Skip to main content

lacework-global-611

2.2.2 Ensure that Auto provisioning of 'Vulnerability assessment for machines' is Set to 'On' (Manual)

note

This rule has been changed to manual, see Permanently Manual Rules (that were deemed automated) for CIS Azure 1.5.0 for details.

Profile Applicability

• Level 2

Description

Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.

Rationale

Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.

Impact

Additional licensing is required and configuration of Azure Arc introduces complexity beyond this recommendation.

Audit

From Azure Portal

  1. From Azure Home select the Portal Menu
  2. Select Microsoft Defender for Cloud
  3. Then Environment Settings
  4. Select a subscription
  5. Click on Auto Provisioning in the left column.
  6. Ensure that Vulnerability assessment for machines is set to On

Repeat the above for any additional subscriptions.

Remediation

From Azure Portal

  1. From Azure Home select the Portal Menu
  2. Select Microsoft Defender for Cloud
  3. Then Environment Settings
  4. Select a subscription
  5. Then Auto Provisioning in the left column.
  6. Ensure that Vulnerability assessment for machines is set to On

Repeat the above for any additional subscriptions.

References

https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-data-collection?tabs=autoprovision-va
https://msdn.microsoft.com/en-us/library/mt704062.aspx
https://msdn.microsoft.com/en-us/library/mt704063.aspx
https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/list
https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/create
https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-posture-vulnerability-management#pv-5-perform-vulnerability-assessments

Additional Information

While this feature is generally available as of publication, it is not yet available for Azure Government tenants.