Skip to content

[RULE] AZ-KV-003: Key Vault without diagnostic logging enabled #26

Description

@Vishnu2707

What to build

A scan rule that detects Azure Key Vaults with no diagnostic
logging configured. Without logging, access to secrets, keys,
and certificates is not recorded, making it impossible to detect
unauthorised access or investigate a breach involving key material.

Rule details

  • Rule ID: AZ-KV-003
  • Severity: MEDIUM
  • Category: Key Vault
  • Frameworks: CIS 8.4, NIST DE.CM-7, ISO 27001 A.12.4.1

Files to create

  • scanner/rules/az_kv_003.py
  • playbooks/cli/fix_az_kv_003.sh

Technical note

Use azure-mgmt-monitor to check diagnostic settings.
Call client.diagnostic_settings.list(resource_uri) where
resource_uri is the full Key Vault resource ID.
A vault with no diagnostic settings or with all logs disabled
should be flagged.

How to get started

  1. Read CONTRIBUTING.md
  2. Fork the repo, create branch feat/az-kv-003
  3. Write the rule and playbook
  4. Open a PR to dev

Acceptance Criteria

  • Rule follows template exactly
  • Returns correct findings JSON
  • Playbook tested
  • Framework mappings included in all three compliance files

Activity

  1. added
    good first issuePerfect for first time contributors
    new-ruleAdding a new misconfiguration scan rule
    on May 6, 2026
  2. parthrohit22 commented on May 8, 2026

    @parthrohit22
    Collaborator

    I’d like to take Issue #26 (AZ-KV-003 - Key Vault without diagnostic logging enabled).

    I recently worked on AZ-KV-002, so I already have the Key Vault scanning flow and validation setup locally. I can extend that into diagnostic settings and logging validation for this rule.

    Planning to have the rule, playbook, framework mappings, and testing completed by Monday noon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

good first issuePerfect for first time contributorsnew-ruleAdding a new misconfiguration scan rule

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions