Skip to main content

Where to Find Common Azure Evidence Items

This article includes examples of where you can find common evidence items within your Azure environment.

Stephanie Lorraine avatar
Written by Stephanie Lorraine
Updated over a year ago

Antivirus (only needed if hosting Windows servers):

Azure offers different resource images that contains Antivirus solutions installed, the client needs to review their configuration in order to demonstrate what type of instances and what antivirus they have installed.

Access to Production:

The users who have access will be listed in Active Directory:

Availability Monitoring Tool:

Azure Monitor works as the Availability Monitoring Tool, here you can check for evidence of alarms too:

Encryption Keys:

The Key Vaults Service will contain all the keys available in Azure:

Remote System Authentication:

All the information related to the access to network and how it’s configured can be found in the Virtual Network service:

Infrastructure Change List:

If enabled, Activity Log will display any Infrastructure Change done in Azure:

Intrusion Detection System:

If enabled, Azure Security Center will give you the evidence you need in Azure:

Password Settings:

Go to Authentication Methods in Azure Portal:

Firewall:

Go to Azure Firewall Manager for General Firewall Configuration:

Go to Web Application Firewall (WAF) Policies for specific application rules:

Backup Schedule and Settings:

Go to Azure Backup Center settings to find evidence:

Role Access Management:

Go to Active Directory → Roles and Administrators:

Cloud Admin Users:

Go to Active Directory → Roles and Administrators and look for Network Administrator Role:

Encryption in Transit:

Go to the Connection Services configuration to extract information about the encryption of VPNs and other:

Security/Hardening Configurations:

Go to the Virtual Machines service to find the predefined hardening configuration for new Virtual Machines:

API Security:


Go to: https://www.ssllabs.com/ssltest/ and enter your API URL and ensure you check “Do not show the results on the boards”

In few minutes you will get an analysis of the SSL Certificates used in your api:

Questions?

Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.

Did this answer your question?