Azure-SecurityCenter-High-Severity-Alerts-Enabled
Severity : High
Description: This control ensures that Notify about alerts with the following severity field is marked. Enabling security alerts emailing ensures that the security alert emails from Microsoft get receive by appropriate email address. This ensures that any potential security issues are informormed and you can timely mitigate the risk.
Remediation Steps:
Perform following to update parameters:
Login to Azure Portal using https://portal.azure.com.
Go to Security Center.
Click on Pricing & settings.
Click on Subscriptions.
Under Settings click on Email notifications.
Mark check box for Notify about alerts with the following severity.
Click Save.
Important:
Along with ASC Default assignment, there could be custom policy assignments with the policy definition "Enable Monitoring in Azure Security Center". 'Monitor missing Endpoint Protection in Azure Security Center' should be enabled for at least one of such assignments
Reference:.
CIS Microsoft Azure Foundations Benchmark v1.3.0 - 02-01-2021 : Recommendation #2.14
https://docs.microsoft.com/en-us/rest/api/securitycenter/securitycontacts/list
https://docs.microsoft.com/en-us/rest/api/securitycenter/securitycontacts/update
Blue Hexagon Proprietary