> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-december-2024.md).

# Features Introduced in December 2024

Learn what’s new on Prisma® Cloud in December 2024.

* [New Features](#new-features)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [IAM Policy Update](#iam-policy-update)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notice](#deprecation-notice)

## New Features

| **Feature**                                                                                                                                                                                                          | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Action Plans</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.12.1</mark></p>                                       | <p>Secure your cloud assets with enhanced efficiency with <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/action-plans">Prisma Cloud Action Plans</a>. Action Plans programmatically group multiple alerts related to a single affected asset into one actionable plan. Every Action Plans include a summary as well as specific remediation steps, tailored to effectively maximize risk reduction.</p><ul><li><strong>Prioritization</strong>—Action Plans group together alerts and assets that can be secured through a single fix, ensuring your security team spends time on the most effective outcomes. Actions are prioritized based on security context and Prisma Cloud alerts.</li><li><strong>Execution and Delegation</strong>—Leverage your integrations on Prisma Cloud to help delegate security fixes to your team through Jira tickets and/or Slack messages with a single click.</li><li><strong>Detailed Visibility</strong>—Ensure that every alert resolved or asset impacted is visible in one location, and provide detailed context to your security teams.</li><li><strong>Security Fix Efficiency</strong>—Using machine learning and generative models, Action Plans help summarize tasks across the various alerts that impact the same asset, ensuring that there is a comprehensive plan to reduce alerts with the least number of required steps.</li></ul><p>Action Plans is released in a phased rollout and will be available on all Prisma Cloud stacks by January 8, 2025.</p><p><img src="/files/9nuWv7HAeBk8SXJzMBxR" alt="" data-size="original"></p> |
| <p><strong>Search for Assets with Secrets</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.12.1</mark></p>                     | <p>The <strong>Secrets</strong> attributes within the <strong>Investigate > Asset</strong> search help you prioritize and find assets with secret exposure risks. Along with <strong>Finding</strong> and <strong>Vulnerability</strong>, you can now also use <strong>Secrets</strong> as a security context to identify Attack Paths in your environment. You can create custom policies based on the specific asset query.</p><p>In order to use the <strong>Secrets</strong> attributes, make sure you have enabled <strong>Agentless Scanning</strong> during onboarding.</p><p><img src="/files/0Zrfj7OtrGrXtUlyg48e" alt="" data-size="original"></p><p>You can view your search results in both Table and Graph modes. In the Table mode, a new <strong>View by: Secret</strong> allows you to view all the secret detections that match the query.</p><p><img src="/files/PJSFOwKOA3vUcenFoa9G" alt="" data-size="original"></p><p>In the Graph mode, each Secrets node is a representation of all the secret detections for that specific asset.</p><p><img src="/files/1E4IWZQtnNj0vIiwe5tQ" alt="" data-size="original"></p><p>To see all matching secret detections for the given asset, click on the <strong>Secrets</strong> node and then click <strong>View Details</strong>.</p><p><img src="/files/INVBvm8MRHMXjJaHTaeL" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                 |
| <p><strong>AISPM Compliance with OWASP Top 10 for LLM and NIST AI 600-1</strong></p><p><mark style="background-color:orange;">Secure the Data</mark></p><p><mark style="background-color:orange;">24.12.1</mark></p> | To empower your organization to proactively address the unique security, ethical, and regulatory challenges associated with AI deployments, Prisma Cloud AISPM now includes enhanced risk identification and compliance capabilities for AI and ML systems that aligns with two critical standards - OWASP Top 10 for Large Language Models (LLM) and NIST AI 600-1.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

## Changes in Existing Behavior

| **Feature**                                                                                                                       | **Description**                                                                                                                                                                                                                                                                                                                    |
| --------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon EC2 VPC Endpoint Service Count Updates</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p> | <p>Prisma Cloud will no longer ingest EC2 VPC Endpoint Services that are visible to, but not owned by AWS accounts. Only VPC Endpoint Services directly owned by an AWS account will be ingested.</p><p><strong>Impact—</strong> Low. Since the VPC Endpoint Services that will not be ingested are resources owned by Amazon.</p> |

## API Ingestions

| **Service**                                                                                                           | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| --------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon Cognito</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                    | <p><strong>aws-cognito-user-pool-client</strong></p><p>Additional permissions required:</p><ul><li><code>cognito-idp:ListUserPools</code></li><li><code>cognito-idp:ListUserPoolClients</code></li><li><code>cognito-idp:DescribeUserPoolClient</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                       |
| <p><strong>Amazon Data Lifecycle Manager</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>     | <p><strong>aws-dlm-lifecycle-policy</strong></p><p>Additional permissions required:</p><ul><li><code>dlm:GetLifecyclePolicies</code></li><li><code>dlm:GetLifecyclePolicy</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                           |
| <p><strong>Amazon EC2</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                        | <p><strong>aws-ec2-network-insights-analysis</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeNetworkInsightsAnalyses</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                       |
| <p><strong>Amazon EC2</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                        | <p><strong>aws-ec2-egress-only-internet-gateway</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeEgressOnlyInternetGateways</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                 |
| <p><strong>Amazon EventBridge</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                | <p><strong>aws-events-archive</strong></p><p>Additional permissions required:</p><ul><li><code>events:ListArchives</code></li><li><code>events:DescribeArchive</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                                                                                                        |
| <p><strong>Amazon EventBridge</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                | <p><strong>aws-events-connection</strong></p><p>Additional permissions required:</p><ul><li><code>events:ListConnections</code></li><li><code>events:DescribeConnection</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                                                                                               |
| <p><strong>Amazon IVS</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                        | <p><strong>aws-ivs-channel</strong></p><p>Additional permissions required:</p><ul><li><code>ivs:ListChannels</code></li><li><code>ivs:GetChannel</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                                                    |
| <p><strong>Amazon Lightsail</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                  | <p><strong>aws-lightsail-storage-bucket</strong></p><p>Additional permission required:</p><ul><li><code>lightsail:GetBuckets</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                                           |
| <p><strong>Amazon Lightsail Disk</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>             | <p><strong>aws-lightsail-disk</strong></p><p>Additional permission required:</p><ul><li><code>lightsail:GetDisks</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                                                       |
| <p><strong>Amazon MemoryDB</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                   | <p><strong>aws-memorydb-subnet-group</strong></p><p>Additional permissions required:</p><ul><li><code>memorydb:DescribeSubnetGroups</code></li><li><code>memorydb:ListTags</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                          |
| <p><strong>Amazon MemoryDB</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                   | <p><strong>aws-memorydb-snapshot</strong></p><p>Additional permissions required:</p><ul><li><code>memorydb:DescribeSnapshots</code></li><li><code>memorydb:ListTags</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                                 |
| <p><strong>AWS Application Migration Service</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p> | <p><strong>aws-mgn-source-server</strong></p><p>Additional permission required:</p><ul><li><code>mgn:DescribeSourceServers</code></li></ul><p>The Security Audit role does not include the above permission. You must manually update the CFT template to enable it.</p>                                                                                                                                                                             |
| <p><strong>AWS Fault Injection Service</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>       | <p><strong>aws-fis-experiment-template</strong></p><p>Additional permissions required:</p><ul><li><code>fis:ListExperimentTemplates</code></li><li><code>fis:GetExperimentTemplate</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                                                  |
| <p><strong>AWS Network Manager</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>               | <p><strong>aws-network-manager-global-network-site</strong></p><p>Additional permissions required:</p><ul><li><code>networkmanager:DescribeGlobalNetworks</code></li><li><code>networkmanager:GetSites</code></li></ul><p>The Security Audit role only includes <code>networkmanager:DescribeGlobalNetworks</code> permission.</p><p>You must manually include <code>networkmanager:GetSites</code> permission in the CFT template to enable it.</p> |
| <p><strong>Amazon Recycle Bin</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                | <p><strong>aws-recycle-bin-ebs-snapshot-rule</strong></p><p>Additional permissions required:</p><ul><li><code>rbin:ListRules</code></li><li><code>rbin:GetRule</code></li><li><code>rbin:ListTagsForResource</code></li></ul><p>The Security Audit role does not include the above permissions. You must manually update the CFT template to enable them.</p>                                                                                        |
| <p><strong>Amazon SageMaker</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                  | <p><strong>aws-sagemaker-notebook-instance-lifecycle-config</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListNotebookInstanceLifecycleConfigs</code></li><li><code>sagemaker:DescribeNotebookInstanceLifecycleConfig</code></li></ul><p>The Security Audit role includes the above permissions.</p>                                                                                                                    |
| <p><strong>Amazon S3</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                         | <p><strong>aws-s3-multi-region-access-point</strong></p><p>Additional permission required:</p><ul><li><code>s3:ListMultiRegionAccessPoints</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                             |
| <p><strong>Amazon Transcribe</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                 | <p><strong>aws-transcribe-transcription-job</strong></p><p>Additional permissions required:</p><ul><li><code>transcribe:ListTranscriptionJobs</code></li><li><code>transcribe:GetTranscriptionJob</code></li></ul><p>The Security Audit role only includes <code>transcribe:ListTranscriptionJobs</code> permission.</p><p>You must manually include <code>transcribe:GetTranscriptionJob</code> permission in the CFT template to enable it.</p>    |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>            | <p><strong>azure-active-directory-role-assignment-schedules</strong></p><p>Additional permission required:</p><ul><li><code>RoleAssignmentSchedule.Read.Directory</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                              |
| <p><strong>Azure Application Insights</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>        | <p><strong>azure-application-insights-workbooks</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Insights/Workbooks/Read</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                                              |
| <p><strong>Azure API Management</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>              | <p><strong>azure-api-management-service-subscriptions</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.ApiManagement/service/subscriptions/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                                           |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                 | <p><strong>azure-app-service-connections</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/connections/Read</code></li><li><code>Microsoft.Resources/subscriptions/resourceGroups/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                                                           |
| <p><strong>Azure Automation Accounts</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>         | <p><strong>azure-automation-account-hybrid-runbook-workers</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Automation/automationAccounts/read</code></li><li><code>Microsoft.Automation/automationAccounts/hybridRunbookWorkerGroups/hybridRunbookWorkers/read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                     |
| <p><strong>Azure Compute</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                     | <p><strong>azure-compute-restore-point-collections</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Compute/restorePointCollections/read</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                              |
| <p><strong>Azure Compute</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                     | <p><strong>azure-compute-proximity-placement-groups</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Compute/proximityPlacementGroups/read</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                            |
| <p><strong>Azure Machine Learning</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>            | <p><strong>azure-machine-learning-workspace-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.MachineLearningServices/workspaces/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                            |
| <p><strong>Azure Virtual WAN</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                 | <p><strong>azure-virtual-wan-virtual-hubs</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Network/virtualHubs/read</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                                                   |
| <p><strong>Google App Engine</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                 | <p><strong>gcloud-app-engine-service-version</strong></p><p>Additional permissions required:</p><ul><li><code>appengine.services.list</code></li><li><code>appengine.versions.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                                            |
| <p><strong>Google App Engine</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                 | <p><strong>gcloud-app-engine-service</strong></p><p>Additional permission required:</p><ul><li><code>appengine.services.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                                                   |
| <p><strong>Google App Engine</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                 | <p><strong>gcloud-app-engine-domain-mapping</strong></p><p>Additional permission required:</p><ul><li><code>appengine.applications.get</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                                         |
| <p><strong>Google Bigquery Data Policy</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>       | <p><strong>gcloud-bigquery-data-policy</strong></p><p>Additional permissions required:</p><ul><li><code>bigquery.dataPolicies.list</code></li><li><code>bigquery.dataPolicies.getIamPolicy</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                                                                    |
| <p><strong>Google Integration Connectors</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>     | <p><strong>gcloud-integration-connectors-endpoint-attachment</strong></p><p>Additional permission required:</p><ul><li><code>connectors.endpointAttachments.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                               |
| <p><strong>Google Integration Connectors</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>     | <p><strong>gcloud-integration-connectors-custom-connector-version</strong></p><p>Additional permissions required:</p><ul><li><code>connectors.customConnectors.list</code></li><li><code>connectors.customConnectorVersions.list</code></li></ul><p>The Viewer role includes the above permissions.</p>                                                                                                                                              |
| <p><strong>Google Integration Connectors</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>     | <p><strong>gcloud-integration-connectors-custom-connector</strong></p><p>Additional permission required:</p><ul><li><code>connectors.customConnectors.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                     |
| <p><strong>OCI Vaults</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                        | <p><strong>oci-vault-secret-versions</strong></p><p>Additional permissions required:</p><ul><li><code>SECRET\_INSPECT</code></li><li><code>SECRET\_VERSION\_INSPECT</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                                                                                                           |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>Alibaba Cloud VPC flow log not enabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies Virtual Private Clouds (VPCs) where flow logs are not enabled.</p><p>VPC flow logs capture information about the traffic entering and exiting network interfaces in the VPC. Without VPC flow logs, there is limited visibility into network traffic, making it challenging to detect and investigate suspicious activities, potential data breaches, or security policy violations. Enabling VPC flow logs enhances network monitoring, improves threat detection, and supports compliance requirements.</p><p>As a security best practice, it is recommended to enable VPC flow logs.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'alibaba_cloud' and api.name = 'alibaba-cloud-vpc' AND json.rule = vpcFlowLogs[*].flowLogId does not exist and status equal ignore case Available
</code></pre></td></tr><tr><td><p><strong>Alibaba Cloud OSS bucket logging not enabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies Alibaba Cloud Object Storage Service (OSS) buckets that do not have logging enabled.</p><p>Enabling logging for OSS buckets helps capture access and operation events, which are critical for security monitoring, troubleshooting, and auditing. Without logging, you lack visibility into who accesses and interacts with your bucket, potentially missing unauthorized access or suspicious behaviour.</p><p>As a security best practice, it is recommended to enable logging for OSS buckets.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'alibaba_cloud' and api.name = 'alibaba-cloud-oss-bucket-info' AND json.rule = bucket.logging.targetBucket does not exist
</code></pre></td></tr><tr><td><p><strong>AWS ECR private repository with cross-account access</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies AWS ECR private repository that are configured with cross-account access.</p><p>An ECR repository is a storage location within Amazon Elastic Container Registry (ECR) where Docker container images are stored and managed. Granting cross-account access to an ECR repository risks unauthorized access and data exposure, requiring strict policy controls and monitoring.</p><p>It is recommended to implement strict access controls and allow only trusted entities to access to an ECR repository to mitigate security risks.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ecr-get-repository-policy' AND json.rule = policy.Statement[?any(Effect equals Allow and (Principal.AWS does not equal * and Principal does not equal * and Principal.AWS contains arn and Principal.AWS does not contain $.registryId))] exists
</code></pre></td></tr><tr><td><p><strong>AWS CloudWatch Log groups not encrypted by Customer Managed Key (CMK)</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies AWS CloudWatch Log groups that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using a CMK that is disabled.</p><p>A CloudWatch Log Group is a collection of log streams that share the same retention, monitoring, and access control settings. Encrypting with a Customer Managed Key (CMK) provides additional control over key rotation, management, and access policies compared to the default encryption.</p><p>As a security best practice, using CMK to encrypt your CloudWatch Log Groups is advisable as it gives you full control over the encrypted data.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'aws-cloudwatch-log-group' as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyManager does not equal CUSTOMER or (keyMetadata.keyManager equals CUSTOMER and keyMetadata.keyState equals Disabled) as Y; filter '($.X.kmsKeyId does not exist ) or ($.X.kmsKeyId exists and $.X.kmsKeyId equals $.Y.keyMetadata.arn)'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS MSK cluster public access is enabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies the Amazon Managed Streaming for Apache Kafka (Amazon MSK) Cluster is configured with public access enabled.</p><p>Amazon MSK gives you the option to turn on public access to the brokers of MSK clusters. When the AWS MSK Cluster is public there could be posibility that the data can be exposed publicly.</p><p>It is recommended to disable the public access on the AWS MSK cluster to prevent unathourized access and complaince requirements.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-msk-cluster' AND json.rule = brokerNodeGroupInfo.connectivityInfo.publicAccess.type does not equal "DISABLED"
</code></pre></td></tr><tr><td><p><strong>AWS FSX Windows filesystem is not configured with file access auditing</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies the AWS FSX Windows filesystem not configured FileAccessAuditLogLevel and FileShareAccessAuditLogLevel.</p><p>Amazon FSx for Windows File Server supports auditing of end-user access to files, folders, and file shares. FileAccessAuditLogLevel and FileShareAccessAuditLogLevel Both settings can be configured to log successful events, failed events, both, or neither, depending on your auditing requirements. Not configuring these audit logs can lead to undetected unauthorized access and non-compliance with security regulations.</p><p>It is recommended to configure both log access to files and folders and access to file shares according to your business requirements to ensure comprehensive logging, providing visibility, accountability, and compliance, and enabling effective monitoring and incident response capabilities.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'aws-fsx-file-system' AND json.rule = FileSystemType equals "WINDOWS" and ( WindowsConfiguration.AuditLogConfiguration.FileAccessAuditLogLevel equals "DISABLED" AND  WindowsConfiguration.AuditLogConfiguration.FileShareAccessAuditLogLevel equals "DISABLED")
</code></pre></td></tr><tr><td><p><strong>AWS EMR cluster is not enabled with termination protection</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies the AWS EMR Cluster that is not enabled with termination protection.</p><p>Termination protection protects your clusters from accidental termination, When termination protection is enabled, any attempt to terminate the cluster through the AWS Management Console, CLI, or API will be blocked unless the protection is explicitly disabled first. Termination protection useful for long-running or critical clusters where accidental termination could result in data loss or significant downtime.</p><p>It recommended to enable Termination protection on AWS EMR clusters from accidental termination.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-emr-describe-cluster' AND json.rule = status.state does not contain TERMINATING and terminationProtected is false
</code></pre></td></tr><tr><td><p><strong>AWS Lightsail Instance does not restrict traffic on admin ports</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies the AWS Lightsail instance having network rule with unrestricted access ("0.0.0.0/0" or "::/0") on port 22 or 3389.</p><p>The firewall in Amazon Lightsail manages inbound traffic permitted to connect to your instance via its public IP address, controlling access to specific IPs and ports. Leaving administrative ports open to unrestricted access increases the risk of unauthorized access, such as brute-force attacks, which can compromise the instance and expose sensitive data.</p><p>It is recommended to <strong>limit</strong> access to specific IP addresses in the firewall rules to reduce unauthorized access attempts.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'aws-lightsail-instance' AND json.rule = state.name contains "running" and networking.ports[?any( accessDirection equals inbound and (cidrs contains "0.0.0.0/0" or ipv6Cidrs contains "::/0") and (((toPort == 22 or fromPort == 22) or (toPort > 22 and fromPort &#x3C; 22)) or ((toPort == 3389 or fromPort == 3389) or (toPort > 3389 and fromPort &#x3C; 3389))))] exists
</code></pre></td></tr><tr><td><p><strong>AWS Security Group allows all ingress traffic on CIFS port (445)</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies Security groups that allow all traffic on port 445 used by Common Internet File System (CIFS).</p><p>Common Internet File System (CIFS) is a network file-sharing protocol that allows systems to share files over a network. unrestricted CIFS access can expose your data to unauthorized users, leading to potential security risks.</p><p>It is recommended to restrict CIFS port 445 access to only trusted networks to prevent unauthorized access and data breaches.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name= 'aws-ec2-describe-security-groups' AND json.rule = isShared is false and (ipPermissions[?any((ipRanges[*] contains 0.0.0.0/0 or ipv6Ranges[*].cidrIpv6 contains ::/0) and ((toPort == 445 or fromPort == 445) or (toPort > 445 and fromPort &#x3C; 445)))] exists)
</code></pre></td></tr><tr><td><p><strong>AWS Route53 Domain transfer lock is not enabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies the AWS Route53 domain which is not enabled with transfer lock.</p><p>Route 53 Domain Transfer Lock is a security feature that prevents unauthorised domain transfers by locking the domain at the registrar level. The feature sets the "clientTransferProhibited" flag, which is a registry setting enabled by the registrar to force all transfer requests to be rejected automatically. If Route 53 Domain Transfer Lock is disabled, your domain is vulnerable to unauthorized transfers, which can lead to service disruptions, data breaches, reputational damage, and financial loss.</p><p>It is recommended to enable Route 53 Domain Transfer Lock to prevent unauthorized domain transfers and protect your domain from potential security threats and disruptions.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-route53-domain' AND json.rule = statusList[*] does not contain "clientTransferProhibited"
</code></pre></td></tr><tr><td><p><strong>Azure Microsoft Entra ID account lockout threshold greater than 10</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies if the account lockout threshold for Microsoft Entra ID (formerly Azure AD) accounts is configured to allow more than 10 failed login attempts before the account is locked out.</p><p>A high lockout threshold (greater than 10) increases the risk of brute-force or password spray attacks, where attackers can attempt multiple passwords over time without triggering account lockouts, leaving accounts vulnerable to unauthorized access. Setting the lockout threshold to a reasonable value (e.g., less than or equal to 10) balances usability and security by limiting the number of login attempts before an account is locked, reducing exposure to attacks while preventing frequent unnecessary lockouts for legitimate users.</p><p>As a security best practice, it is recommended to configure the account lockout threshold to less than or equal to 10.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-active-directory-group-settings' and json.rule = values[?any( name equals LockoutThreshold and (value greater than 10 or value does not exist))] exists
</code></pre></td></tr><tr><td><p><strong>Azure Microsoft Entra ID account lockout duration less than 60 seconds</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies if the account lockout duration for Microsoft Entra ID (formerly Azure AD) accounts is configured to be less than 60 seconds. The lockout duration determines how long the account remains locked after exceeding the lockout threshold.</p><p>A lockout duration of less than 60 seconds increases the risk of brute-force or password spray attacks. Malicious actors can exploit a short lockout period to attempt multiple logins more frequently, increasing the likelihood of gaining unauthorized access. Configuring the lockout duration to be at least 60 seconds helps reduce the frequency of repeated login attempts during a brute-force attack, improving protection against such attacks while ensuring a reasonable delay for legitimate users after exceeding the threshold.</p><p>As a security best practice, it is recommended to configure the account lockout duration to greater than or equal to 60 seconds.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-active-directory-group-settings' and json.rule = values[?any(name equals LockoutDurationInSeconds and (value less than 60 or value does not exist))] exists
</code></pre></td></tr><tr><td><p><strong>Azure disk data access authentication mode not enabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies if the Data Access Authentication Mode for Azure disks is disabled. This mode is crucial for controlling how users upload or export Virtual Machine Disks by requiring an Azure Entra ID role to authorize such operations.</p><p>Without enabling this mode, users can create SAS tokens to export disks without stringent identity-based restrictions. This increases the risk of unauthorized disk access or data exposure, especially in environments handling sensitive data. Enabling the Data Access Authentication Mode ensures that only users with the appropriate Data Operator for Managed Disk role in Azure Entra ID can export or manage disks. This enhances data security by preventing unauthorized disk exports and restricting access to secure download URLs.</p><p>As a security best practice, it is recommended to enable data access authentication mode for Azure disks.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-disk-list' AND json.rule = dataAccessAuthMode does not equal ignore case AzureActiveDirectory and managedBy contains virtualMachines and provisioningState equal ignore case Succeeded
</code></pre></td></tr><tr><td><p><strong>Azure App Service basic authentication enabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies Azure App Services which have basic authentication enabled.</p><p>Basic Authentication allows local identity management for App Services without using a centralized identity provider like Azure Entra ID, posing a security risk by creating isolated identity systems that lack centralized control and are vulnerable to credential compromise and unauthorized access. Disabling Basic Authentication and integrating with a centralized solution like Azure Entra ID enhances security with stronger authentication, improved access management, and reduced attack risks.</p><p>As a security best practice, it is recommended to disable basic authentication for Azure App Services.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'azure-app-service-basic-publishing-credentials-policies' AND json.rule = properties.allow is true as X; config from cloud.resource where api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running as Y; filter '$.X.id contains $.Y.id'; show Y;
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Run function is using default service account with editor role</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Cloud Run functions that are using the default service account with the editor role.</p><p>GCP Compute Engine Default service account is automatically created upon enabling the Compute Engine API. This service account is granted the IAM basic Editor role by default, unless explicitly disabled. Assigning default service account with the editor role to cloud run functions could lead to privilege escalation. Granting minimal access rights helps in promoting a better security posture.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' and api.name = 'gcloud-projects-get-iam-user' AND json.rule = user contains "compute@developer.gserviceaccount.com" and roles[*] contains "roles/editor" as X; config from cloud.resource where api.name = 'gcloud-cloud-function-v2' AND json.rule = status equals ACTIVE and serviceConfig.serviceAccountEmail contains "compute@developer.gserviceaccount.com" as Y; filter ' $.X.user equals $.Y.serviceConfig.serviceAccountEmail '; show Y;
</code></pre></td></tr><tr><td><p><strong>GCP Spanner Databases not encrypted with CMEK</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Spanner databases that are not encrypted with a Customer-Managed Encryption Key (CMEK).</p><p>Google Cloud Spanner is a scalable, globally distributed, and strongly consistent database service. By using CMEK with Spanner, you retain complete control over the encryption keys protecting your sensitive data, ensuring that only authorized users with access to these keys can decrypt and access the information. Without CMEK, data is encrypted with Google-managed keys, which may not provide the level of control required for handling sensitive data in certain industries.</p><p>It is recommended to encrypt Spanner database data using a Customer-Managed Encryption Key (CMEK).</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-cloud-spanner-database' AND json.rule = state equal ignore case ready and encryptionConfig.kmsKeyNames does not exist
</code></pre></td></tr><tr><td><p><strong>GCP Spanner Database drop protection disabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Spanner Databases with drop protection disabled.</p><p>Google Cloud Spanner is a scalable, globally distributed, and strongly consistent database service. The Spanner database drop protection feature prevents accidental deletion of databases and configurations. Without drop protection enabled, a user error or malicious action could lead to irreversible data loss and service disruption for all applications relying on that Spanner instance.</p><p>It is recommended to enable drop protection on spanner database to prevent from accidental deletion.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' and api.name = 'gcloud-cloud-spanner-database' AND json.rule = state equal ignore case ready and enableDropProtection does not exist
</code></pre></td></tr><tr><td><p><strong>GCP SQL Instance not encrypted with CMEK</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP SQL Instances that are not encrypted with Customer Managed Encryption Keys (CMEK).</p><p>Using CMEK for SQL Instances provides greater control over data at rest encryption by allowing key rotation and revocation, which enhances security and helps meet compliance requirements. Encrypting SQL Instances with CMEK ensures better data privacy management.</p><p>It is recommended to use CMEK for SQL Instance encryption.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' and api.name = 'gcloud-sql-instances-list' AND json.rule = state equals "RUNNABLE" and diskEncryptionConfiguration.kmsKeyName does not exist
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench Instance has Secure Boot disabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench instances with Secure Boot disabled.</p><p>Secure Boot is a security feature that ensures only trusted, digitally signed software runs during the boot process, protecting against advanced threats such as rootkits and bootkits. By verifying the integrity of the bootloader and operating system, Secure Boot prevents unauthorized software from compromising the system at startup. Without Secure Boot, instances are vulnerable to persistent malware and unauthorized code that could compromise the system deeply.</p><p>It is recommended to enable Secure Boot for Vertex AI Workbench instances.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" AND shieldedInstanceConfig.enableSecureBoot is false
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench Instance JupyterLab interface access mode set to single user</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench Instances with JupyterLab interface access mode set to single user.</p><p>Vertex AI Workbench Instance can be accessed using the web-based JupyterLab interface. Access mode controls the control access to this interface. Allowing access to only a single user could limit collaboration, increase chances of credential sharing, and hinder security audits and reviews of the resource.</p><p>It is recommended to avoid single user access and make use of the service account access mode for workbench instances.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" and ( gceSetup.metadata.proxy-mode equals "mail" or gceSetup.metadata.proxy-user-mail exists )
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench Instance auto-upgrade is disabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench Instances that have auto-upgrade disabled.</p><p>Auto-upgrading Google Cloud Vertex environments ensures timely security updates, bug fixes, and compatibility with APIs and libraries. It reduces security risks associated with outdated software, enhances stability, and enables access to new features and optimizations.</p><p>It is recommended to enable auto-upgrade to minimize maintenance overhead and mitigate security risks.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-workbench-instance' AND json.rule = state equals "ACTIVE" and gceSetup.metadata.notebook-upgrade-schedule does not exist
</code></pre></td></tr><tr><td><p><strong>GCP SQL database instance deletion protection is disabled</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP SQL database instances that have deletion protection disabled.</p><p>Enabling instance deletion protection on GCP SQL databases is crucial for preventing accidental data loss, especially in production environments where an unintended deletion could disrupt services and impact business continuity. Deletion protection adds an extra safeguard, requiring intentional action to disable the setting before deletion, helping teams avoid costly downtime and ensuring the availability of essential data.</p><p>It is recommended to enable deletion protection on GCP SQL database instances to prevent accidental deletion.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = state equals "RUNNABLE" and deletionProtectionEnabled is false
</code></pre></td></tr><tr><td><p><strong>GCP Secrets Manager secret not encrypted with CMEK</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Secrets Manager secrets that are not encrypted with a Customer-Managed Encryption Key (CMEK).</p><p>GCP Secret Manager securely stores and controls access to API keys, passwords, certificates, and other sensitive data. By using CMEK with secrets, you retain complete control over the encryption keys protecting your sensitive data, ensuring that only authorized users with access to these keys can decrypt and access the information. Without CMEK, data is encrypted with Google-managed keys, which may not provide the level of control required for handling sensitive data in certain industries.</p><p>It is recommended to encrypt Secrets Manager secrets using a Customer-Managed Encryption Key (CMEK).</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-secretsmanager-secret' AND json.rule = replication.userManaged.replicas[*].customerManagedEncryption.kmsKeyName does not exist and replication.automatic.customerManagedEncryption.kmsKeyName does not exist
</code></pre></td></tr><tr><td><p><strong>GCP Secrets Manager secret not encrypted with CMEK</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy identifies GCP Secrets Manager secrets that are not encrypted with a Customer-Managed Encryption Key (CMEK).</p><p>GCP Secret Manager securely stores and controls access to API keys, passwords, certificates, and other sensitive data. By using CMEK with secrets, you retain complete control over the encryption keys protecting your sensitive data, ensuring that only authorized users with access to these keys can decrypt and access the information. Without CMEK, data is encrypted with Google-managed keys, which may not provide the level of control required for handling sensitive data in certain industries.</p><p>It is recommended to encrypt Secrets Manager secrets using a Customer-Managed Encryption Key (CMEK).</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-secretsmanager-secret' AND json.rule = replication.userManaged.replicas[*].customerManagedEncryption.kmsKeyName does not exist and replication.automatic.customerManagedEncryption.kmsKeyName does not exist
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>AWS EMR cluster is not enabled with local disk encryption</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>The policy is updated to exclude different <code>TERMINATED</code> states of the EMR cluster while triggering alerts to provide more accurate results.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-emr-describe-cluster' as X; config from cloud.resource where api.name = 'aws-emr-security-configuration' as Y; filter '($.X.status.state does not contain TERMINATING) and ($.X.securityConfiguration contains $.Y.name) and ($.Y.EncryptionConfiguration.EnableAtRestEncryption is true) and ($.Y.EncryptionConfiguration.AtRestEncryptionConfiguration.LocalDiskEncryptionConfiguration does not exist)' ; show X;
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-emr-describe-cluster' as X; config from cloud.resource where api.name = 'aws-emr-security-configuration' as Y; filter '($.X.status.state does not contain TERMINATING and $.X.status.state does not contain TERMINATED and $.X.status.state does not contain TERMINATED_WITH_ERRORS) and ($.X.securityConfiguration contains $.Y.name) and ($.Y.EncryptionConfiguration.EnableAtRestEncryption is true) and ($.Y.EncryptionConfiguration.AtRestEncryptionConfiguration.LocalDiskEncryptionConfiguration does not exist)' ; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Existing alerts where the state of the EMR cluster is <code>TERMINATED</code> or <code>TERMINATED_WITH_ERRORS</code> will be resolved.</p></td></tr><tr><td><p><strong>AWS EMR cluster is not enabled with local disk encryption using Custom key provider</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>The policy RQL is updated to exclude different <code>TERMINATED</code> states of the EMR cluster  while triggering alerts to provide more accurate results.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-emr-describe-cluster' as X; config from cloud.resource where api.name = 'aws-emr-security-configuration' as Y; filter '($.X.status.state does not contain TERMINATING) and ($.X.securityConfiguration equals $.Y.name) and ($.Y.EncryptionConfiguration.AtRestEncryptionConfiguration.LocalDiskEncryptionConfiguration exists and $.Y.EncryptionConfiguration.AtRestEncryptionConfiguration.LocalDiskEncryptionConfiguration.EncryptionKeyProviderType does not equal Custom)' ; show X;
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where api.name = 'aws-emr-describe-cluster' as X; config from cloud.resource where api.name = 'aws-emr-security-configuration' as Y; filter '($.X.status.state does not contain TERMINATING and $.X.status.state does not contain TERMINATED and $.X.status.state does not contain TERMINATED_WITH_ERRORS) and ($.X.securityConfiguration equals $.Y.name) and ($.Y.EncryptionConfiguration.AtRestEncryptionConfiguration.LocalDiskEncryptionConfiguration exists and $.Y.EncryptionConfiguration.AtRestEncryptionConfiguration.LocalDiskEncryptionConfiguration.EncryptionKeyProviderType does not equal Custom)'; show X;
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> Low. Existing alerts where the state of the EMR cluster is <code>TERMINATED</code> or <code>TERMINATED_WITH_ERRORS</code> will be resolved.</p></td></tr><tr><td><p><strong>GCP PostgreSQL instance database flag log_hostname is not set to off</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>The policy RQL is updated to not generate false positive alerts in case the <code>log_hostname</code> is not set by default.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = "state equals RUNNABLE and databaseVersion contains POSTGRES and (settings.databaseFlags[*].name does not contain log_hostname or settings.databaseFlags[?any(name contains log_hostname and value contains on)] exists)"
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = "state equals RUNNABLE and databaseVersion contains POSTGRES and settings.databaseFlags[?any(name contains log_hostname and value contains on)] exists"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Informational</p><p><strong>Impact–</strong> Low. Existing alerts where the <code>log_hostname</code> flag is not set will be resolved.</p></td></tr><tr><td><p><strong>GCP GKE unsupported node version</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>The policy RQL is updated to provide accurate results.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentNodeVersion starts with "1.27." or currentNodeVersion starts with "1.28." or currentNodeVersion starts with "1.29." or currentNodeVersion starts with "1.30."  or currentNodeVersion starts with "1.31.")
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = isNodeVersionSupported exists AND isNodeVersionSupported does not equal "true"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Medium. New alerts may be triggered when the GKE version is not supported since the policy RQL is updated to check for the complete version.</p></td></tr><tr><td><p><strong>GCP GKE unsupported Master node version</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>The policy RQL is updated to provide accurate results.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentNodeVersion starts with "1.27." or currentNodeVersion starts with "1.28." or currentNodeVersion starts with "1.29." or currentNodeVersion starts with "1.30."  or currentNodeVersion starts with "1.31.")
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = isMasterVersionSupported exists AND isMasterVersionSupported does not equal "true"
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Medium</p><p><strong>Impact–</strong> Medium. New alerts may be generated when the GKE version is not supported since the policy RQL is updated to check for the complete version.</p></td></tr><tr><td><p><strong>GCP VM instance with the external IP address</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>The policy description and recommendation steps are updated to provide better context. The policy RQL is updated to consider public IPv6 addresses assigned to GCP VM instances.</p><p><strong>Current Description–</strong></p><p>This policy identifies the VM instances with the external IP address associated. To reduce your attack surface, VM instances should not have public/external IP addresses. Instead, instances should be configured behind load balancers, to minimize the instance’s exposure to the internet.</p><p>This policy will not report instances created by GKE because some of them have external IP addresses and cannot be changed by editing the instance settings. Instances created by GKE should be excluded. These instances have names that start with 'gke-' and contains 'default-pool'.</p><p><strong>Updated Description–</strong></p><p>This policy identifies GCP VM instances that are assigned a public IP.</p><p>Using a public IP with a GCP VM exposes it directly to the internet, increasing the risk of unauthorized access and attacks. This makes the VM vulnerable to threats such as brute force attempts, DDoS attacks, and other malicious activities. To mitigate these risks, it is safer to use private IPs and secure access methods like VPNs or load balancers.</p><p>It is recommended to avoid assigning public IPs to VM instances.</p><p><strong>Current RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-instances-list' AND json.rule = status equals RUNNING and networkInterfaces[*].accessConfigs exists and (name does not start with gke- and name does not contain default-pool)
</code></pre><p><strong>Updated RQL–</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-instances-list' AND json.rule = name does not start with "gke-" and status equals RUNNING and (networkInterfaces[*].accessConfigs exists or networkInterfaces.ipv6AccessConfigs exists)
</code></pre><p><strong>Policy Type–</strong> Config</p><p><strong>Policy Severity–</strong> Low</p><p><strong>Impact–</strong> None. New alerts will be generated for the failing resources. This will cover the resources where a public IPv6 address is assigned to a VM.</p></td></tr><tr><td><strong>Policy Delete</strong></td><td></td></tr><tr><td><p><strong>GCP VM instance is assigned with public IP</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p></td><td><p>This policy is deleted and combined with <strong>GCP VM instance with the external IP address</strong> as a single policy.</p><p><strong>Impact–</strong> Low. Existing alerts will be resolved as <strong>POLICY_DELETED</strong>.</p></td></tr></tbody></table>

## IAM Policy Update

The remediation steps for the following IAM policies have been updated in 24.12.1 release.

* GCP Users and Machine Identities with IAM Metadata Write permissions are unused for 90 days
* GCP Users and Machine Identities with IAM Metadata Read permissions are unused for 90 days
* GCP Users and Machine Identities with IAM Data Write permissions are unused for 90 days
* GCP Users and Machine Identities with IAM Data Read permissions are unused for 90 daysGCP Groups and Service Accounts with IAM Metadata Write permissions are unused for 90 days
* GCP Groups and Service Accounts with IAM Metadata Read permissions are unused for 90 days
* GCP Groups and Service Accounts with IAM Data Write permissions are unused for 90 days
* GCP Groups and Service Accounts with IAM Data Read permissions are unused for 90 daysGCP Administrators with IAM permissions are unused for 90 daysGCP Users and Machine Identities with Administrative Permissions
* GCP Groups and Service Accounts with Administrative Permissions

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                                                                   | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>PCI DSS v4.0.1</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                                                                                         | <p>Prisma Cloud now supports the latest version of PCI DSS v4.0.1 compliance framework. This latest revision emphasizes a risk-based approach, incorporating new requirements that address evolving threats such as phishing and e-skimming attacks. Notably, the updated standard mandates stricter multi-factor authentication measures, increased password complexity, and enhanced controls for managing client-side scripts to safeguard against unauthorized modifications.</p><p>You can now access this built-in compliance standard and related policies on the <strong>Compliance > Standards</strong> page. Additionally, users can generate reports for immediate viewing or downloading, as well as set up scheduled reports to continuously monitor compliance with the PCI DSS v4.0.1 framework over time.</p> |
| <p><strong>ACSC Information Security Manual (ISM)</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>                                                                 | <p>Prisma Cloud now supports the latest version (September 2024) of ACSC Information Security Manual (ISM) compliance framework. This framework provides a structured approach for managing compliance risks, ensuring that sensitive information is safeguarded while adapting to changing regulations.</p><p>You can now access this built-in compliance standard and related policies on the <strong>Compliance > Standards</strong> page. Additionally, users can generate reports for immediate viewing or downloading, as well as set up scheduled reports to continuously monitor compliance with the ACSC Information Security Manual (ISM) framework over time.</p>                                                                                                                                                  |
| <p><mark style="background-color:orange;">Update</mark> <strong>MLPS 2.0, MLPS 2.0 (Level 2) & MLPS 2.0 (Level 3)</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p> | <p>New mappings are added for Multi-Level Protection Scheme 2.0 - MLPS 2.0, MLPS 2.0 (Level 2) & MLPS 2.0 (Level 3) compliance standards for enhanced coverage.</p><p><strong>Impact—</strong> As new mappings are added, compliance score may vary</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

## REST API Updates

| **Change**                                                                                                      | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Alert Evidence Graph</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p>        | <p>The Alert API <a href="https://pan.dev/prisma-cloud/api/cspm/get-alert-evidence-graph/">Alert Evidence Graph</a> - <code>GET /alert/v1/{id}/graph</code> includes two new properties in the <code>AlertEvidenceGraph</code> response object:</p><ul><li><code>CapabilityNode</code></li><li><code>PrimaryAssetNode{}</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Action Plan Management APIs</strong></p><p><mark style="background-color:orange;">24.12.1</mark></p> | <p>The following new endpoints are available in the Action Plan Management APIs:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/action-plan/list-action-plans/">List Action Plans</a> - POST /apm/api/v1/action-plan</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/update-an-action-plan/">Update Action Plan Status or Assignee</a> - PATCH /apm/api/v1/action-plan/{action-plan-id}/status-assignee</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/pdate-an-action-plan-feedback/">Update Action Plan Feedback</a> - PATCH /apm/api/v1/action-plan/{action-plan-id}/feedback</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/recommendation-summary-action-plan/">Recommendation Summary</a> - GET /apm/api/v1/action-plan/{action-plan-id}/recommendation-summary</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/action-plan-related-alerts">List Related Alerts</a> - GET /apm/api/v1/action-plan/{action-plan-id}/related-alerts</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/action-plan-impacted-assets/">List Impacted Assets</a> - GET /apm/api/v1/action-plan/{action-plan-id}/impacted-assets</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/action-plan-notification-service/">Send Notification</a> - POST /apm/api/v1/action-plan/{action-plan-id}/notification/ondemand</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/get-action-plan-names/">List Action Plan Names</a> - GET /apm/api/v1/action-plan/names</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/list-action-plans-names/">Suggest Filters</a> - POST /apm/api/v1/filter/action-plan/suggest</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/action-plan-business-criticality-assets/">List Filtered Critical Assets</a> - POST /apm/api/v1/critical-asset</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/action-plan-set-asset-criticality/">Set Asset Criticality</a> - POST /apm/api/v1/asset-criticality</li><li><a href="https://pan.dev/prisma-cloud/api/action-plan/action-plan-check-asset-criticality/">Check Asset Criticality</a> - GET /apm/api/v1/asset-criticality/{asset-id}</li></ul> |

## Deprecation Notice

| **Change**                                                                                                                                                                | **Description**                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><mark style="background-color:orange;"><strong>End of support for AWS Polly Voices API</strong></mark></p><p><mark style="background-color:orange;">24.12.1</mark></p> | <p><code>aws-polly-voices</code> API is planned for deprecation. Due to this change, Prisma Cloud will no longer ingest metadata for the <code>aws-polly-voices</code> API.</p><p>In RQL, the key will not be available in the <code>api.name</code> attribute auto-completion.</p><p><strong>Impact</strong>: If you have a saved search based on this API, you must manually delete it.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-december-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
