Organization should establish network monitoring and defense
Medium
Azure
General
manual-cis-network-monitoring
How to fix it
Establish and maintain network monitoring capabilities to detect and alert on potential intrusions. Deploy IDS/IPS, network flow analysis, and centralized log correlation (SIEM).
How to verify
- Verify network monitoring tools are deployed (IDS/IPS, SIEM)
- Confirm alert review procedures exist
- Verify incident escalation process from monitoring
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes