What to build
A scan rule that detects Azure Key Vaults with no diagnostic
logging configured. Without logging, access to secrets, keys,
and certificates is not recorded, making it impossible to detect
unauthorised access or investigate a breach involving key material.
Rule details
- Rule ID: AZ-KV-003
- Severity: MEDIUM
- Category: Key Vault
- Frameworks: CIS 8.4, NIST DE.CM-7, ISO 27001 A.12.4.1
Files to create
- scanner/rules/az_kv_003.py
- playbooks/cli/fix_az_kv_003.sh
Technical note
Use azure-mgmt-monitor to check diagnostic settings.
Call client.diagnostic_settings.list(resource_uri) where
resource_uri is the full Key Vault resource ID.
A vault with no diagnostic settings or with all logs disabled
should be flagged.
How to get started
- Read CONTRIBUTING.md
- Fork the repo, create branch feat/az-kv-003
- Write the rule and playbook
- Open a PR to dev
Acceptance Criteria
What to build
A scan rule that detects Azure Key Vaults with no diagnostic
logging configured. Without logging, access to secrets, keys,
and certificates is not recorded, making it impossible to detect
unauthorised access or investigate a breach involving key material.
Rule details
Files to create
Technical note
Use azure-mgmt-monitor to check diagnostic settings.
Call client.diagnostic_settings.list(resource_uri) where
resource_uri is the full Key Vault resource ID.
A vault with no diagnostic settings or with all logs disabled
should be flagged.
How to get started
Acceptance Criteria