How to create a overview over all VMs and his CIS compliance status?

Rust, Christopher 0 Reputation points
2024-05-15T07:00:47.17+00:00

Is there any way to generate an overview to see the CIS compliance coverage over all virtual maschines?

Me problem is, we need to use CIS Images vor VMs but some applications need the possibility to deactivate some of the CIS rules to work correctly.

So we need two things to work safe:

  • overview over all vms with exception rules
  • a process to deactivate rules of a CIS image
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,318 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
808 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Sedat SALMAN 13,180 Reputation points
    2024-05-15T09:28:24.1366667+00:00

    at first, you can assign the relevant CIS policy to your resource

    then you can use the Azure Policy Compliance Scan action to trigger an on-demand evaluation scan

    https://learn.microsoft.com/en-us/azure/governance/policy/how-to/get-compliance-data#on-demand-evaluation-scan


  2. deherman-MSFT 34,036 Reputation points Microsoft Employee
    2024-05-15T22:47:24.08+00:00

    @Rust, Christopher

    Microsoft Purview Compliance Manager is a feature in the Microsoft Purview compliance portal to help you understand your organization's compliance posture and take actions to help reduce risks. Compliance Manager offers a premium template for building an assessment for this regulation. Find the template in the assessment templates page in Compliance Manager. Learn how to build assessments in Compliance Manager.

    CIS-CAT Pro is the CIS tool which can be used to automate the scan against your VMs. CIS Hardened images are available, which you noted. The process to reverse any of the protections would be up to each protection and somewhat defeat the purpose off using a hardened image. It might be worth reaching out to their support for these questions.
    https://www.cisecurity.org/support

    Hope this helps! Let me know if you still have questions.


    If you still have questions, please let us know in the "comments" and we would be happy to help you. Comment is the fastest way of notifying the experts.

    If the answer has been helpful, we appreciate hearing from you and would love to help others who may have the same question. Accepting answers helps increase visibility of this question for other members of the Microsoft Q&A community.

    Thank you for helping to improve Microsoft Q&A!

    User's image