability to send a separate email with only the password for newly created user.
Added event-based discovery propagators and handlers for new AWS discoveries.
Discover new assets for AWS, Azure, and GCP (See New Asset Types Discovered Section below.)
Removed Account ID of the S3 bucket(s) from the Add provider screen.
Improved performance for filtering by Attached interface/subnet in Azure security group.
Fixed Issues
Performance timeout issue in Compliance reports.
Appcontrol stops updating workloads, when license limit reached.
Compliance groups of sub-accounts are not automatically created during the creation of an Organization account.
Asset Inventory: Null Pointer Exception when viewing the VM that doesn't have a name.
Calendar issue on Dashboard and Compliance Checks Inspector.
Visualization - No network flow for the specific account(s) that a Business Unit admin manages.
Terraform checks are added automatically into the cloud compliance group when it is auto created upon adding cloud provider.
Network Group creation fails in a high load environment.
Business Unit: A BU user could manage his or her own BU.
User passwords show as plain text in the logs.
Unable to edit GCP provider account.
Unable to edit Azure provider account.
Edit Azure provider account: 'FlowStorageResourceGroup:' is not a required field when 'Share Access Signature' is checked.
Unable to see Public and Private IPs in the Asset Inventory page.
Asset Inventory: filter name was called 'VM with Public IP' instead of 'Asset with Public IP'.
Unable to discover GCP SQL database instances.
Checks Available page: CheckType is always 'Custom Policy' after cloning check from other check types.
Risk Score update message did not consider AssetType (just AssetId) - this caused issues with Azure assets that can have the same AssetId for multiple asset types.
Known Issues
Compliance Inspector - view check details: Detail are not showing for deleted check.
Openstack VMs do not set flag for IP public address.
Business Unit admins are able to see recommendations for provider account(s) that they do not manage.
Compliance check details: paging issue for results when using open text search.
Network security group: paging issue on open text search.
Admins who do not have configuration permissions can see the pulldown menu. (UI issue only - they see an empty page if they select a menu option, and therefore cannot update permissions)
Recommendations are not supported for microsegmentation in Openstack network policies.
AWS/EKS or Azure/AKS K8S are also exported as provider account(s) when exporting an AWS and Azure provider account.
New Asset Types Discovered
AWS
AWS Access Analyzer
AWS Account Password Policy
AWS Athena Workgroup
AWS CloudWatch Metric Alarm
AWS CloudWatch Log Group
AWS Detective Graph
AWS EC2 Account Attribute
AWS Glue Crawler
AWS Guard Duty Detector
AWS Guard Duty Finding
AWS Macie Job
AWS OpenID Connector Provider
AWS Organization Tag Policy
AWS BackupPolicy
AWS iService Opt Out Policy
AWS Round Table
AWS Server Certificate
AWS SAML Provider
AWS Stackset
AWS Stackset Instance
AWS WAF WebACL
Added Public Access Block Configuration field to AWS S3 Bucke
Azure
Azure Activity Log Alerts
Azure Diagnostic Settings
Azure Disk encryption set
Azure Spring Cloud
Azure Spring App
Azure Virtual Network
Added Server Vulnerability Assessment property for SQL Servers
Added Azure defender pricing bundles in Azure Subscriptions
Added Data Export Settings and Alert Sync Settings in Azure Subscription
Added Data Table Service properties to Azure Storage Account
GCP
GCP Bigquery Table
Azure Diagnostic Settings
New Compliance Checks
AWS
aws-001-013:1.4.0 Ensure there is only one active access key available for any single IAM user
aws-001-019:1.4.0 Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed
aws-001-020:1.4.0 Ensure that IAM Access analyzer is enabled for all regions
aws-001-021:1.4.0 Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
aws-002-101:1.4.0 Ensure all S3 buckets employ encryption-at-rest
aws-002-102:1.4.0 Ensure S3 Bucket Policy is set to deny HTTP requests
aws-002-103:1.4.0 Ensure MFA Delete is enable on S3 buckets
aws-002-104:1.4.0 Ensure all data in Amazon S3 has been discovered, classified and secured when required
aws-002-105:1.4.0 Ensure that Amazon S3 Buckets are configured with 'Block public access (bucket settings)
aws-002-201:1.4.0 Ensure EBS volume encryption is enabled
aws-003-010:1.4.0 Ensure that Object-level logging for write events is enabled for S3 bucket
aws-003-011:1.4.0 Ensure that Object-level logging for read events is enabled for S3 bucket
aws-004-015:1.4.0 Ensure a log metric filter and alarm exists for AWS Organizations changes
aws-005-001:1.4.0 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
aws-005-004:1.4.0 Ensure routing tables for VPC peering are 'least access'
aws-200-170:1.0.0 Ensure AWS Guard Duty Detector is enabled
aws-200-169:1.0.0 Ensure AWS WAF is used to protect the web application
aws-200-171:1.0.0 Ensure that user does not have excessive privileges
Azure
azr-200-039:1.1.0 - Maximum number of rules in a network security group
azr-004-308:1.3.1 Ensure 'Allow access to Azure services' for PostgreSQL Database Server is disabled
azr-004-205:1.3.1 Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server
azr-004-201:1.3.1 Ensure that Advanced Threat Protection (ATP) on a SQL server is set to 'Enabled'
azr-004-202:1.3.1 Ensure that Vulnerability Assessment (VA) is enabled on a SQL server by setting a Storage Account
azr-004-203:1.3.1 Ensure that VA setting Periodic Recurring Scans is enabled on a SQL server
azr-004-204:1.3.1 Ensure that VA setting Send scan reports to is configured for a SQL server
azr-002-001:1.3.1 Ensure that Azure Defender is set to On for Servers
azr-002-002:1.3.1 Ensure that Azure Defender is set to On for App Service
azr-002-003:1.3.1 Ensure that Azure Defender is set to On for Azure SQL database servers
azr-002-004:1.3.1 Ensure that Azure Defender is set to On for SQL Servers on machines
azr-002-005:1.3.1 Ensure that Azure Defender is set to On for Storage
Copyright © 2021 Cloudvisory Documentation, FireEye Inc.
3
azr-002-006:1.3.1 Ensure that Azure Defender is set to On for Kubernetes
azr-002-007:1.3.1 Ensure that Azure Defender is set to On for Container Registries
azr-002-008:1.3.1 Ensure that Azure Defender is set to On for Key Vault
azr-002-009:1.3.1 Ensure that Windows Defender ATP (WDATP) integration with Security Center is selected
azr-002-010:1.3.1 Ensure that Microsoft Cloud App Security (MCAS) integration with Security Center is selected
azr-002-012:1.3.1 Ensure any of the ASC Default policy setting is not set to Disabled
azr-002-015:1.3.1 Ensure that 'All users with the following roles' is set to 'Owner'
azr-003-008:1.3.1 Ensure soft delete is enabled for Azure Storage
azr-003-009:1.3.1 Ensure storage for critical data are encrypted with Customer Managed Key
azr-003-010:1.3.1 Ensure Storage logging is enabled for Blob service for read, write, and delete requests
azr-003-011:1.3.1 Ensure Storage logging is enabled for Table service for read, write, and delete requests
azr-004-205:1.3.1 Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server
azr-005-003:1.3.1 Ensure that Diagnostic Logs are enabled for all services which support it
azr-005-101:1.3.1 Ensure that a 'Diagnostics Setting' exists
azr-005-102:1.3.1 Ensure Diagnostic Setting captures appropriate categories
azr-005-202:1.3.1 Ensure that Activity Log Alert exists for Delete Policy Assignment
azr-006-006:1.3.1 Ensure that UDP Services are restricted from the Internet
azr-007-001:1.3.1 Ensure Virtual Machines are utilizing Managed Disks
azr-007-007:1.3.1 Ensure that VHD's are encrypted
azr-009-010:1.3.1 Ensure FTP deployments are disabled
azr-001-023:1.3.1 Ensure Custom Role is assigned for Administering Resource Locks
GCP
gcp-002-012:1.2.0 Ensure that Cloud DNS logging is enabled for all GCP VPC networks
gcp-004-011:1.2.0 Ensure that GCP Compute instances have Confidential Computing enabled
gcp-006-303:1.2.0 Ensure 'user connections' database flag for GCP Cloud SQL SQL Server instance is set as appropriate
gcp-006-304:1.2.0 Ensure 'user options' database flag for GCP Cloud SQL SQL Server instance is not configured
gcp-006-305:1.2.0 Ensure 'remote access' database flag for GCP Cloud SQL SQL Server instance is set to 'off'
gcp-006-306:1.2.0 Ensure '3625 (trace flag)' database flag for GCP Cloud SQL SQL Server instance is set to 'off'
gcp-007-003:1.2.0 Ensure that a Default Customer-managed encryption key (CMEK) is specified for all GCP BigQuery Data Sets
gcp-006-207:1.2.0 Ensure 'log_statement' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately
gcp-006-208:1.2.0 Ensure 'log_hostname' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately
gcp-006-209:1.2.0 Ensure 'log_parser_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'
gcp-006-210:1.2.0 Ensure 'log_planner_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'
gcp-006-211:1.2.0 Ensure 'log_executor_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'
gcp-006-212:1.2.0 Ensure 'log_statement_stats' database flag for GCP Cloud SQL PostgreSQL instance is set to 'off'
gcp-006-213:1.2.0 Ensure that the 'log_min_messages' database flag for GCP Cloud SQL PostgreSQL instance is set appropriately
gcp-006-214:1.2.0 Ensure 'log_min_error_statement' database flag for GCP Cloud SQL PostgreSQL instance is set to 'Error' or stricter
gcp-006-102:1.2.0 Ensure 'skip_show_database' database flag for GCP Cloud SQL Mysql instance is set to 'on'
gcp-006-202:1.2.0 Ensure 'log_error_verbosity' database flag for GCP Cloud SQL PostgreSQL instance is set to 'DEFAULT' or stricter
gcp-006-205:1.2.0 Ensure 'log_duration' database flag for GCP Cloud SQL PostgreSQL instance is set to 'on'
gcp-006-301:1.2.0 Ensure 'external scripts enabled' database flag for GCP Cloud SQL SQL Server instance is set to 'off'
gcp-007-002:1.2.0 Ensure that all GCP BigQuery Tables are encrypted with Customer-managed encryption key (CMEK)