> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-august-2024.md).

# Features Introduced in August 2024

Learn what’s new on Prisma® Cloud in August 2024.

* [New Features](#new-features)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notices](#deprecation-notices)
* [End of Sale Notice](#end-of-sale)

## New Features

| **Feature**                                                                                                                                                                                                                                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Managed Security Service Provider</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                              | <p>Prisma Cloud <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/mssp/mssp">Managed Security Service Provider</a> (MSSP) offering allows you to administer large customer groups efficiently by enabling you to:</p><ul><li>Manage and operate a large number of tenants from a single console.</li><li>Dynamically create and delete tenants on demand.</li><li>Efficiently segment and manage customers into industry defined groups such as Healthcare, Finance, and so on.</li><li>Segment tenants by reallocating credits as needed, between tenants under management.</li><li>Isolate customer data in adherence with established security best practices.</li><li>Get centralized visibility into security telemetry such as incidents, attack paths, and misconfigurations.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Code to Cloud Tracing for Vulnerabilities</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                      | <p>Prisma Cloud now supports tracing of vulnerabilities from container images deployed in Runtime back to the specific root cause in Build (package manager file in a repository or a package being directly added).</p><p>With <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/c2c-tracing-vulnerabilities/c2c-tracing-vulnerabilities">Code to Cloud tracing</a> you can identify all the vulnerabilities found on a runtime container image, match which registry image was used in the deployment, discover what pipeline was used to build it and from where, identify which Dockerfile contains the instructions to build the image, the Package Manager file and packages pulled into it and it’s Base Image. Prisma Cloud scans all the source components to find which ones have the same vulnerability found in runtime and builds the trace.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><mark style="background-color:orange;">Update</mark> <strong>Vulnerabilities Dashboard</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.8.2</mark></p> | <p>The Vulnerabilities Dashboard includes a number of enhancements:</p><ul><li><p>The number of <strong>Internet Exposed</strong> assets are now displayed in the <strong>Vulnerabilities Funnel</strong>.</p><div><figure><img src="/files/HytGoB7aLqvX6c1hL3vZ" alt="vulnerabilities funnel 1"><figcaption></figcaption></figure></div></li><li><p>Hover over the CVEs listed under <strong>Most Important Vulnerabilities</strong> to view more details about the CVE.</p><div><figure><img src="/files/kfzDUPW6VUtwS0y7LMut" alt="most imp vulnerabilities cve details 1"><figcaption></figcaption></figure></div></li><li><p>Previously, the Vulnerabiities Dashboard displayed vulnerabilities across all the cloud accounts. Now, you can filter vulnerabilities by <strong>Account Group</strong> or <strong>Cloud Account</strong>. As you select the values in the filter, the information displayed on the Dashboard automatically refreshes.</p><div><figure><img src="/files/WyvDWR6Z4bP0L5y9ptxt" alt="vulnerabilities db filters 1"><figcaption></figcaption></figure></div><div><figure><img src="/files/H6DaWcImKMQao8M6fYs5" alt="vulnerabilities db filters 2"><figcaption></figcaption></figure></div><p>Note that currently the <strong>Vulnerabilities Burndown</strong> widget does not support the new filters, so the information displayed under <strong>Vulnerabilities Burndown</strong> will not match your filter criteria.</p></li><li><p>You can edit a widget to filter by <strong>Cluster Name</strong> and <strong>Cluster Namespace</strong> and save that filter at the wdiget level. The <strong>Cluster Namespace</strong> option is presented only after you select enter a <strong>Cluster Name</strong>.</p><div><figure><img src="/files/qEFtaRLEbfFLN3iPwykL" alt="vulnerabilities cluster name filter 1"><figcaption></figcaption></figure></div></li><li><p>A new <strong>Vulnerable Assets</strong> widget provides a view of all your vulnerable assets across your application lifecycle by type. You can see how many packets, IaC files, registry images, host VM images, serverless functions, deployed image, and hosts have vulnerabilities across the different lifecycle.</p><div><figure><img src="/files/SzQMK4obAsNMUhhs0WI2" alt="vulnerabilities dashboard vul assets 1"><figcaption></figcaption></figure></div><p>Hover over the tiles to get more details of where those hosts are, the provider, how many cloud accounts are associated, and how many vulnerabilities are associated with those assets. Click on an asset to navigate directly to <strong>Search</strong> page.</p><div><figure><img src="/files/VNqkaOsf8nZOx5IjUnX7" alt="vulnerabilities dashboard vul assets 2"><figcaption></figcaption></figure></div></li><li><p>Along with the <strong>Account Group</strong> and <strong>Cloud Account</strong> filters, the <strong>Search</strong> page now supports the <strong>Cluster Name</strong> and <strong>Cluster Namespace</strong> filters. Make sure you first select a <strong>Cluster Name</strong> after which you can select a <strong>Cluster Namespace</strong>.</p><div><figure><img src="/files/CayO3A2lF7FDKAGy499G" alt="vulnerabilities cluster name filter 2"><figcaption></figcaption></figure></div></li><li><p>By default, the <strong>View By</strong> is set to <strong>CVE</strong> that displays all the CVEs that affect your assets. You can switch to <strong>Asset</strong>, which provides you a view of all the assets relevant to your search criteria instead of the CVEs.</p><div><figure><img src="/files/GQB0wsbMa0uu0zsaaDWP" alt="search view by cve"><figcaption></figcaption></figure></div></li></ul> |
| <p><strong>Support for Custom Build Bicep Policies</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                | You can now create custom build Bicep policies through both the [Code and Visual editors](https://docs.prismacloud.io/en/enterprise-edition/content-collections/governance/custom-build-policies/visual-editor), offering you the flexibility to align with organizational requirements and preferences.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Data Security Posture Management and Artificial Intelligence Security Posture Management</strong></p><p><mark style="background-color:orange;">Secure the Data</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p> | <p>Prisma Cloud Data Security Posture Management (DSPM) and Artificial Intelligence Security Posture Management (AI-SPM) are now generally available.</p><ul><li><a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/data-security-posture-management/welcome/welcome">DSPM</a> enables you to discover, classify, protect, and govern data across your cloud environments.</li><li><a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/data-security-posture-management/welcome-to-prisma-cloud-aispm/introduction-ai">AI-SPM</a> provides complete visibility in to your AI pipelines. It prioritizes misconfigurations and strengthens the overall integrity of your AI framework and minimizes the risk of data exposure and compliance breaches.</li></ul><p>You can subscribe to DSPM from the Prisma Cloud console. Select your user <strong>Profile icon > View Subscriptions</strong> and click <strong>Subscribe</strong> under Data Security Posture Management.</p><p><img src="/files/jdNXyNTvXNFdO3t3wn7j" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>DSPM Permissions and Default Permission Group</strong></p><p><mark style="background-color:orange;">Secure the Data</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                            | Prisma Cloud includes a new **Data Security Posture Management** [permission](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/prisma-cloud-admin-permissions) that allows you to grant access to all the DSPM capabilities for Custom Permission Groups. For ease of use, Prisma Cloud also has a new **Data Security Posture Management** Default Permission Group, which includes this new permission.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>AI Assisted Queries</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                            | <p>Enhancements to Prisma Cloud’s query launcher allow you to use <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/launch-your-query">AI assisted queries</a> to retrieve saved searches from your current tenant. Going beyond keyword matching, AI powered semantic searches provide ease of use when launching investigations in Prisma Cloud. For instance, typing “public facing” as a query, returns results with “reachable from untrusted internet sources” as well, because the saved search matches the meaning of the query "public facing". AI assisted search can be toggled on and off as needed. Use the feedback buttons as shown in the image below to provide your feedback on this feature. There will be a phased rollout of this feature across all stacks.</p><p><img src="/files/dOrgV0LBlLDXK9nqelOL" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>RQL for AWS Access Key Discovery</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                               | <p>Prisma Cloud’s RQL enhancements help you discover detailed information about Access Keys held by users, their activity, rotation, and usage. Available for AWS, the following RQL query helps you enforce zero trust best practices in your cloud environment:</p><ul><li>Queries the number of days passed since the last usage of an access key</li></ul><p><code>source.cloud.accesskey.lastused.days (>, <, = )</code></p><ul><li>Queries the number of active access keys held by a user</li></ul><p><code>source.cloud.accesskey.activekeys (<, >, =) (0, 1, 2)</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><mark style="background-color:orange;">Update</mark> <strong>Cloud Network Analyzer</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>    | Prisma Cloud **AWS EC2 instance with unrestricted outbound access to internet** CNA policy now ignores resources created by Prisma Cloud agentless scanning as those are very well restricted and short lived workloads that can only communicate back with Prisma Cloud.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>New AI and Machine Learning Category in Custom Build Policies</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>                          | <p>When creating or editing custom <strong>Build</strong> policies under <strong>Application Security > Governance</strong>, you will now find a new category— <strong>AI and Machine Learning</strong>. This category is available in the YAML policy templates within the <strong>Code Editor</strong> and under the <strong>Category Type</strong> option in the <strong>Visual Editor</strong>.</p><p>The <strong>AI and Machine Learning</strong> category offers granular control over <strong>Build</strong> configurations for machine learning and artificial intelligence workloads. You can use it into your custom policies and relevant dashboards through the <strong>IaC Category</strong> filter, which streamlines policy management for AI resources. For more details, see <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/governance/custom-build-policies/custom-build-policies">Custom Build Policies</a>.</p><p><img src="/files/iNb3AtmJwkPVEky9phOW" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>New Resource Classes Filter</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                            | <p>A new filter, <strong>Resource Classes</strong>, is now available under <strong>Application Security > Inventory > IaC Resources</strong>. This filter becomes active after you select a <strong>Framework</strong> from the inventory table.</p><p><strong>Resource Classes</strong> provide a structured method for categorizing infrastructure resources based on their type, function, or other relevant criteria. This helps streamline the filtering and management of assets within the IaC inventory. Supported options for <strong>Resource Classes</strong> include— <strong>Compute, Storage, Network, Identity & Security, Database, AI and Machine Learning, Analytics, Code</strong>, and <strong>Others</strong>. For more details, see <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/cloud-and-software-inventory/iac-resources#resource-class">Resource Class.</a></p><p><img src="/files/sWeAPZWIRcF0OILOWFYh" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Blocklist Resource Control</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                             | You can now define granular resource controls to allow or block any use of specific resource types defined in Terraform, enabling you to create blocklists that specify which resources are restricted within your environment, enhancing security and compliance by preventing unauthorized resource usage. For more details, see [example blocklist](https://docs.prismacloud.io/en/enterprise-edition/content-collections/governance/custom-build-policies/custom-build-policy-examples#resource-blocklist).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

## Changes in Existing Behavior

| **Feature**                                                                                                                                   | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| --------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Multiselect Disabled for Alert Rule Name Filter</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>            | <p>You cannot select multiple alert rules in the <strong>Alert Rule Name</strong> filter on the <strong>Alerts > Overview</strong> page. The multiselect option is disabled to eliminate inconsistent results when filtering more than one alert rule.</p><p>When using the <code>POST/alerts/policy</code> API, make sure to include only one <strong>Alert Rule Name</strong> in the filters attribute of the request body schema.</p>                                                                                           |
| <p><strong>Role-Based Access Control for Compliance and Alert Reports</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p> | <p>User-generated reports are only visible to System Administrators and to users with the same role.</p><p>Implementing Role-Based Access Control (RBAC) enhances data security by streamlining report access for users with the same role, while also preventing unauthorized access.</p>                                                                                                                                                                                                                                         |
| <p><strong>Create or Update Policy Permissions</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                        | <p>The Create/Update Policy Permissions are divided into the two granular permissions as follows:</p><ul><li>Policy</li><li>Manage Policy Compliance Mapping</li></ul><p><strong>Impact—</strong></p><ul><li>Users managing new custom permission groups must select both permissions explicitly if they want to assign compliance mappings during policy create/update operation.</li><li>Manage policy compliance mapping is added by default to all existing permission groups with policy create/update permissions.</li></ul> |

## API Ingestions

| **Service**                                                                                                                                                              | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                        | <p><strong>aws-bedrock-foundation-model</strong></p><p>Additional permissions required:</p><ul><li><code>bedrock:ListFoundationModels</code></li><li><code>bedrock:GetFoundationModel</code></li></ul><p>The Security Audit role include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                                                                                                                               |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                        | <p><strong>aws-bedrock-custom-model</strong></p><p>Additional permissions required:</p><ul><li><code>bedrock:ListCustomModels</code></li><li><code>bedrock:GetCustomModel</code></li><li><code>bedrock:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                                                                                                                                         |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                        | <p><strong>aws-bedrock-agent</strong></p><p>Additional permissions required:</p><ul><li><code>bedrock:ListAgents</code></li><li><code>bedrock:GetAgent</code></li><li><code>bedrock:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                                                                                                    |
| <p><strong>AWS Resource Groups and Tagging</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                       | <p><strong>aws-resourcegroupstaggingapi-report-creation</strong></p><p>Additional permission required:</p><ul><li><code>tag:DescribeReportCreation</code></li></ul><p>The Security Audit role does not include the above permission. You must manually update the CFT template to enable them.</p>                                                                                                                                                                                                                                                          |
| <p><strong>AWS Resource Groups and Tagging</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                       | <p><strong>aws-resourcegroupstaggingapi-compliance-summary</strong></p><p>Additional permission required:</p><ul><li><code>tag:GetComplianceSummary</code></li></ul><p>The Security Audit role does not include the above permission. You must manually update the CFT template to enable them.</p>                                                                                                                                                                                                                                                         |
| <p><mark style="background-color:orange;">Update</mark> <strong>AWS Key Management Service (KMS)</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p> | <p><strong>aws-kms-get-key-rotation-status</strong></p><p>The API is updated to include the <code>multiRegion</code> field in the JSON resource configuration. As part of this change, the <code>multiRegion</code> key is now available in RQL auto-completion.</p>                                                                                                                                                                                                                                                                                        |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                | <p><strong>azure-active-directory-authentication-methods-registration-campaign</strong></p><p>Additional permission required:</p><ul><li><code>Policy.read.all</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                | <p><strong>azure-active-directory-subscribed-sku</strong></p><p>Additional permission required:</p><ul><li><code>Organization.Read.All</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                     | <p><strong>azure-app-service-plan-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/serverfarms/Read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                      |
| <mark style="background-color:orange;">Update</mark> **Azure Storage**                                                                                                   | <p>The following APIs are updated to include the <code>StorageAccountId</code> and <code>StorageAccountName</code> fields in the JSON resource configuration. This enhancement facilitates more complex joins and improved cross-referencing in RQL queries.</p><ul><li><code>azure-storage-account-blob-diagnostic-settings</code></li><li><code>azure-storage-account-file-diagnostic-settings</code></li><li><code>azure-storage-account-queue-diagnostic-settings</code></li><li><code>azure-storage-account-table-diagnostic-settings</code></li></ul> |
| <p><strong>Google Cloud VMware Engine</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                            | <p><strong>gcloud-vmware-engine-external-address</strong></p><p>Additional permissions required:</p><ul><li><code>vmwareengine.privateClouds.list</code></li><li><code>vmwareengine.externalAddresses.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                 |
| <p><strong>Google Cloud Domains</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                  | <p><strong>gcloud-cloud-domains-registration</strong></p><p>Additional permissions required:</p><ul><li><code>domains.registrations.list</code></li><li><code>domains.registrations.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                           |
| <p><strong>Google BigLake</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                        | <p><strong>gcloud-biglake-catalog-database-table</strong></p><p>Additional permissions required:</p><ul><li><code>biglake.catalogs.list</code></li><li><code>biglake.databases.list</code></li><li><code>biglake.tables.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                               |
| <p><strong>Google BigLake</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                        | <p><strong>gcloud-biglake-catalog-database</strong></p><p>Additional permissions required:</p><ul><li><code>biglake.catalogs.list</code></li><li><code>biglake.databases.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                              |
| <p><strong>Google BigLake</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                                        | <p><strong>gcloud-biglake-catalog</strong></p><p>Additional permission required:</p><ul><li><code>biglake.catalogs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>Google BigQuery Data Transfer</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                         | <p><strong>gcloud-bigquery-data-transfer-config</strong></p><p>Additional permission required:</p><ul><li><code>bigquery.transfers.get</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>AWS Systems Manager</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                   | <p><strong>aws-ssm-service-setting</strong></p><p>Additional permission required:</p><ul><li><code>ssm:GetServiceSetting</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>AWS Systems Manager</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                   | <p><strong>aws-ssm-session</strong></p><p>Additional permission required:</p><ul><li><code>ssm:DescribeSessions</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>AWS Web Application Firewall (WAF)</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                    | <p><strong>aws-waf-v2-global-rule-group</strong></p><p>Additional permissions required:</p><ul><li><code>wafv2:ListRuleGroups</code></li><li><code>wafv2:GetRuleGroup</code></li></ul><p>The Security Audit role includes the <code>wafv2:ListRuleGroups</code> permission.</p><p>The Security Audit role does not include the <code>wafv2:GetRuleGroup</code> permission. You must manually add it to the CFT template to enable it.</p>                                                                                                                   |
| <p><strong>Azure Kusto</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                           | <p><strong>azure-kusto-databases</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Kusto/Clusters/read</code></li><li><code>Microsoft.Kusto/Clusters/Databases/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                               |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                | <p><strong>azure-active-directory-authentication-strength-policy</strong></p><p>Additional permission required:</p><ul><li><code>Policy.Read.All</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Azure Monitor</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                         | <p><strong>azure-monitor-data-collection-rules</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Insights/DataCollectionRules/Read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Azure SQL Database</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                    | <p><strong>azure-sql-vm</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.SqlVirtualMachine/sqlVirtualMachines/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Azure Virtual Desktop</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                 | <p><strong>azure-virtual-desktop-application-groups</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.DesktopVirtualization/applicationgroups/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Google Application Integration</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                        | <p><strong>gcloud-application-integration</strong></p><p>Additional permissions required:</p><ul><li><code>integrations.integrations.list</code></li><li><code>integrations.integrationVersions.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                       |
| <p><strong>Google Backup and DR</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                  | <p><strong>gcloud-backup-dr-management-server</strong></p><p>Additional permissions required:</p><ul><li><code>backupdr.managementServers.list</code></li><li><code>backupdr.managementServers.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                |
| <p><strong>Google Cloud Scheduler</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                                | <p><strong>gcloud-cloud-scheduler-job</strong></p><p>Additional permission required:</p><ul><li><code>cloudscheduler.jobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                              |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>AWS API Gateway REST API execution logging disabled</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies AWS API Gateway REST API’s that have disabled execution logging in their stages.</p><p>AWS API Gateway REST API is a service for creating and managing RESTful APIs integrated with backend services like Lambda and HTTP endpoints. Execution logs all the API activity logs to CloudWatch, which helps in incident response, security and compliance, troubleshooting, and monitoring.</p><p>It is recommended to enable logging on the API Gateway REST API to track API activity.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-apigateway-get-stages' AND json.rule = methodSettings.[].loggingLevel does not exist OR methodSettings.[].loggingLevel equal ignore case off as X; config from cloud.resource where api.name = 'aws-apigateway-get-rest-apis' as Y; filter ' $.X.restApi equal ignore case $.Y.id '; show Y;
</code></pre></td></tr><tr><td><p><strong>AWS S3 access point Block public access setting disabled</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies AWS S3 access points with the block public access setting disabled.</p><p>AWS S3 Access Point simplifies managing data access by creating unique access control policies for specific applications or users within a S3 bucket. The Amazon S3 Block Public Access feature manages access at the account, bucket, and access point levels. Each level’s settings can be configured independently but cannot override more restrictive settings at higher levels. Instead, access point settings complement those at the account and bucket levels.</p><p>It is recommended to enable the Block public access setting on a S3 access point unless intended for public exposure.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-s3-access-point' AND json.rule = networkOrigin equal ignore case internet and (publicAccessBlockConfiguration does not exist or (publicAccessBlockConfiguration.blockPublicAcls is false and publicAccessBlockConfiguration.ignorePublicAcls is false and publicAccessBlockConfiguration.blockPublicPolicy is false and publicAccessBlockConfiguration.restrictPublicBuckets is false))
</code></pre></td></tr><tr><td><p><strong>AWS Secrets Manager secret configured with automatic rotation not rotated as scheduled</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies the AWS Secrets Manager secret not rotated successfully based on the rotation schedule.</p><p>Secrets Manager stores secrets centrally, encrypts them automatically, controls access, and rotates secrets safely. By rotating secrets, you replace long-term secrets with short-term ones, limiting the risk of unauthorized use. If secrets fail to rotate in Secrets Manager, long-term secrets remain in use, increasing the risk of unauthorized access and potential data breaches.</p><p>It is recommended that proper configuration and monitoring of the rotation process be ensured to mitigate these risks.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-secretsmanager-describe-secret' AND json.rule = 'lastRotatedDate exists and rotationEnabled is true and _DateTime.daysBetween($.lastRotatedDate,today()) > $.rotationRules.automaticallyAfterDays'
</code></pre></td></tr><tr><td><p><strong>AWS S3 bucket with cross-account access</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies the AWS S3 bucket policy allows one or more of the actions (s3:DeleteBucketPolicy, s3:PutBucketAcl, s3:PutBucketPolicy, s3:PutEncryptionConfiguration, s3:PutObjectAcl) for a principal in another AWS account.</p><p>An S3 bucket policy that defines permissions and conditions for accessing an Amazon S3 bucket and its objects. Granting permissions like s3:DeleteBucketPolicy, s3:PutBucketAcl, s3:PutBucketPolicy, s3:PutEncryptionConfiguration, and s3:PutObjectAcl to other AWS accounts can lead to unauthorized access and potential data breaches.</p><p>It is recommended to review and remove permissions from the S3 bucket policy by deleting statements that grant access to restricted actions for other AWS accounts.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-s3api-get-bucket-acl' AND json.rule = policy.Statement[?any(Effect equals Allow and (Principal.AWS does not equal * and Principal does not equal * and Principal.AWS contains arn and Principal.AWS does not contain $.accountId) and (Action contains "s3:Put*" or Action contains "s3:Delete*" or Action equals "*" or Action contains "s3:*" or Action is member of ('s3:DeleteBucketPolicy','s3:PutBucketAcl','s3:PutBucketPolicy','s3:PutEncryptionConfiguration','s3:PutObjectAcl') ))] exists
</code></pre></td></tr><tr><td><p><strong>AWS Lambda Function with administrative permissions</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Lambda Functions granted administrative permissions, increasing the blast radius in case of a potential compromise of the function.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.access.isAdministrative = true AND source.cloud.service.name = 'lambda'
</code></pre></td></tr><tr><td><p><strong>Azure Function App with administrative permissions</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Function App instances granted administrative permissions, increasing the blast radius in case of a potential compromise of the function.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where dest.cloud.type = 'AZURE' AND action.access.isAdministrative = true and source.cloud.service.name = 'microsoft.web'
</code></pre></td></tr><tr><td><p><strong>Azure Database for MySQL flexible server public network access setting is enabled</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Azure Database for MySQL flexible servers which have public network access setting enabled.</p><p>Publicly accessible MySQL servers are vulnerable to external threats with risk of unauthorized access or may remotely exploit any vulnerabilities.</p><p>As a best security practice, it is recommended to configure the MySQL servers with IP-based strict server-level firewall rules or virtual-network rules or private endpoints so that servers are accessible only to restricted entities.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-mysql-flexible-server' AND json.rule = properties.state equal ignore case Ready and firewallRules[*] is empty and properties.network.publicNetworkAccess equal ignore case Enabled
</code></pre></td></tr><tr><td><p><strong>Azure Database for MySQL flexible server firewall rule allow access to all IPv4 address</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Azure Database for MySQL flexible servers which have firewall rule allowing access to all IPV4 address.</p><p>MySQL server having a firewall rule with start IP being 0.0.0.0 and end IP being 255.255.255.255 (i.e. all IPv4 addresses) would allow access to server from any host on the internet. Allowing access to all IPv4 addresses expands the potential attack surface and exposes the MySQL server to increased threats.Allowing access to all IPv4 addresses expands the potential attack surface and exposes the MySQL server to increased threats.</p><p>As a best security practice, it is recommended to configure the MySQL servers with restricted IP-based server-level firewall rules so that servers are accessible only to restricted entities.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-mysql-flexible-server' AND json.rule = properties.state equal ignore case Ready and properties.network.publicNetworkAccess equal ignore case Enabled and firewallRules[?any(properties.startIpAddress equals 0.0.0.0 and properties.endIpAddress equals 255.255.255.255)] exists
</code></pre></td></tr><tr><td><p><strong>Azure Event Hub Namespace having authorization rules except RootManageSharedAccessKey</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Azure Event Hub Namespaces which have authorization rules except RootManageSharedAccessKey.</p><p>Having Azure Event Hub namespace authorization rules other than 'RootManageSharedAccessKey' could provide access to all queues and topics under the namespace which pose a risk if these additional rules are not properly managed or secured.</p><p>As best practice, it is recommended to remove Event Hub namespace authorization rules other than RootManageSharedAccessKey and create access policies at the entity level, which provide access to only that specific entity for queues and topics.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-event-hub-namespace' AND json.rule = authorizationRules[*].name exists and authorizationRules[?any(name does not equal RootManageSharedAccessKey)] exists
</code></pre></td></tr><tr><td><p><strong>Azure Event Hub Instance not defined with authorization rule</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Azure Event Hub Instances that are not defined with authorization rules.</p><p>If the Azure Event Hub Instance authorization rule is not defined, there is a heightened risk of unauthorized access to the event hub data and resources. This could potentially lead to unauthorized data retrieval, tampering, or disruption of the event hub operations. Defining proper authorization rules helps mitigate these risks by controlling and restricting access to the event hub resources.</p><p>As a best practice, it is recommended to define the least privilege security model access policies at Event Hub Instance.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-event-hub-namespace' AND json.rule = properties.disableLocalAuth is false as X; config from cloud.resource where api.name = 'azure-event-hub' AND json.rule = properties.status equal ignore case ACTIVE and authorizationRules[*] is empty as Y; filter '$.Y.id contains $.X.name'; show Y;
</code></pre></td></tr><tr><td><p><strong>Azure user not restricted to create Microsoft Entra Security Group</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies instances in the Microsoft Entra ID configuration where security group creation is not restricted to administrators only.</p><p>When the ability to create security groups is enabled, all users in the directory can create new groups and add members to them. Unless there is a specific business need for this broad access, it is best to limit the creation of security groups to administrators only.</p><p>As a best practice, it is recommended to restrict the ability to create Microsoft Entra Security Groups to administrators only.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-active-directory-authorization-policy' AND json.rule = defaultUserRolePermissions.allowedToCreateSecurityGroups is true
</code></pre></td></tr><tr><td><p><strong>Azure Guest User Invite not restricted to users with specific admin role</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies instances in the Microsoft Entra ID configuration where guest user invitations are not restricted to specific administrative roles.</p><p>Allowing anyone in the organization, including guests and non-admins, to invite guest users can lead to unauthorized access and potential data breaches. This unrestricted access poses a significant security risk.</p><p>As a best practice, it is recommended to configure guest user invites to specific admin roles. This will ensure that only authorized personnel can invite guests, maintaining tighter control over access to cloud resources.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-active-directory-authorization-policy' AND json.rule = not (allowInvitesFrom equal ignore case adminsAndGuestInviters OR allowInvitesFrom equal ignore case none)
</code></pre></td></tr><tr><td><p><strong>Azure Machine learning compute instance configured with public IP</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies Azure Machine Learning compute instances which are configured with public IP.</p><p>Configuring an Azure Machine Learning compute instance with a public IP exposes it to significant security risks, including unauthorized access and cyber-attacks. This setup increases the likelihood of data breaches, where sensitive information and intellectual property could be accessed by unauthorized individuals, leading to potential data leakage and loss.</p><p>As a best practice, it is recommended not to configure Azure Machine Learning instances with public IP.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-machine-learning-compute' AND json.rule = properties.provisioningState equal ignore case Succeeded AND properties.properties.connectivityEndpoints.publicIpAddress exists AND properties.properties.connectivityEndpoints.publicIpAddress does not equal ignore case "null"
</code></pre></td></tr><tr><td><p><strong>Cloud Service account is inactive for 90 days</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies cloud service accounts in Azure, AWS, and GCP that have not been used in the last 90 days.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount', 'service principal', 'user assigned', 'system assigned' ) AND grantedby.cloud.entity.lastlogin.days > 90
</code></pre></td></tr><tr><td><p><strong>Cloud Service account with Metadata Write Permissions is inactive for 90 days</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies cloud service accounts in Azure, AWS, and GCP that have not been used in the last 90 days and hold Metadata Write permissions.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount', 'service principal', 'user assigned', 'system assigned' ) AND grantedby.cloud.entity.lastlogin.days > 90 AND action.access.level = 'Metadata Write'
</code></pre></td></tr><tr><td><p><strong>Cloud Service account with Metadata Read Permissions is inactive for 90 days</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies cloud service accounts in Azure, AWS and GCP that have not been used in the last 90 days and hold Metadata Read permissions.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount', 'service principal', 'user assigned', 'system assigned' ) AND grantedby.cloud.entity.lastlogin.days > 90 AND action.access.level = 'Metadata Read'
</code></pre></td></tr><tr><td><p><strong>Cloud Service account with Data Write Permissions is inactive for 90 days</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies cloud service accounts in Azure, AWS and GCP that have not been used in the last 90 days and hold Data Write permissions.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount', 'service principal', 'user assigned', 'system assigned' ) AND grantedby.cloud.entity.lastlogin.days > 90 AND action.access.level = 'Data Write'
</code></pre></td></tr><tr><td><p><strong>Cloud Service account with Data Read Permissions is inactive for 90 days</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p>This policy identifies cloud service accounts in Azure, AWS and GCP that have not been used in the last 90 days and hold Data Read permissions.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount', 'service principal', 'user assigned', 'system assigned' ) AND grantedby.cloud.entity.lastlogin.days > 90 AND action.access.level = 'Data Read'
</code></pre></td></tr><tr><td><p><strong>AWS FSx for OpenZFS file systems not configured to copy tags to backups or volumes</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies the AWS FSx for OpenZFS file system is configured to copy tags to backups or volumes.</p><p>AWS FSx for OpenZFS is a managed service for deploying and scaling OpenZFS file systems on AWS. Tags make resource identification and management easier, ensuring consistent security policies across file systems. Without copying tags to backups and volumes in AWS FSx for OpenZFS, enforcing consistent access control and tracking sensitive data in these resources becomes challenging.</p><p>It is recommended to configure an FSx for the OpenZFS file system to copy tags to backups and volumes.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-fsx-file-system' AND json.rule = FileSystemType equals "OPENZFS" and Lifecycle equals "AVAILABLE" and (OpenZFSConfiguration.CopyTagsToBackups is false or OpenZFSConfiguration.CopyTagsToVolumes is false )
</code></pre></td></tr><tr><td><p><strong>AWS Private CA root certificate authority is enabled</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies enabled AWS Private CA root certificate authorities.</p><p>AWS Private CA enables creating a root CA to issue private certificates for securing internal resources like servers, applications, users, devices, and containers. The root CA should be disabled for daily tasks to minimize risk, as it should only issue certificates for intermediate CAs, allowing it to remain secure while intermediate CAs handle the issuance of end-entity certificates.</p><p>It is recommended to disable the AWS Private CA root certificate authority to secure.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-acm-pca-certificate-authority' AND json.rule = Type equal ignore case ROOT and Status equal ignore case active
</code></pre></td></tr><tr><td><p><strong>AWS EC2 instance is assigned with public IP</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies the AWS EC2 instance having a public IP address assigned.</p><p>AWS EC2 instances with public IPs are virtual servers hosted in the Amazon Web Services (AWS) cloud that can be accessed over the internet. Public IPs increase an EC2 instance’s attack surface, necessitating robust security configurations to prevent unauthorized access and attacks.</p><p>It is recommended to use private IPv4 addresses for communication between EC2 instances and disassociate the public IP address from an instance or disable auto-assign public IP addresses in the subnet.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ec2-describe-instances' AND json.rule = networkInterfaces[*].association.publicIp exists
</code></pre></td></tr><tr><td><p><strong>AWS Secrets Manager secret not configured to rotate within 90 days</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies the AWS Secrets Manager secret is not configured to automatically rotate the secret within 90 days.</p><p>Rotating secrets minimizes the risk of compromised credentials and reduces exposure to potential threats. Failing to rotate secrets increases the risk of security breaches and prolonged exposure to threats.</p><p>It is recommended to configure automatic rotation in AWS Secrets Manager to replace long-term secrets with short-term ones, reducing the risk of compromise.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-secretsmanager-describe-secret' AND json.rule = rotationEnabled is true and owningService is not member of (appflow, databrew, datasync, directconnect, events, opsworks-cm, rds, sqlworkbench) and rotationRules.automaticallyAfterDays exists and rotationRules.automaticallyAfterDays greater than 90
</code></pre></td></tr><tr><td><p><strong>AWS RDS instance with network path from the untrust internet source</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies AWS RDS instances with network path from untrusted internet source.</p><p>AWS RDS is AWS managed service for running relational databases in the cloud. Allowing an AWS RDS instance to be reachable from any untrusted internet source increases the risk of unauthorized access and potential security breaches due to expanded attack surface.</p><p>It is recommended to restrict traffic from untrusted IP addresses and limit the access to known hosts, services, or specific entities for the RDS Database instances.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network Config</p><pre><code>config from network where source.network = UNTRUST_INTERNET and dest.resource.type = 'PaaS' and dest.cloud.type = 'AWS' and dest.paas.service.type = 'AWS RDS'
</code></pre></td></tr><tr><td><p><strong>AWS Redshift cluster with network path from the untrust internet source</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies the AWS Redshift clusters with network path from the untrusted internet source.</p><p>Redshift clusters are AWS cloud-based data warehouses designed for data analysis and querying of large datasets. Allowing an AWS Redshift cluster to be reachable from any untrusted internet source increases the risk of unauthorized access and potential security breaches due to expanded attack surface.</p><p>It is recommended to restrict traffic from untrusted IP addresses and limit the access to known hosts, services, or specific entities for the Redshift clusters.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network Config</p><pre><code>config from network where source.network = UNTRUST_INTERNET and dest.resource.type = 'PaaS' and dest.cloud.type = 'AWS' and dest.paas.service.type = 'AWS Redshift'
</code></pre></td></tr><tr><td><p><strong>Azure Microsoft Entra ID users can consent to apps accessing company data on their behalf not set to verified publishers</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies instances in the Microsoft Entra ID configuration where users in your Azure Microsoft Entra ID (formerly Azure Active Directory) can consent to applications accessing company data on their behalf, even if the applications are not from verified publishers.</p><p>Allowing unverified applications to access company data increases the likelihood of data breaches and unauthorized access, which could lead to the exposure of confidential information. Using unverified applications can lead to non-compliance with data protection regulations and undermine trust in the organization’s data handling practices.</p><p>As a best practice, it is recommended to configure the user consent settings to restrict access only to applications from verified publishers.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-active-directory-authorization-policy' AND json.rule = defaultUserRolePermissions.permissionGrantPoliciesAssigned[*] does not contain "ManagePermissionGrantsForSelf.microsoft-user-default-low"
</code></pre></td></tr><tr><td><p><strong>Azure Machine Learning compute instance not running latest OS Image Version</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies Azure Machine Learning compute instances not running on the latest available image version.</p><p>Running compute instances on outdated image versions increases security risks. Without the latest security patches and updates, these instances are more vulnerable to attacks, which can compromise machine learning models and data.</p><p>As a best practice, it is recommended to recreate or update Azure Machine Learning compute instances to the latest image version, ensuring they have the most recent security patches and updates.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-machine-learning-compute' AND json.rule = properties.provisioningState equal ignore case "Succeeded" and properties.properties.state equal ignore case "Running" and properties.properties.osImageMetadata.isLatestOsImageVersion is false
</code></pre></td></tr><tr><td><p><strong>Azure Network Watcher not enabled</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies Azure subscription regions where Network Watcher is not enabled.</p><p>Azure Network Watcher provides tools to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network. Without Network Watcher enabled, you lose critical capabilities to monitor and diagnose network issues, making it difficult to identify and resolve performance bottlenecks, network security rules, and connectivity issues.</p><p>As a best practice, it is recommended to enable Azure Network Watcher for your region to leverage its monitoring and diagnostic capabilities.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-watcher-list' AND json.rule = provisioningState equals Succeeded as X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>Azure SQL server public network access setting is enabled</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies Azure SQL servers which have public network access setting enabled.</p><p>Publicly accessible SQL servers are vulnerable to external threats with risk of unauthorized access or may remotely exploit any vulnerabilities.</p><p>It is recommended to configure the SQL servers with IP-based strict server-level firewall rules or virtual-network rules or private endpoints so that servers are accessible only to restricted entities.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-sql-server-list' AND json.rule = ['sqlServer'].['properties.state'] equal ignore case Ready and ['sqlServer'].['properties.publicNetworkAccess'] equal ignore case Enabled and ['sqlServer'].['properties.privateEndpointConnections'] is empty and firewallRules[*] is empty
</code></pre></td></tr><tr><td><p><strong>Azure PostgreSQL flexible server secure transport parameter is disabled</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies PostgreSQL flexible servers for which secure transport (SSL connectivity) parameter is disabled.</p><p>Secure transport (SSL connectivity) helps to provide a new layer of security, by connecting server to client applications using Secure Sockets Layer (SSL). Enforcing SSL connections between server and client applications helps protect against ‘man in the middle’ attacks by encrypting the data stream between the server and application.</p><p>As a security best practice, it is recommended to enable secure transport parameter for Azure PostgreSQL flexible server.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-postgresql-flexible-server' AND json.rule = properties.state equal ignore case Ready and require_secure_transport.value does not equal ignore case on
</code></pre></td></tr><tr><td><p><strong>Azure SQL server using insecure TLS version</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies Azure SQL servers which use insecure TLS version.</p><p>Enforcing TLS connections between database server and client applications helps protect against 'man in the middle' attacks by encrypting the data stream between the server and application.</p><p>As a security best practice, it is recommended to use the latest TLS version for Azure SQL server.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-sql-server-list' AND json.rule = ['sqlServer'].['properties.state'] equal ignore case "Ready" and (['sqlServer'].['properties.minimalTlsVersion'] equal ignore case "None" or ['sqlServer'].['properties.minimalTlsVersion'] equals "1.0" or ['sqlServer'].['properties.minimalTlsVersion'] equals "1.1")
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Function not enabled with VPC connector for network egress</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies GCP Cloud Functions that are not enabled with a VPC connector for network egress. This includes both Cloud Functions v1 and Cloud Functions v2.</p><p>Using a VPC connector for network egress in GCP Cloud Functions is crucial to prevent security risks such as data interception and unauthorized access. This practice strengthens security by allowing safe communication with private resources, enhancing traffic monitoring, reducing the risk of data leaks, and ensuring compliance with security policies.</p><p>It is recommended to configure GCP Cloud Functions with a VPC connector.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-cloud-function-v2' AND json.rule = state equals ACTIVE and serviceConfig.vpcConnector does not exist
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Function with overly permissive network ingress settings</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies GCP Cloud Functions that have overly permissive network ingress settings. This includes both Cloud Functions v1 and Cloud Functions v2.</p><p>Ingress settings control whether resources outside of your Google Cloud project or VPC Service Controls perimeter can invoke a function. With overly permissive ingress setting, all inbound requests to invoke function are allowed, both from the public and from resources within the same project. Restrictive network ingress settings for cloud functions in GCP minimize the risk of unauthorized access and attacks by limiting inbound traffic to trusted sources. This approach enhances security, prevents malicious activities, and ensures only legitimate traffic reaches your applications.</p><p>It is recommended to restrict the public traffic and allow traffic from VPC networks in the same project or traffic through the Cloud Load Balancer.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-cloud-function-v2' AND json.rule = state equals ACTIVE and serviceConfig.ingressSettings equals ALLOW_ALL
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Function v1 is using unsecured HTTP trigger</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies GCP Cloud Functions v1 that are using unsecured HTTP trigger.</p><p>Using HTTP triggers for cloud functions poses significant security risks, including vulnerability to interception, tampering, and various attacks like man-in-the-middle. Conversely, HTTPS triggers provide encrypted communication, safeguarding sensitive data and ensuring confidentiality. HTTPS also supports authentication mechanisms, enhancing overall security and trust.</p><p>It is recommended to enable 'Require HTTPS' for HTTP triggers for all cloud functions v1.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-cloud-function-v2' AND json.rule = environment equals GEN_1 and serviceConfig.securityLevel does not equal SECURE_ALWAYS
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Function is publicly accessible by allUsers or allAuthenticatedUsers</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies GCP Cloud Functions that are publicly accessible by allUsers or allAuthenticatedUsers.</p><p>Granting permissions to 'allusers' or 'allAuthenticatedUsers' on any resource in GCP makes the resource public. Public access over cloud functions can lead to unauthorized invocations of the function or leakage of sensitive information such as the function’s source code.</p><p>Following the least privileged access policy, it is recommended to grant access restrictively and avoid granting permissions to allUsers or allAuthenticatedUsers unless absolutely needed.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-cloud-function-v2' AND json.rule = state equals ACTIVE and iamPolicy.bindings[?any(members[*] is member of ("allAuthenticatedUsers","allUsers"))] exists
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Function is granted a basic role</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies GCP Cloud Functions that are granted a basic role. This includes both Cloud Functions v1 and Cloud Functions v2.</p><p>Basic roles are highly permissive roles that existed before the introduction of IAM and grant wide access over project to the grantee. The use of basic roles for granting permissions increases the blast radius and could help to escalate privilege further in case the Cloud Function is compromised.</p><p>Following the principle of least privilege, it is recommended to avoid the use of basic roles.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = roles[*] contains "roles/viewer" or roles[*] contains "roles/editor" or roles[*] contains "roles/owner" as X; config from cloud.resource where api.name = 'gcloud-cloud-function-v2' as Y; filter '$.Y.serviceConfig.serviceAccountEmail equals $.X.user'; show Y;
</code></pre></td></tr><tr><td><p><strong>OCI Object Storage Bucket write level logging is disabled</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>This policy identifies Object Storage buckets that have write-level logging disabled.</p><p>Enabling write-level logging for Object Storage provides more visibility into changes to objects in your buckets. Without write-level logging, there is no record of changes made to the bucket. This lack of visibility can lead to undetected data breaches, unauthorized changes, and compliance violations.</p><p>As a best practice, it is recommended to enable write-level logging on Object Storage buckets.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'oci-object-storage-bucket' as X; config from cloud.resource where api.name = 'oci-logging-logs' as Y; filter 'not ($.X.name contains $.Y.configuration.source.resource and $.Y.configuration.source.service contains objectstorage and $.Y.configuration.source.category contains write and $.Y.lifecycleState equal ignore case ACTIVE )'; show X;
</code></pre></td></tr><tr><td><p><strong>User with Administrative Permissions Has Active Access Keys Which Are Unused Over 90 Days</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>Identifies user accounts with administrative permissions for which active access keys exist and have not been used in at least 90 days. Access keys are long-term credentials which allow AWS IAM users programmatic access to resources. When the user in question possesses administrative permissions, and their access keys are active but not in use, they can potentially be found by an adversary, granting them administrative permissions.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.access.isAdministrative = true AND source.cloud.accesskey.lastused.days > 90 AND source.cloud.accesskey.activekeys > 0
</code></pre></td></tr><tr><td><p><strong>Cloud Service account with high privileges is inactive for 90 days and is assigned to a resource</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>Identifies cloud service accounts in Azure, AWS and GCP which have administrative permissions that have not been used in the last 90 days and are attached to a resource.</p><p>As opposed to user accounts, service accounts are predictable. Therefore, if a service account has administrative permissions which it has not used in the past 90 days, we can confidently say the resource it is attached to does not require them, and remove the permissions, decreasing the blast radius in case of a compromise of the service account.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount', 'service principal', 'user assigned', 'system assigned' ) AND action.access.isAdministrative = true AND grantedby.cloud.entity.lastlogin.days > 90 AND source.cloud.resource.type in ( 'instance', 'function', 'oidc-provider', 'environment', 'task-definition', 'WebIdentity', 'virtualMachines', 'sites', 'App Registration', 'service', 'workflows', 'virtualMachineScaleSets/virtualMachines', 'instances', 'applications', 'services', 'functions', 'serviceAccounts')
</code></pre></td></tr><tr><td><p><strong>User account with high privileges and MFA disabled</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>Identifies user accounts with administrative permissions for which Multi-Factor Authentication (MFA) is not enabled.</p><p>Sensitive accounts such as those with administrative permissions are considered high value to attackers and tend to be targeted.</p><p>As such, these accounts, when not safeguarded by an additional authentication factor, have a higher chance of successful compromise, which would result in the adversary gaining administrative permissions within your ogranization.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where action.access.isAdministrative = true AND source.cloud.resource.type = 'user' AND source.mfaenabled = False
</code></pre></td></tr><tr><td><p><strong>Third-Party Service Account with High Privileges at the Folder or Organization Level</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>Identifies instances of third-party vendor owned service accounts which are granted high privileges and may allow administrative access to your cloud environment.</p><p>This increases the attack surface, as in case of a compromise of the vendor’s environment, an attacker would gain elevated access to your account by abusing the service account permissions.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where dest.cloud.type = 'GCP' AND grantedby.cloud.entity.type = 'serviceaccount' AND action.access.isAdministrative = true AND source.cloud.account.isvendor = true AND grantedby.level.type IN ( 'GCP Organization', 'GCP Folder' )
</code></pre></td></tr><tr><td><p><strong>Service Account with Cross Cloud Administrative Access</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p>Identifies service accounts with permissions to assume an administrative role in another account hosted in a different cloud vendor environment.</p><p>Administrative permissions can result in the compromising of the security posture of your organization.</p><p>As the service account resides in a separate cloud vendor’s environment, a compromise of the source account could lead to lateral movement exposing the second account and enlarging the blast radius across cloud provider environments.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Policy Subtype—</strong> Permissions</p><pre><code>config from iam where source.cloud.type = 'GCP' AND dest.cloud.type = 'AWS' and action.access.isadministrative = True AND grantedby.cloud.entity.type = 'role'
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL and Metadata</strong></td><td></td></tr><tr><td><p><strong>AWS SageMaker endpoint data encryption at rest not configured with CMK</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p></td><td><p><strong>Changes—</strong> The policy name and description are updated.</p><p><strong>Current Policy Name—</strong> AWS SageMaker endpoint data encryption at rest not configured</p><p><strong>Updated Policy Name—</strong> AWS SageMaker endpoint data encryption at rest not configured with CMK</p><p><strong>Current Policy Description—</strong> This policy identifies AWS SageMaker Endpoints not configured with data encryption at rest.</p><p>AWS SageMaker Endpoint configuration defines the resources and settings for deploying machine learning models to SageMaker endpoints. By default, SageMaker Endpoints are not encrypted at rest. Enabling the encryption helps protect the integrity and confidentiality of the data on the storage volume attached to the ML compute instance that hosts the endpoint.</p><p>It is recommended to set encryption at rest to mitigate the risk of unauthorized access and potential data breaches.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS SageMaker Endpoints not configured with data encryption at rest.</p><p>AWS SageMaker Endpoint configuration defines the resources and settings for deploying machine learning models to SageMaker endpoints. By default, SageMaker encryption uses transient keys if a KMS key is not specified, which does not provide the control and management benefits of <strong>AWS Customer Managed KMS Key</strong>. Enabling the encryption helps protect the integrity and confidentiality of the data on the storage volume attached to the ML compute instance that hosts the endpoint.</p><p>It is recommended to set encryption at rest to mitigate the risk of unauthorized access and potential data breaches.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>GCP GKE unsupported Master node version</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy description and RQL are updated to narrow down resources based on currently supported GKE versions and remove false positives.</p><p><strong>Current Policy Description—</strong> Ensure your GKE Master node version is supported. This policy checks your GKE master node version and generates an alert if the version running is unsupported.</p><p><strong>Updated Policy Description—</strong> This policy identifies the GKE master node version and generates an alert if the version running is unsupported.</p><p>Using an unsupported version of Google Kubernetes Engine (GKE) on Google Cloud Platform (GCP) can lead to several potential issues and risks, such as security vulnerabilities, compatibility issues, performance and stability problems, and compliance concerns. To mitigate these risks, it’s crucial to regularly update the GKE clusters to supported versions recommended by Google Cloud.</p><p>As a security best practice, it is always recommended to use the latest version of GKE.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = isMasterVersionSupported exists AND isMasterVersionSupported does not equal "true"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentMasterVersion starts with "1.27." or currentMasterVersion starts with "1.28." or currentMasterVersion starts with "1.29." or currentMasterVersion starts with "1.30." )
</code></pre><p><strong>Impact—</strong> Low. Existing alerts will be resolved for the GKE clusters where the GKE major and minor versions are not end of life as per the GCP release schedule.</p></td></tr><tr><td><p><strong>GCP GKE unsupported node version</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy description and RQL are updated to narrow down resources based on currently supported GKE versions and remove false positives.</p><p><strong>Current Policy Description—</strong> Ensure your GKE node version is supported. This policy checks your GKE node version and generates an alert if the version running is unsupported.</p><p><strong>Updated Policy Description—</strong> This policy identifies the GKE node version and generates an alert if the version running is unsupported.</p><p>Using an unsupported version of Google Kubernetes Engine (GKE) on Google Cloud Platform (GCP) can lead to several potential issues and risks, such as security vulnerabilities, compatibility issues, performance and stability problems, and compliance concerns. To mitigate these risks, it’s crucial to regularly update the GKE clusters to supported versions recommended by Google Cloud.</p><p>As a security best practice, it is always recommended to use the latest version of GKE.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = isNodeVersionSupported exists AND isNodeVersionSupported does not equal "true"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentNodeVersion starts with "1.27." or currentNodeVersion starts with "1.28." or currentNodeVersion starts with "1.29." or currentNodeVersion starts with "1.30." )
</code></pre><p><strong>Impact—</strong> Low. Existing alerts will be resolved for the GKE clusters where the GKE major and minor versions are not end of life as per the GCP release schedule.</p></td></tr><tr><td><p><strong>AWS Secret Manager Secret that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS Secret Manager Secret that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS Secret Manager Secret is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS Secret Manager Secret resources which are publicly accessible through IAM policies. Ensure that the AWS Secret Manager Secret resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS Secret Manager Secrets with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'secretsmanager' and dest.cloud.resource.type = 'Secret' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'secretsmanager' and dest.cloud.resource.type = 'Secret' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS KMS Key that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS KMS Key that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS KMS Key is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS KMS Key resources which are publicly accessible through IAM policies. Ensure that the AWS KMS Key resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS KMS Keys with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'kms' AND dest.cloud.resource.type = 'key' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'kms' AND dest.cloud.resource.type = 'key' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS Lambda Layer Version that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS Lambda Layer Version that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS Lambda Layer Version is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS Lambda Layer Version resources which are publicly accessible through IAM policies. Ensure that the AWS AWS Lambda Layer Version resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS Lambda Layer Versions with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> Critical</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'lambda' AND dest.cloud.resource.type = 'layerVersion' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'AWS:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist)
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'lambda' AND dest.cloud.resource.type = 'layerVersion' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS SQS Queue that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS SQS Queue that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS SQS Queue is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS SQS Queue resources which are publicly accessible through IAM policies. Ensure that the AWS SQS Queue resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS SQS Queues with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'sqs' AND dest.cloud.resource.type = 'queue' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'sqs' AND dest.cloud.resource.type = 'queue' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS SNS Topic that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS SNS Topic that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS SNS Topic is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS SNS Topic resources which are publicly accessible through IAM policies. Ensure that the AWS SNS Topic resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS SNS Topics with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'sns' AND dest.cloud.resource.type = 'topic' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'sns' AND dest.cloud.resource.type = 'topic' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS ECR Repository that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS ECR Repository that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS ECR Repository is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS ECR Repository resources which are publicly accessible through IAM policies. Ensure that the AWS ECR Repository resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS ECR Repositories with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'ecr' AND dest.cloud.resource.type = 'repository' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 'ecr' AND dest.cloud.resource.type = 'repository' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS S3 bucket with data destruction permissions is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS S3 bucket with data destruction permissions is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS S3 Bucket with Data Destruction Permissions is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> Having a publicly accessible AWS S3 bucket with the 's3:DeleteBucket' permission can be extremely risky. This permission allows anyone with access to the bucket to delete the bucket with all objects inside. If unauthorized access or compromise occurs, it could result in intentional or accidental data destruction, leading to permanent loss of important or sensitive information stored in the bucket.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS S3 Buckets with Resource-based policies which allow all principals and the 's3:DeleteBucket' permission. This configuration could grant anyone with access to the bucket the ability to delete it together with all objects inside, potentially leading to permanent loss of information stored in the bucket.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 's3' AND dest.cloud.resource.type = 'bucket' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist AND action.name IN ( 's3:DeleteBucket' ))
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 's3' AND dest.cloud.resource.type = 'bucket' AND grantedby.cloud.policy.condition does not exist AND action.name IN ( 's3:DeleteBucket' )
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS S3 bucket that is publicly accessible through IAM policies</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and RQL are updated to take into account all resource-based policy conditions to ensure full coverage.</p><p><strong>Current Policy Name—</strong> AWS S3 bucket that is publicly accessible through IAM policies</p><p><strong>Updated Policy Name—</strong> AWS S3 bucket is Publicly Accessible Through Resource-Based Policies</p><p><strong>Current Policy Description—</strong> This policy identifies the AWS S3 bucket resources which are publicly accessible through IAM policies. Ensure that the AWS S3 bucket resources provisioned in your AWS account are not publicly accessible from the Internet to avoid sensitive data exposure and minimize security risks.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS S3 Buckets with Resource-based policies which allow all principals. This configuration creates a risk of sensitive information exposure.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 's3' AND dest.cloud.resource.type = 'bucket' AND grantedby.cloud.policy.condition ( 'aws:SourceArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:VpcSourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:username' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:userid' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpc' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceVpce' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIp' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceIdentity' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalArn' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:SourceOwner' ) does not exist AND grantedby.cloud.policy.condition ( 'kms:CallerAccount' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:PrincipalOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgID' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceOrgPaths' ) does not exist AND grantedby.cloud.policy.condition ( 'aws:ResourceAccount' ) does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' and source.public = true AND dest.cloud.service.name = 's3' AND dest.cloud.resource.type = 'bucket' AND grantedby.cloud.policy.condition does not exist
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Third-party service account can assume a service account with high privileges</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy description and RQL are updated to add support for GCP service accounts</p><p><strong>Current Policy Description—</strong> This policy identifies instances where third-party vendors are granted the ability to assume roles with high privileges and may allow significant administrative access to your cloud environment. Such permissions can potentially lead to unauthorized access or escalation of privileges, compromising the security posture of your organization</p><p><strong>Updated Policy Description—</strong> This policy identifies instances where third-party vendors are granted the ability to assume or impersonate roles with high privileges and may allow significant administrative access to your cloud environment. Such permissions can potentially lead to unauthorized access or escalation of privileges, compromising the security posture of your organization.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> IAM</p><p><strong>Current RQL—</strong></p><pre><code>config from iam where dest.cloud.type = 'AWS' AND grantedby.cloud.entity.type = 'role' AND action.access.isAdministrative = true AND source.cloud.account.isvendor = true
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from iam where grantedby.cloud.entity.type IN ( 'role', 'serviceaccount' ) AND action.access.isadministrative = true AND source.cloud.account.isvendor = true
</code></pre><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><p><strong>AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0)</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0)</p><p><strong>Updated Policy Name—</strong> AWS EC2 instance with network path from the internet (0.0.0.0/0)</p><p><strong>Current Policy Description—</strong> This policy identifies AWS EC2 instances that are internet reachable with unrestricted access (0.0.0.0/0). EC2 instances with unrestricted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS EC2 instances with network path from the internet (0.0.0.0/0).</p><p>AWS EC2 instances with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</p><p><strong>Updated Policy Name—</strong> AWS EC2 instance with network path from the internet (0.0.0.0/0) on ports 80/443</p><p><strong>Current Policy Description—</strong> This policy identifies AWS EC2 instances that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). EC2 instances with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS EC2 instances with network path from the internet (0.0.0.0/0) on ports 80/443.</p><p>AWS EC2 instances with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits. Port 80 and 443 are frequently targeted ports and utilized for HTTP and HTTPS protocols, making them susceptible to attacks like cross-site scripting, SQL injections, cross-site request forgeries, and DDoS attacks.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports</p><p><strong>Updated Policy Name—</strong> AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports</p><p><strong>Current Policy Description—</strong> This policy identifies AWS EC2 instances that are internet reachable with unrestricted access (0.0.0.0/0) to Admin ports (22 / 3389). EC2 instances with unrestricted access to the internet for admin ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS EC2 instances with network path from the internet (0.0.0.0/0) on ports 22/3389.</p><p>AWS EC2 instances with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits. Port 22 and 2289 are frequently targeted ports and utilized for remote access using SSH and RDP protocols respectively, making them susceptible to attacks like brute force and vulnerability exposure/exploitation.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS EC2 instance that is reachable from untrust internet source to ports with high risk</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> AWS EC2 instance that is reachable from untrust internet source to ports with high risk</p><p><strong>Updated Policy Name—</strong> AWS EC2 instance with network path from the untrust internet source on ports with high risk</p><p><strong>Current Policy Description—</strong> This policy identifies AWS EC2 instances that are internet reachable with untrust internet source to ports with high risk. EC2 instances with unrestricted access to the internet for high risky port may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS EC2 instances with network path from the untrust internet source on ports with high risk.</p><p>AWS EC2 instances with network path from the untrust internet source on ports with high risk increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>AWS EC2 instance with unrestricted outbound access to internet</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> AWS EC2 instance with unrestricted outbound access to internet</p><p><strong>Updated Policy Name—</strong> AWS EC2 instance with network path to the internet (0.0.0.0/0)</p><p><strong>Current Policy Description—</strong> This policy identifies EC2 instances that allow unrestricted outbound traffic to the internet. As a best practice, restrict outbound traffic and limit the access to known hosts or services.</p><p><strong>Updated Policy Description—</strong> This policy identifies AWS EC2 instances with network path to the internet (0.0.0.0/0).</p><p>AWS EC2 instances with network path to the internet increases the risk of cyber attacks, crypto mining and data breaches which can be used by malicious actors. Such instances are especially prone to data exfiltration or mining exploits.</p><p>As a best practice, restrict traffic to unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure Cosmos DB (PaaS) instance reachable from untrust internet source</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure Cosmos DB (PaaS) instance reachable from untrust internet source</p><p><strong>Updated Policy Name—</strong> Azure Cosmos DB (PaaS) instance with network path from the untrust internet source</p><p><strong>Current Policy Description—</strong> This policy identifies Azure Cosmos DB (PaaS) instances that are internet reachable from untrust internet source. Cosmos DB (PaaS) instances with untrusted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from untrusted IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure Cosmos DB (PaaS) instances with network path from the untrust internet source.</p><p>Cosmos DB (PaaS) instances with network path from the untrust internet source may enable bad actors to use brute force or exploit a vulnerability on a system to gain unauthorized access. Further database vulnerabilities or weaknesses could potentially be exploited to compromise the integrity, availability, or confidentiality of the data stored.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure MySQL (PaaS) instance reachable from untrust internet source on TCP port 3306</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure MySQL (PaaS) instance reachable from untrust internet source on TCP port 3306</p><p><strong>Updated Policy Name—</strong> Azure MySQL (PaaS) instance with network path from the untrust internet source on TCP port 3306</p><p><strong>Current Policy Description—</strong> This policy identifies Azure MySQL (PaaS) instances that are internet reachable from untrust internet source on TCP port 3306. MySQL (PaaS) instances with untrusted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from untrusted IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure MySQL (PaaS) instance with network path from the untrust internet source on TCP port 3306.</p><p>Azure MySQL (PaaS) instance with network path from the untrust internet source on TCP port 3306 may enable bad actors to use brute force or exploit a vulnerability on a system to gain unauthorized access. Further database vulnerabilities or weaknesses could potentially be exploited to compromise the integrity, availability, or confidentiality of the data stored.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure PostgreSQL (PaaS) instance reachable from untrust internet source on TCP port 5432</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure PostgreSQL (PaaS) instance reachable from untrust internet source on TCP port 5432</p><p><strong>Updated Policy Name—</strong> Azure PostgreSQL (PaaS) instance with network path from the untrust internet source on TCP port 5432</p><p><strong>Current Policy Description—</strong> This policy identifies Azure PostgreSQL (PaaS) instances that are internet reachable from untrust internet source on TCP port 5432. PostgreSQL (PaaS) instances with untrusted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from untrusted IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure PostgreSQL (PaaS) instance with network path from the untrust internet source on TCP port 5432.</p><p>Azure PostgreSQL (PaaS) instance with network path from the untrust internet source on TCP port 5432 may enable bad actors to use brute force or exploit a vulnerability on a system to gain unauthorized access. Further database vulnerabilities or weaknesses could potentially be exploited to compromise the integrity, availability, or confidentiality of the data stored.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure SQL Server (PaaS) reachable from any untrust internet source</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure SQL Server (PaaS) reachable from any untrust internet source</p><p><strong>Updated Policy Name—</strong> Azure SQL Server (PaaS) with network path from the untrust internet source</p><p><strong>Current Policy Description—</strong> This policy identifies Azure SQL Servers (PaaS) that are internet reachable from any untrust internet source. SQL Server instances with untrusted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from untrusted IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure SQL Server (PaaS) with network path from the untrust internet source.</p><p>Azure SQL Server (PaaS) with network path from the untrust internet source may enable bad actors to use brute force or exploit a vulnerability on a system to gain unauthorized access. Further database vulnerabilities or weaknesses could potentially be exploited to compromise the integrity, availability, or confidentiality of the data stored.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure Virtual Machine in running state that is internet reachable with unrestricted access (0.0.0.0/0)</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure Virtual Machine in running state that is internet reachable with unrestricted access (0.0.0.0/0)</p><p><strong>Updated Policy Name—</strong> Azure Virtual Machine with network path from the internet (0.0.0.0/0)</p><p><strong>Current Policy Description—</strong> This policy identifies Azure Virtual Machines in running state that are internet reachable with unrestricted access (0.0.0.0/0). Virtual Machines with unrestricted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure Virtual Machines with network path from the internet (0.0.0.0/0).</p><p>Azure Virtual Machines with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure Virtual Machine reachable from any untrust internet source to ports with high risk</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure Virtual Machine reachable from any untrust internet source to ports with high risk</p><p><strong>Updated Policy Name—</strong> Azure Virtual Machine with network path from the untrust internet source on ports with high risk</p><p><strong>Current Policy Description—</strong> This policy identifies Azure Virtual machines that are reachable from any untrust internet source to ports with high risk. Azure VMs with untrust access to ports with high risk may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure Virtual Machines with network path from the untrust internet source on ports with high risk.</p><p>Azure Virtual Machines with network path from the untrust internet source on ports with high risk increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</p><p><strong>Updated Policy Name—</strong> Azure Virtual Machine with network path from the internet (0.0.0.0/0) on ports 80/443</p><p><strong>Current Policy Description—</strong> This policy identifies Azure Virtual Machines that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). Azure Virtual Machines with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure Virtual Machines with network path from the internet (0.0.0.0/0) on ports 80/443.</p><p>Azure Virtual Machines with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits. Port 80 and 443 are frequently targeted ports and utilized for HTTP and HTTPS protocols, making them susceptible to attacks like cross-site scripting, SQL injections, cross-site request forgeries, and DDoS attacks.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</p><p><strong>Updated Policy Name—</strong> Azure Virtual Machine with network path from the internet (0.0.0.0/0) on Admin ports</p><p><strong>Current Policy Description—</strong> This policy identifies Azure Virtual Machines that are internet reachable with unrestricted access (0.0.0.0/0) to admin ports. Azure VMs with unrestricted internet access to admin ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies Azure Virtual Machines with network path from the internet (0.0.0.0/0) on Admin ports.</p><p>Azure Virtual Machines with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits. Admin ports can increase opportunities for malicious activities such as hacking, Man-In-The-Middle attacks (MITM), and brute-force attacks</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0)</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0)</p><p><strong>Updated Policy Name—</strong> GCP VM instance with network path from the internet (0.0.0.0/0)</p><p><strong>Current Policy Description—</strong> This policy identifies GCP VM instances that are internet reachable with unrestricted access (0.0.0.0/0). VM instances with unrestricted access to the internet may enable bad actors to use brute force on a system to gain unauthorised access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit the access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies GCP VM instances with network path from the internet (0.0.0.0/0).</p><p>GCP VM instances with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443</p><p><strong>Updated Policy Name—</strong> GCP VM instance with network path from the internet (0.0.0.0/0) on ports 80/443</p><p><strong>Current Policy Description—</strong> This policy identifies GCP VM instances that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). GCP VM instances with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies GCP VM instances with network path from the internet (0.0.0.0/0) on ports 80/443.</p><p>GCP VM instances with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits. Port 80 and 443 are frequently targeted ports and utilized for HTTP and HTTPS protocols, making them susceptible to attacks like cross-site scripting, SQL injections, cross-site request forgeries, and DDoS attacks.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389</p><p><strong>Updated Policy Name—</strong> GCP VM instance with network path from the internet (0.0.0.0/0) on Admin ports</p><p><strong>Current Policy Description—</strong> This policy identifies GCP VM instances that are internet reachable with unrestricted access (0.0.0.0/0) to Admin ports (22 / 3389). VM instances with unrestricted internet access to admin ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies GCP VM instances with network path from the internet (0.0.0.0/0) on ports 22/3389.</p><p>GCP VM instances with network path from the internet increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits. Port 22 and 2289 are frequently targeted ports and utilized for remote access using SSH and RDP protocols respectively, making them susceptible to attacks like brute force and vulnerability exposure/exploitation.</p><p>As a best practice, restrict traffic from unknown IP addresses and limit the access from known hosts, services, or specific entities.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>GCP VM instance that is reachable from untrust internet source to ports with high risk</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and recommendation metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> GCP VM instance that is reachable from untrust internet source to ports with high risk</p><p><strong>Updated Policy Name—</strong> GCP VM instance with network path from the untrust internet source on ports with high risk</p><p><strong>Current Policy Description—</strong> This policy identifies GCP VM instances that are reachable from untrust internet source to ports with high risk. VM instances with unrestricted access to the internet for high risky port may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.</p><p><strong>Updated Policy Description—</strong> This policy identifies GCP VM instances with network path from the untrust internet source on ports with high risk.</p><p>GCP VM instances with network path from the untrust internet source on ports with high risk increases the risk of unauthorized access, cyber attacks, and data breaches, as it may provide a larger attack surface for malicious actors. Such instances are especially prone to brute force or vulnerability exploits.</p><p>As a best practice, it is recommended to allow access from Trusted IP list and limit the access from known hosts, services, or specific entities.</p><p>Prisma Cloud Trusted IP List allows administrators to specify a list of IP addresses that are considered trusted or safe.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Network</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Google Workspace Super Admin not enrolled with 2-step verification</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Google Workspace Super Admin not enrolled with 2-step verification</p><p><strong>Updated Policy Name—</strong> GCP Google Workspace Super Admin not enrolled with 2-step verification</p><p><strong>Current Policy Description—</strong> This policy identifies Google Workspace Super Admin that do not have 2-Step Verification enabled. Super Admin accounts have access to all features in the Admin console and Admin API. It is recommended to enable 2-Step Verification for all Super Admins as it provides an additional layer of security in case account credentials are compromised.</p><p><strong>Updated Policy Description—</strong> This policy identifies Google Workspace Super Admins that do not have 2-Step Verification enabled.</p><p>Super Admin accounts have access to all features in the Admin console and Admin API. This additional layer of 2SV significantly reduces the risk of unauthorized access, protecting administrative controls and sensitive data from potential breaches. Implementing 2-Step Verification safeguards your entire Google Workspace environment, maintaining robust security and compliance standards.</p><p>It is recommended to enable 2-Step Verification for all Super Admins as it provides an additional layer of security in case account credentials are compromised.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr><tr><td><p><strong>Google Workspace User not enrolled with 2-step verification</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p></td><td><p><strong>Changes—</strong> The policy name, description, and metadata are revised as follows:</p><p><strong>Current Policy Name—</strong> Google Workspace User not enrolled with 2-step verification</p><p><strong>Updated Policy Name—</strong> GCP Google Workspace User not enrolled with 2-step verification.</p><p><strong>Current Policy Description—</strong> This policy identifies Google Workspace Users who do not have 2-Step Verification enabled. 2-Step Verification is a simple best practice that adds an extra layer of protection on top of username and password combination. It is recommended to enable 2-Step Verification for all users as it provides increased security for user account settings and resources.</p><p><strong>Updated Policy Description—</strong> This policy identifies Google Workspace Super Admins that do not have 2-Step Verification enabled.</p><p>Super Admin accounts have access to all features in the Admin console and Admin API. This additional layer of 2SV significantly reduces the risk of unauthorized access, protecting administrative controls and sensitive data from potential breaches. Implementing 2-Step Verification safeguards your entire Google Workspace environment, maintaining robust security and compliance standards.</p><p>It is recommended to enable 2-Step Verification for all Super Admins as it provides an additional layer of security in case account credentials are compromised.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> No impact on alerts.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                                    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>SEBI - Consolidated Cybersecurity and Cyber Resilience Framework (CSCRF)</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p> | <p>Prisma Cloud now supports Consolidated Cybersecurity and Cyber Resilience Framework (CSCRF) released by the Securities and Exchange Board of India (SEBI). CSCRF aims to establish a unified framework that encompasses various strategies to safeguard REs (Regulated Entities) and Market Infrastructure Institutions (MIIs) against cyber risks and incidents.</p><p>You can view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                                                                                                                                                                                                           |
| <p><strong>Secure Controls Framework (SCF) - 2024.2</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                 | <p>Prisma Cloud has been updated to incorporate support for the Secure Controls Framework (SCF) - 2024.2, providing a comprehensive approach to both cybersecurity and privacy practices for safeguarding organizational information assets. The SCF’s latest version elaborates on the refinement of current controls, introduces new controls tailored to counteract recent threats and technological advancements, ensures alignment with the most current compliance mandates, and integrates modifications driven by input from the community and industry professionals.</p><p>You can view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p> |
| <p><strong>NIST SP 800-171 Revision 3</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                               | <p>Prisma Cloud now supports the latest version of NIST SP 800-171 Revision 3. This updated includes significant updates to the publication’s control families, security controls and new Prisma cloud policies are mapped to the controls increasing the overall coverage.</p><p>You can view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                                                                                                                                                                                                                                                                                                    |
| <p><strong>Update for CIS AWS Foundation Benchmark</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                  | <p>New Policy mappings are added to both Level 1 and Level 2 of CIS AWS Foundation benchmark v2.0.0 and CIS AWS Foundation benchmark v3.0.0 to improve policy mapping coverage.</p><p><strong>Impact—</strong> As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Update for CIS Microsoft Azure Foundation Benchmark</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                      | <p>New Policy mappings are added to both Level 1 and Level 2 of CIS Microsoft Azure Foundation benchmark v2.0.0 and CIS AWS Foundation benchmark v2.1.0 to improve policy mapping coverage.</p><p><strong>Impact—</strong> As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Update for GDPR</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p>                                                          | <p>New Policy mappings are added to the GDPR compliance standard.</p><p><strong>Impact—</strong> As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CIS Controls v8.1</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                                                        | <p>Prisma Cloud now includes support for the CIS Critical Security Control v8.1 ensuring that your compliance monitoring is based on the latest cybersecurity best practices. This update introduces refined compliance checks, enhanced security profiles, improved reporting functionalities, and actionable remediation recommendations.</p><p>You can now view the built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                                                                                                                                                                                                                                 |

## REST API Updates

| **Change**                                                                                                       | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ---------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>Vulnerabilities Dashboard API</strong></p><p><mark style="background-color:orange;">24.8.2</mark></p> | A new **View** query parameter is added to the [Get Vulnerabilities by RQL](https://pan.dev/prisma-cloud/api/cspm/vulnerabilities-search-api/) API. When searching for vulnerabilities using an RQL query, you can view the details by CVE or Asset. This parameter allows you to get the vulnerabilities details based on the CVE view or Asset view.                                                                                                             |
| <p><strong>Policy API</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>                    | <p>The following endpoints now have a <code>readOnly</code> response parameter to protect policies from unwanted edits.</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-policy/">Policy Info</a> - GET /policy/{id}</li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-policies/">List Policies</a> - GET /policy/</li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-policies-v-2/">List Policies V2</a> - GET /v2/policy</li></ul> |
| <p><strong>Search Manager API</strong></p><p><mark style="background-color:orange;">24.8.1</mark></p>            | <p>The following endpoints now have a <code>readOnly</code> response parameter to protect associated saved searches from unwanted edits.</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-history/">View Search History</a> - GET /search/history</li><li><a href="https://pan.dev/prisma-cloud/api/cspm/search-history-by-id/">Get Search Query by ID</a> - GET /search/history/{id}</li></ul>                                                    |

## Deprecation Notices

| **Change**                                                                                                                                                                                                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><mark style="background-color:orange;"><strong>End of Support for Azure Time Series Insights and Azure Data Catalog Services</strong></mark></p><p><mark style="background-color:orange;">24.8.2</mark></p> | <p>The following APIs are deprecated since Azure has announced the retirement of Azure Time Series Insights and Azure Data Catalog Services. Due to this deprecation, Prisma Cloud will no longer ingest metadata for the following APIs:</p><ul><li><code>azure-timeseriesinsights-environments</code></li><li><code>azure-datacatalog-catalog</code></li></ul><p>When running an RQL query, the key will not be available in the <code>api.name</code> attribute auto-completion.</p><p><strong>Impact—</strong> If you have a saved search or custom policies based on these APIs, you must delete them manually. The policy alerts will be resolved as <strong>Policy\_Deleted</strong>.</p> |

## End of Sale Notice

| **Feature**                    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Prisma Cloud Data Security** | <p>With the GA release of Prisma Cloud DSPM and AI-SPM, Prisma Cloud Data Security (PCDS) module is now in the End of Sale (EOS) status. Note the following important dates:</p><ul><li>PCDS EOS will be effective on August 31, 2024.</li><li>Prisma Cloud tenants will no longer be able to subscribe to the PCDS module after September 1, 2024.</li><li>PCDS subscribed tenants can continue to use the PCDS module until its End of Life.</li><li>End of Life/End of Support will be effective on August 31, 2025 (one year after EOS).</li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-august-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
