Organization should conduct penetration testing
High
Azure
General
manual-cis-penetration-testing
How to fix it
Conduct external and internal penetration testing at least annually. Include both network-layer and application-layer testing. Remediate critical and high findings within 30 days.
How to verify
- Verify penetration test report (dated within 12 months)
- Confirm both external and internal scopes
- Verify remediation records for critical/high findings
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes