> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-march-2024.md).

# Features Introduced in March 2024

Learn what’s new on Prisma® Cloud in March 2024.

* [Announcement](#announcement)
* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notice](#deprecation-notice)

## Announcement

| **Feature**                     | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Prisma Cloud Darwin Release** | <p>The <strong>Prisma Cloud Darwin Release</strong> is now available for Prisma Cloud environments on all stacks. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.</p><p>With this change, your tenant will be updated with the new intuitive user interface and <a href="https://live.paloaltonetworks.com/t5/prisma-cloud-customer-videos/prisma-cloud-evolution-amp-transformation/ta-p/556596">rich set of security capabilities</a>. Refer to the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/">Enterprise Edition—Darwin</a> documentation.</p><p>Contact your Prisma Cloud Customer Success team for more details.</p> |

## New Features

| **Feature**                                                                                                                                                                                                                                                                    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Blobstore Scanning Defender Upgrade for Tanzu Customers</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                                                                                                         | Enhanced the existing `blobstore` scanning feature for Tanzu customers. As a part of this enhancement, existing `blobstore` scanning defenders will now appear disconnected and new defender instances will be automatically created to replace them. The disconnected `blobstore` will disappear after 24 hours as part of the retention process. This upgrade excludes Linux and Windows defenders (Full coverage defenders). If you have have configured `blobstore` scanning and assigned it to a specific `blobstore` defender after the release of 32.04, you are required to manually edit the configurations and change it to a newly created `blobstore` defender scanner. This release also supports a new tile - jammy for TAS.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Added Account ID Information to Defenders Dashboard</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                                                                                                             | The **Account ID** information is displayed on the Defenders dashboard under **Manage > Defenders**. It is also included in the downloadable .csv file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Enhanced Vulnerability Assessment Process</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                                                                                                                       | Prisma Cloud now has an enhanced vulnerability assessment process for applications installed through the OS. If Prisma Cloud cannot detect any vulnerabilities in the vendor feed, it automatically searches for third-party security data to ensure comprehensive security coverage. For a comprehensive list of the detected vulnerabilities, navigate to **Monitor > Vulnerabilities > Vulnerability Explorer**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>Exclude Go CVEs for Windows from the CVEs of UNIX-based Systems</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                                                                                                 | Prisma Cloud now excludes vulnerabilities found in Go packages that are specific to Windows from UNIX-based operating systems in **Vulnerability Explorer**. For a comprehensive list of the detected vulnerabilities, navigate to **Monitor > Vulnerabilities > Vulnerability Explorer**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Cloud Discovery and Exposure Management Enhancements in Prisma Cloud</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>                                          | <p>Prisma Cloud includes the following enhancements for Cloud Discovery and Exposure Management (CDEM):</p><ul><li><p><strong>Enhanced Subscription Process</strong>: Ensure precise scanning of internet-exposed resources by verifying or manually entering your DUNS number and associated Domains while <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/subscribe-to-cdem#enable-cdem-subscription">subscribing to CDEM</a>.</p><div><figure><img src="/files/wXCugmDTXLnPW0NJmApG" alt="duns n domains new subscriber 1"><figcaption></figcaption></figure></div></li><li><p><strong>Asset Snoozing Options</strong>: Choose to temporarily or permanently <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-discovery-exposure-management">snooze</a> your unmanaged (internet-exposed) assets while inspecting your assets in the <strong>Discovery and Exposure Management Dashboard</strong> widgets. Snoozing assets provide the flexibility to view your <strong>Active</strong> assets separately from the <strong>Snoozed</strong> assets on <strong>Inventory > Unmanaged Assets</strong>.</p><div><figure><img src="/files/aaux0bLymHhX22OU9tp6" alt="cdem snooze rn 1"><figcaption></figcaption></figure></div></li><li><strong>Download Unmanaged Assets</strong>: Download the comprehensive list of <strong>Unmanaged Assets</strong> filtered by <strong>Asset type</strong> in .csv format from <strong>Inventory > Unmanaged Assets</strong>, expanding from previous limitations to current page details.</li><li><p><strong>Flow Log Visualization</strong>: Explore the new <strong>Network Flow Log</strong> tab in the side panel while inspecting internet-exposed assets. Visualize traffic flow between internet-exposed (unmanaged) and secure (managed) assets to make informed decisions and take appropriate actions to secure the internet-exposed asset.</p><div><figure><img src="/files/EpgPWdJk5MgcZTB0upav" alt="cdem network flowlog rn 1"><figcaption></figcaption></figure></div></li></ul> |
| <p><strong>Onboard Google Workspace</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>                                                                                      | <p>Prisma Cloud now supports <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/onboard-gcp/onboard-gcp-workspace">onboarding of your Google Workspace</a> domains to Prisma Cloud to get security and visibility into your Workspace accounts. After successful onboarding, you can configure alert rules on Workspace related to multi-factor authentication policies and identify Workspace users that have MFA enabled or disabled.</p><p><img src="/files/VhTcjnhiD1up5WqHNnUd" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Save Widget Configurations as Saved Views</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>                                                                     | <p><strong>Prisma Cloud > Dashboards</strong> now offers the option to save your widget configurations as <strong>Saved Views</strong>. The following caveats apply:</p><ul><li>Views are no longer limited to a maximum of 20.</li><li>Saved Views are enabled by default for the persona (Cloud/Runtime/Application Security) you created them in. If you switch to another persona, the view is disabled but you have the option to re-enable it.</li></ul><p>Create <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/alerts/saved-views">Saved Views</a> to store select widget configurations for a customizable view of your security posture.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Alert Notification Delay Support for Push Integration Method</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>                                                  | The [Alert Notification Delay](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support) capability is now supported for all external integrations that use the **Push** integration method.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><mark style="background-color:orange;">Update</mark> <strong>Advanced Settings Option in AWS Cloud Account Onboarding</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p> | <p>While onboarding your AWS <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/onboard-aws/onboard-aws-account#:~:text=Click%20Next.-,Configure%20Account">Account</a> or <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/onboard-aws/onboard-aws-org#:~:text=Click%20Next.-,Configure%20Account">Organization</a> to Prisma Cloud, a new <strong>Use Tenant Specific External ID</strong> (optional) capability is now available under <strong>Advanced Settings</strong> during account configuration. When you select the <strong>Use Tenant Specific External ID</strong> checkbox, Prisma Cloud provides a unique auto-generated external ID at the tenant level for that particular AWS account or organization once you <strong>Download the CFT</strong>. You can use this optional capability both while onboarding a new as well as editing or updating an existing AWS account or organization.</p><p><img src="/files/q32TGKP9ek44CrypDonr" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><mark style="background-color:orange;">Update</mark> <strong>Policy Subtype Column Included in Downloaded .csv</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>        | On the Governance page if you filter by **Policy Subtype**, the column is now also displayed in the resulting .csv file when you select **Download policies data > Download detailed view**. Previously, the **Policy Subtype** column was displayed in the downloaded csv only on selecting **Download policies data > Download current view**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Prisma Cloud Code Security Scanner Extension Available for VS Code</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>                                                    | The Prisma Cloud Code Security scanner extension is now supported in [Visual Studio Code](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/ides/connect-vscode), offering convenient access to robust security scanning features directly within your coding environment, that allows you to detect and address security issues, including IaC misconfigurations, SCA vulnerabilities, secrets exposure, and license compliance. You can download the extension from the Visual Studio Code Marketplace or through the IDE extensions feature.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

## API Ingestions

| **Service**                                                                                                                                                                  | **API Details**                                                                                                                                                                                                                                                                                                                                            |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon SageMaker</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                         | <p><strong>aws-sagemaker-processing-job</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListProcessingJobs</code></li><li><code>sagemaker:DescribeProcessingJob</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                        |
| <p><strong>Amazon SageMaker</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                         | <p><strong>aws-sagemaker-code-repository</strong></p><p>Additional permissions required:</p><ul><li><code>sagemaker:ListCodeRepositories</code></li><li><code>sagemaker:DescribeCodeRepository</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                    |
| <p><strong>AWS Account Management</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                   | <p><strong>aws-account-contact-information</strong></p><p>Additional permission required:</p><ul><li><code>account:GetContactInformation</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                           |
| <p><strong>AWS Backup</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                               | <p><strong>aws-backup-protected-resources</strong></p><p>Additional permission required:</p><ul><li><code>backup:ListProtectedResources</code></li></ul><p>You must manually add the above permission to the CFT template to enable it.</p>                                                                                                                |
| <p><strong>Amazon EC2</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                               | <p><strong>aws-ec2-vpc-endpoint-connection-notification</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeVpcEndpointConnectionNotifications</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                             |
| <p><strong>AWS Glue</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                                 | <p><strong>aws-glue-job</strong></p><p>Additional permission required:</p><ul><li><code>glue:GetJobs</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                               |
| <p><strong>AWS Glue</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                                 | <p><strong>aws-glue-schema</strong></p><p>Additional permissions required:</p><ul><li><code>glue:ListSchemas</code></li><li><code>glue:GetSchema</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                                                    |
| <p><strong>AWS Security Hub</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                         | <p><strong>aws-securityhub-hub</strong></p><p>Additional permission required:</p><ul><li><code>securityhub:DescribeHub</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                             |
| <p><mark style="background-color:orange;">Update</mark> <strong>AWS Trusted Advisor</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p> | <p><strong>aws-trusted-advisor-check-result</strong></p><p>The API now includes the metadata field which was previously excluded.</p>                                                                                                                                                                                                                      |
| <p><strong>AWS WAF</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                                  | <p><strong>aws-waf-classic-global-ip-set</strong></p><p>Additional permissions required:</p><ul><li><code>waf:ListIPSets</code></li><li><code>waf:GetIPSet</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                        |
| <p><strong>AWS WAF</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                                  | <p><strong>aws-waf-classic-regional-ip-set</strong></p><p>Additional permissions required:</p><ul><li><code>waf-regional:ListIPSets</code></li><li><code>waf-regional:GetIPSet</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                    |
| <p><strong>AWS WAF</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                                  | <p><strong>aws-waf-v2-regional-ip-set</strong></p><p>Additional permissions required:</p><ul><li><code>wafv2:ListIPSets</code></li><li><code>wafv2:GetIPSet</code></li></ul><p>The Security Audit role includes the <code>wafv2:ListIPSets</code> permission.</p>                                                                                          |
| <p><strong>AWS WAF</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                                  | <p><strong>aws-waf-v2-global-ip-set</strong></p><p>Additional permissions required:</p><ul><li><code>wafv2:ListIPSets</code></li><li><code>wafv2:GetIPSet</code></li></ul><p>The Security Audit role includes the <code>wafv2:ListIPSets</code> permission.</p>                                                                                            |
| <p><strong>Azure Logic Apps</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                         | <p><strong>azure-logic-app-workflow-versions</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Logic/workflows/read</code></li><li><code>Microsoft.Logic/workflows/versions/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                 |
| <p><strong>Azure Database for MariaDB Server</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                        | <p><strong>azure-database-maria-db-server-firewall-rules</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.DBforMariaDB/servers/read</code></li><li><code>Microsoft.DBforMariaDB/servers/firewallRules/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                      |
| <p><strong>Azure Defender for Cloud</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                 | <p><strong>azure-defender-for-cloud-jit-network-access-policies</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Security/locations/jitNetworkAccessPolicies/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                 |
| <p><strong>Azure Cognitive Services</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                 | <p><strong>azure-cognitive-search-service</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Search/searchServices/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                             |
| <p><strong>Azure Recovery Services</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                                                  | <p><strong>azure-recovery-service-vault-backup-policies</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.RecoveryServices/Vaults/read</code></li><li><code>Microsoft.RecoveryServices/vaults/backupPolicies/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                |
| <p><mark style="background-color:orange;">Update</mark> <strong>Azure Compute</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>       | <p><strong>azure-vm-list</strong></p><p>The API is updated to include the <code>properties.osProfile.linuxConfiguration.patchSettings.patchMode</code> field in the JSON resource configuration. As part of this change, the <code>properties.osProfile.linuxConfiguration.patchSettings.patchMode</code> key is now available in RQL auto-completion.</p> |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Vertex AI</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>    | <p><strong>gcloud-vertex-ai-notebook-instance</strong></p><p>Prisma Cloud has updated the <strong>gcloud-vertex-ai-notebook-instance</strong> API to exclude the <strong>gcs\_backup\_sync\_last\_updated</strong> field from the resource configuration because it changes frequently causing too many resource snapshots.</p>                            |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Vertex AI</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>    | Prisma Cloud no longer requires access to the **notebooks.locations.list** permission to scan and monitor **gcloud-vertex-ai-notebook-environment** and **gcloud-vertex-ai-notebook-instance** APIs.                                                                                                                                                       |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>AWS RDS database instance not configured with encryption in transit</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS RDS database instances that are not configured with encryption in transit. This covers MySQL, SQL Server, PostgreSQL, MariaDB, and DB2 RDS instances. Enabling encryption is crucial to protect data as it moves through the network and enhances the security between clients and storage servers. Without encryption, sensitive data transmitted between your application and the database is vulnerable to interception by malicious actors. This could lead to unauthorized access, data breaches, and potential compromises of confidential information. It is recommended that data be encrypted while in transit to ensure its security and reduce the risk of unauthorized access or data breaches.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-rds-describe-db-instances' as X; config from cloud.resource where api.name = 'aws-rds-describe-db-parameter-groups' AND json.rule = (((dbparameterGroupFamily starts with "postgres" or dbparameterGroupFamily contains "sqlserver") and (['parameters'].['rds.force_ssl'].['parameterValue'] does not equal 1 or ['parameters'].['rds.force_ssl'].['parameterValue'] does not exist)) or ((dbparameterGroupFamily starts with "mariadb" or dbparameterGroupFamily starts with "mysql") and (parameters.require_secure_transport.parameterValue does not equal 1 or parameters.require_secure_transport.parameterValue does not exist)) or (dbparameterGroupFamily contains "db2-ae" and (parameters.db2comm.parameterValue does not equal ignore case "SSL" or parameters.db2comm.parameterValue does not exist))) as Y; filter '$.X.dbparameterGroups[*].dbparameterGroupArn equals $.Y.dbparameterGroupArn' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Cognito service role does not have identity pool verification</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies the AWS Cognito service role that does not have identity pool verification. AWS Cognito is an identity and access management service for web and mobile apps. AWS Cognito service roles define permissions for AWS services accessing resources. The 'aud' claim in a cognito service role is an identity pool token that specifies the intended audience for the token. If the aud claim is not enforced in the cognito service role trust policy, it could potentially allow tokens issued for one audience to be used to access resources intended for a different audience. This oversight increases the risk of unauthorized access, compromising access controls and elevating the potential for data breaches within the AWS environment. It is recommended to implement proper validation of the 'aud' claim by adding the 'aud' in the Cognito service role trust policy.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-list-roles' AND json.rule = role.assumeRolePolicyDocument.Statement[*].Action contains "sts:AssumeRoleWithWebIdentity" and role.assumeRolePolicyDocument.Statement[*].Principal.Federated contains "cognito-identity.amazonaws.com" and role.assumeRolePolicyDocument.Statement[*].Effect contains "Allow" and role.assumeRolePolicyDocument.Statement[*].Condition.StringEquals does not contain "cognito-identity.amazonaws.com:aud"
</code></pre></td></tr><tr><td><p><strong>AWS Cognito service role with wide privileges does not validate authentication</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies the AWS Cognito service role that has wide privileges and does not validate user authentication. AWS Cognito is an identity and access management service for web and mobile apps. AWS Cognito service roles define permissions for AWS services accessing resources. The 'amr' field in the service role represents how the user was authenticated. if the user was authenticated using any of the supported providers, the 'amr' will contain 'authenticated' and the name of the provider. Not validating the 'amr' field can allow an unauthenticated user (guest access) with a valid token signed by the identity-pool to assume the Cognito role. If this Cognito role has a '<strong>' wildcard in the action and resource, it could lead to lateral movement or unauthorized access. Ensuring limiting privileges according to business requirements can help in restricting unauthorized access and misuse of resources. It is recommended to limit the Cognito service role used for guest access to not have a '</strong>' wildcard in the action or resource.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-iam-list-roles' AND json.rule = role.assumeRolePolicyDocument.Statement[*].Action contains "sts:AssumeRoleWithWebIdentity" and role.assumeRolePolicyDocument.Statement[*].Principal.Federated contains "cognito-identity.amazonaws.com" and role.assumeRolePolicyDocument.Statement[*].Effect contains "Allow" and role.assumeRolePolicyDocument.Statement[*].Condition contains "cognito-identity.amazonaws.com:amr" and role.assumeRolePolicyDocument.Statement[*].Condition contains "unauthenticated" as X; config from cloud.resource where api.name = 'aws-iam-get-policy-version' AND json.rule = document.Statement[?any(Effect equals Allow and Action contains :* and Resource equals * )] exists as Y; filter "($.X.inlinePolicies[*].policyDocument.Statement[?(@.Effect=='Allow' &#x26;&#x26; @.Resource=='*')].Action contains :* ) or ($.X.attachedPolicies[*].policyArn intersects $.Y.policyArn)"; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Redshift cluster with a commonly used master username and public access setting enabled</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS Redshift clusters configured with commonly used master usernames like 'awsuser', 'administrator', or 'admin', and the public access setting is enabled. AWS Redshift, a managed data warehousing service typically stores sensitive and critical data. Allowing public access increases the risk of unauthorized access, data breaches, and potential malicious activities. Using standard usernames increases the risk of password brute-force attacks by potential intruders. As a recommended security measure, it is advised not to use commonly used usernames and to disable public access for the Redshift cluster.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-redshift-describe-clusters' AND json.rule = publiclyAccessible is true and masterUsername is member of ("awsuser","administrator","admin")
</code></pre></td></tr><tr><td><p><strong>AWS Redshift cluster is configured with public accessibility</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS Redshift clusters with the publicly accessible setting set to true. When Amazon Redshift clusters are made public, the likelihood of malicious activity increases, such as unauthorized access or Distributed Denial of Service (DDoS) attacks. As a security best practice, the public accessibility parameter of the Redshift cluster should be turned off.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-redshift-describe-clusters' AND json.rule = publiclyAccessible is true
</code></pre></td></tr><tr><td><p><strong>AWS CloudTrail S3 bucket encrypted with Customer Managed Key (CMK) that is scheduled for deletion</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS CloudTrail S3 buckets encrypted with Customer Managed Key (CMK) that is scheduled for deletion. CloudTrail logs contain account activity related to actions across your AWS infrastructure. These log files stored in Amazon S3 are encrypted by AWS KMS keys. Deleting keys in AWS KMS that are used by CloudTrail is a common defense evasion technique and could be a potential ransomware attacker activity. After a key is deleted, you can no longer decrypt the data that was encrypted under that key, which helps the attacker to hide their malicious activities. It is recommended to regularly monitor the key used for encryption to prevent accidental deletion.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name= 'aws-s3api-get-bucket-acl' AND json.rule = (sseAlgorithm contains "aws:kms" or sseAlgorithm contains "aws:kms:dsse") and kmsMasterKeyID exists as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyManager equal ignore case CUSTOMER and keyMetadata.keyState contains PendingDeletion as Y; config from cloud.resource where api.name = 'aws-cloudtrail-describe-trails' as Z; filter '$.X.kmsMasterKeyID contains $.Y.key.keyArn and $.Z.s3BucketName equals $.X.bucketName'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS SNS Topic not encrypted by Customer Managed Key (CMK)</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS SNS Topics that are not encrypted by Customer Managed Key (CMK). AWS SNS Topics are used to send notifications to subscribers and might contain sensitive information. SNS Topics are encrypted by default by a AWS managed key but users can specify CMK to get enhanced security, control over the encryption key and also comply with any regulatory requirements. As a security best practice use of CMK to encrypt your SNS Topics is advisable as it gives you full control over the encrypted data.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-sns-get-topic-attributes' AND json.rule = KmsMasterKeyId exists and KmsMasterKeyId equal ignore case "alias/aws/sns"
</code></pre></td></tr><tr><td><p><strong>AWS Default VPC is being used</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS Default VPCs that are being used. AWS creates a default VPC automatically upon the creation of your AWS account with a default security group and network access control list (NACL). Using AWS default VPC can lead to limited customization and security concerns due to shared resources and potential misconfigurations, hindering scalability and optimal resource management. As a best practice, using a custom VPC with specific security and network configuration provides greater flexibility and control over your architecture.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-ec2-describe-vpcs' AND json.rule = default is true and shared is false and state equal ignore case available as X; config from cloud.resource where api.name = 'aws-ec2-describe-network-interfaces' AND json.rule = status equal ignore case in-use as Y; filter '$.X.vpcId equals $.Y.vpcId'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS EKS cluster does not have secrets encryption enabled</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS EKS clusters that do not have secrets encryption enabled. AWS EKS cluster secrets are, by default, stored unencrypted in the API server’s underlying data store (etcd). Anyone with direct access to etcd or with API access can retrieve or modify the secrets. Using secrets encryption for your Amazon EKS cluster allows you to protect sensitive information such as passwords and API keys using Kubernetes-native APIs. It is recommended to enable secret encryption to ensure its security and reduce the risk of unauthorized access or data breaches.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-eks-describe-cluster' AND json.rule = encryptionConfig does not exist or (encryptionConfig exists and encryptionConfig[*].provider.keyArn does not exist and encryptionConfig[*].resources[*] does not contain secrets)
</code></pre></td></tr><tr><td><p><strong>AWS Elastic Load Balancer v2 (ELBv2) with cross-zone load balancing disabled</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies load balancers that do not have cross-zone load balancing enabled. Cross-zone load balancing is a feature that evenly distributes incoming traffic across healthy targets in all availability zones that have been configured. This can help to ensure that your application is able to manage additional traffic and limit the danger of any single availability zone getting overwhelmed and perhaps affecting load balancer performance. So, it is recommended to enable cross-zone load balancing.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = ['attributes'].['load_balancing.cross_zone.enabled'] is false
</code></pre></td></tr><tr><td><p><strong>AWS MSK cluster encryption in transit is not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies AWS MSK clusters with encryption in transit in a disabled state. Without in-transit encryption, data can be intercepted when moving between brokers. So it is recommended to enable in-transit encryption between brokers within a cluster to ensure that data exchanged between brokers within the cluster is encrypted, thereby protecting sensitive data from eavesdropping and unauthorized access.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name = 'aws-msk-cluster' AND json.rule = encryptionInfo.encryptionInTransit.clientBroker contains PLAINTEXT or encryptionInfo.encryptionInTransit.inCluster is false
</code></pre></td></tr><tr><td><p><strong>AWS RDS Postgres Cluster does not have Query Logging enabled</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies RDS Postgres clusters with query logging disabled. In AWS RDS PostgreSQL, by default, the logging level captures login failures, fatal server errors, deadlocks, and query failures. To log data changes, we recommend enabling cluster logging for monitoring and troubleshooting. To obtain adequate logs, an RDS cluster should have log_statement and log_min_duration_statement parameters configured. It is a best practice to enable additional RDS cluster logging, which will help in data change monitoring and troubleshooting.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-rds-db-cluster-parameter-group' AND json.rule = parameters.log_min_duration_statement.ParameterValue does not exist or parameters.log_min_duration_statement.ParameterValue equals -1 as X; config from cloud.resource where api.name= 'aws-rds-db-cluster' AND json.rule = status contains available and engine contains postgres as Y; filter '$.X.DBClusterParameterGroupName equals $.Y.dbclusterParameterGroup'; show Y;
</code></pre></td></tr><tr><td><p><strong>GCP Composer environment web server network access control allows access from all IP addresses</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies GCP Composer environments with web server network access control that allows access from all IP addresses. Web server network access controls which IP addresses will have access to the Airflow web server. By default, this feature allows all connections from the public internet. Allowing all traffic to the composer environment may allow a bad actor to brute force their way into the system and potentially get access to the entire network. As a best practice, restrict traffic solely from known static IP addresses. Limit the access list to include known hosts, services, or specific employees only.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-composer-environment' AND json.rule = state equals "RUNNING" and config.webServerNetworkAccessControl.allowedIpRanges[?any( value equals "0.0.0.0/0" or value equals "::0/0" )] exists
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Run service is using default service account with editor role</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies GCP Cloud Run services that are utilizing the default service account with the editor role. In Google Cloud Platform (GCP), the Compute Engine Default service account is automatically created upon enabling the Compute Engine API. This service account is granted the IAM basic Editor role by default, unless explicitly disabled. To adhere to the principle of least privilege and mitigate potential privilege escalation risks, it is recommended not to assign the default service account, particularly when granting the editor role. This ensures that instances are provisioned with minimal access rights, promoting a better security posture.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = user contains "compute@developer.gserviceaccount.com" and roles[*] contains "roles/editor" as X; config from cloud.resource where api.name = 'gcloud-cloud-run-services-list' AND json.rule = spec.template.spec.serviceAccountName contains "compute@developer.gserviceaccount.com" as Y; filter ' $.X.user equals $.Y.spec.template.spec.serviceAccountName '; show Y;
</code></pre></td></tr><tr><td><p><strong>GCP GKE cluster node boot disk not encrypted with CMEK</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies GCP GKE clusters that do not have their node boot disk encrypted with CMEK. The GKE node boot disk is the persistent disk that houses the Kubernetes node file system. By default, this disk is encrypted by a GCP managed key but users can specify customer managed encryption key to get enhanced security, control over the encryption key, and also comply with any regulatory requirements. As a security best practice use of CMEK to encrypt the boot disk of GKE cluster nodes is advisable.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = status equals "RUNNING" and nodePools[?any(config.bootDiskKmsKey does not exist)] exists
</code></pre></td></tr><tr><td><p><strong>GCP SQL Instance with public IP address does not have authorized network configured</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies GCP Cloud SQL instances with public IP addresses that do not have authorized network configured. Clients can connect to the SQL instance securely by using the Cloud SQL Proxy or adding the client’s public address as an authorized network. If the client application is connecting directly to a Cloud SQL instance on its public IP address, client’s external IP address needs to be added as an Authorized network to allow the connection. It is recommended to add authorized networks to reduce the access vector.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = state equals "RUNNABLE" and ipAddresses[?any( type equal ignore case "PRIMARY" )] exists and settings.ipConfiguration.authorizedNetworks is empty
</code></pre></td></tr><tr><td><p><strong>GCP Dataproc Cluster not configured with Customer-Managed Encryption Key (CMEK)</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies Dataproc Clusters that are not configured with CMEK. Dataproc cluster and job data are stored on persistent disks associated with the Compute Engine VMs in the cluster as well as in a Cloud Storage staging bucket. As a security best practice use of CMEK to encrypt this data on persistent disk and bucket is advisable and provides more control to the user.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-dataproc-clusters-list' AND json.rule = config.encryptionConfig.gcePdKmsKeyName does not exist and config.encryptionConfig.kmsKey does not exist
</code></pre></td></tr><tr><td><p><strong>GCP PostgreSQL instance database flag cloudsql.enable_pgaudit is not set to on</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies PostgreSQL database instances in which database flag cloudsql.enable_pgaudit is not set to on. Enabling the flag cloudsql.enable_pgaudit enables the logging by pgAudit extension for the database (if installed). The pgAudit extension for PostgreSQL databases provides detailed session and object logging to comply with government, financial, &#x26; ISO standards and provides auditing capabilities to mitigate threats by monitoring security events on the instance. Any changes to the database logging configuration should be made in accordance with the organization’s logging policy.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = "databaseVersion contains POSTGRES and (settings.databaseFlags[?(@.name=='cloudsql.enable_pgaudit')] does not exist or settings.databaseFlags[?(@.name=='cloudsql.enable_pgaudit')].value does not equal on)"
</code></pre></td></tr><tr><td><p><strong>GCP PostgreSQL instance database flag log_min_error_statement is not set</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies PostgreSQL database instances in which database flag log_min_error_statement is not set. The log_min_error_statement flag defines the minimum message severity level that are considered as an error statement. Messages for error statements are logged with the SQL statement. Valid values include DEBUG5, DEBUG4, DEBUG3, DEBUG2, DEBUG1, INFO, NOTICE, WARNING, ERROR, LOG, FATAL, and PANIC. Each severity level includes the subsequent levels. log_min_error_statement flag value changes should only be made in accordance with the organization’s logging policy. Proper auditing can help in troubleshooting operational problems and also permits forensic analysis.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-sql-instances-list' AND json.rule = "databaseVersion contains POSTGRES and settings.databaseFlags[?(@.name=='log_min_error_statement')] does not exist"
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench user-managed notebook is using a default service account with the editor role</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>Identifies GCP Vertex AI Workbench user-managed notebooks that are using the default service account with the editor role. When you create a new Vertex AI Workbench user-managed notebook, the compute engine default service account is associated with the notebook by default if any other service account is not configured. The compute engine default service account is automatically created when the Compute Engine API is enabled and is granted the IAM basic Editor role if you have not disabled this behavior explicitly. These permissions can be exploited to get admin access to the GCP project. To be compliant with the principle of least privileges and prevent potential privilege escalation, it is recommended that Vertex AI Workbench user-managed notebooks are not assigned the 'Compute Engine default service account' especially when the editor role is granted to the service account.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-vertex-ai-notebook-instance' AND json.rule = state equals "ACTIVE" and serviceAccount contains "compute@developer.gserviceaccount.com" as X; config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = user contains "compute@developer.gserviceaccount.com" and roles[*] contains "roles/editor" as Y; filter ' $.X.serviceAccount equals $.Y.user'; show X;
</code></pre></td></tr><tr><td><p><strong>New CI/CD Configuration Build Policies</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p>The following default <a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference/ci-cd-pipeline-policies/ci-cd-pipeline-policies">CI/CD policies</a> are added within the <strong>Build</strong> subtype of <strong>Configuration</strong> policies under <strong>Governance</strong> for enhanced continuous integration and deployment pipeline security:</p><p><a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference/ci-cd-pipeline-policies/azure-repo-cicd-pipeline-policies/azure-repo-cicd-pipeline-policies">Azure Policies</a></p><ul><li>Repository in Azure Repos does not dismiss pull request approvals on the default branch when new commits are pushed</li><li>NPM project contains unused dependencies in an Azure Repos repository</li><li>NPM package downloaded from git without commit hash reference in an Azure Repos repository</li></ul><p><a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference/ci-cd-pipeline-policies/github-cicd-pipeline-policies/github-cicd-pipeline-policies">GitHub Policies</a></p><ul><li>NPM project contains unused dependencies in a GitHub repository</li><li>NPM package downloaded from git without commit hash reference in a GitHub repository</li></ul><p><a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference/ci-cd-pipeline-policies/gitlab-cicd-pipeline-policies/gitlab-cicd-pipeline-policies">GitLab Policies</a></p><ul><li>NPM project contains unused dependencies in a GitLab repository</li><li>NPM package downloaded from git without commit hash reference in a GitLab repository</li></ul></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><mark style="background-color:orange;">Update</mark> <strong>Azure Microsoft Defender for Cloud set to Off for DNS</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p><strong>Changes—</strong> The Policy description and RQL have been updated to check either of the config i.e, Azure Microsoft Defender for servers plan 2 (which includes DNS) has not been enabled or Azure Microsoft Classic Defender for Cloud which has defender setting for DNS set to Off.</p><p><strong>Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current Policy Description—</strong> Identifies Azure Microsoft Defender for Cloud which has defender setting for DNS set to Off. Enabling Azure Defender provides advanced security capabilities like providing threat intelligence, anomaly detection, and behavior analytics in the Azure Microsoft Defender for Cloud. Defender for DNS monitors the queries and detects suspicious activities without the need for any additional agents on your resources. It is highly recommended to enable Azure Defender for DNS.</p><p><strong>Updated Policy Description—</strong> Identifies Azure Microsoft Defender for Cloud which has a defender setting for DNS set to Off. Enabling Azure Defender for the cloud provides advanced security capabilities like threat intelligence, anomaly detection, and behavior analytics. Defender for DNS monitors the queries and detects suspicious activities without the need for any additional agents on your resources. It is highly recommended to enable Azure Defender for DNS.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any(name equals Dns and properties.pricingTier does not equal Standard)] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any(name equals VirtualMachines and properties.pricingTier equal ignore case Standard and properties.subPlan equal ignore case P2)] does not exist or pricings[?any(name equals Dns and properties.pricingTier does not equal Standard)] exists
</code></pre><p><strong>Impact—</strong> Low. New Alerts might be generated in case the Azure Microsoft Defender for servers plan 2 is not enabled or Azure Microsoft Defender for Cloud which has defender setting for DNS set to Off. Existing alerts might get resolved in case Azure Microsoft Classic Defender for servers plan 2 is enabled.</p></td></tr><tr><td><p><mark style="background-color:orange;">Update</mark> <strong>AWS SQS queue access policy is overly permissive</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL has been updated to consider Action: SQS* as the IAM action and prefix are case-insensitive.</p><p><strong>Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-sqs-get-queue-attributes' AND json.rule = attributes.Policy.Statement[?any(Effect equals Allow and Action anyStartWith sqs: and (Principal.AWS contains * or Principal equals *) and Condition does not exist)] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-sqs-get-queue-attributes' AND json.rule = attributes.Policy.Statement[?any(Effect equals Allow and (Action anyStartWith sqs: or Action anyStartWith SQS:) and (Principal.AWS contains * or Principal equals *) and Condition does not exist)] exists
</code></pre><p><strong>Impact—</strong> Low. New Alerts might be generated in case the IAM action starts with SQS*</p></td></tr><tr><td><p><mark style="background-color:orange;">Update</mark> <strong>GCP Storage buckets are publicly accessible to all users</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p></td><td><p><strong>Changes—</strong> Policy RQL has been updated to account for bucket level prevent public access feature. The recommendation is also updated as per the updated GCP UI.</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-storage-buckets-list' AND json.rule = 'iam.bindings[*] size greater than 0 and iam.bindings[*].members[*] any equal allUsers'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-storage-buckets-list' AND json.rule = iamConfiguration.publicAccessPrevention does not equal ignore case "enforced" and iam.bindings[*] size greater than 0 and iam.bindings[*].members[*] any equal allUsers'
</code></pre><p><strong>Impact—</strong> Low. Existing alerts on buckets with the prevent public access feature enabled at the bucket level will be resolved. Alerts will be generated against the policy violations.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                              | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ----------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for Telecommunications Security Act (TSA)</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p> | <p>Prisma Cloud now supports the <strong>Telecommunications Security Act - TSA</strong> compliance standard. This framework encompasses measures to ensure the security and integrity of telecommunications networks and data. It includes provisions for network security, data protection, encryption, access controls, and various other categories.</p><p>You can view this built-in standard and the associated policies from <strong>Compliance > Standards</strong>. You can also generate reports for immediate viewing or download, and schedule recurring reports to track this compliance standard over time.</p> |
| <p><strong>Support for HITrust CSF 11.2.0</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p>                    | <p>Prisma Cloud now supports the <strong>HITrust CSF 11.2.0</strong> compliance standard. This compliance standard includes all the requirements and controls provided by HITrust CSF and Prisma Cloud policies mapped.</p><p>You can view this built-in standard and the associated policies from <strong>Compliance > Standards</strong>. You can also generate reports for immediate viewing or download, and schedule recurring reports to track this compliance standard over time.</p>                                                                                                                                 |
| <p><strong>Policy mappings update for NIST 800-53 Revision 5</strong></p><p><mark style="background-color:orange;"><strong>24.3.2</strong></mark></p> | <p>The compliance requirements in NIST 800-53 Revision 5 compliance standard are updated with new mappings.</p><p><strong>Impact-</strong> As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                                                                                                |

## REST API Updates

| **Change**                                                                                                                                                                              | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Report Vulnerabilities Using Package URL (purl) Format</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                   | <p>The following API responses include a new <code>purl</code> parameter:</p><ul><li><a href="https://pan.dev/compute/api/get-images">Get Image Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-registry/">Get Registry Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-scans/">Get All CI Image Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-hosts/">Get Host Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-vms/">Get VM Image Scan Results</a></li><li><a href="https://pan.dev/compute/api/get-serverless/">Get All CI Image Scan Results</a></li></ul><p>The <code>purl</code> field identifies the absolute path for the packages.</p>                          |
| <p><strong>API to Send Console Logs to Remote Syslog</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                                | The [Add Logging Settings](https://pan.dev/compute/api/post-settings-logging/) API includes a new `cert` parameter under `Syslog` to configure a TLS certificate.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Asset Explorer APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>    | The [Get Asset - POST /uai/v1/asset](https://pan.dev/prisma-cloud/api/cspm/get-asset-details-by-id/) endpoint now includes an array of IP addresses in the response.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>AWS Cloud Account APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p> | <p>The following parameters are added to <a href="https://pan.dev/prisma-cloud/api/cspm/add-aws-cloud-account/">Add Cloud Account (AWS)</a>, <a href="https://pan.dev/prisma-cloud/api/cspm/update-aws-cloud-account/">Update Cloud Account (AWS)</a>, and <a href="https://pan.dev/prisma-cloud/api/cspm/get-aws-cloud-account-status/">Get Cloud Account Status (AWS)</a>:</p><ul><li>customMemberRoleNameEnabled</li><li>skipOverrideMemberRoleName</li><li>unifiedCftDisabled</li><li>memberRoleName</li><li>useTenantExternalId</li></ul>                                                                                                                                                                                                    |
| <p><strong>CDEM APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>              | <p>The following CDEM endpoints are available to snooze, unsnooze, download your unmanaged assets, and get the traffic flow logs:</p><ul><li>Snooze Unmanaged Assets - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-snooze/">POST /asm/api/v1/asset/snooze</a></li><li>Unsnooze Unmanaged Assets - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-unsnooze/">POST /asm/api/v1/asset/reopen</a></li><li>Download Unmanaged Assets - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-download/">POST /asm/api/v1/asset/download</a></li><li>Get Flow Logs of Unmanaged Assets - <a href="https://pan.dev/prisma-cloud/api/cspm/fetch-flowlog-relationships/">GET /asm/api/v1/asset/{assetId}/flowlog-relationships</a></li></ul> |
| <p><strong>GCP Cloud Account APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p> | <p>The following endpoints now support Google Workspace account type to onboard and update the onboarded Google Workspace account to Prisma Cloud:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/add-gcp-cloud-account/">Add Cloud Account (GCP)</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/update-gcp-cloud-account/">Update Cloud Account (GCP)</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-gcp-cloud-account-status/">Get Cloud Account Status (GCP)</a></li></ul>                                                                                                                                                                                                                              |
| <p><strong>IAM APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>               | A new [Get Permissions V4 - POST /iam/api/v4/search/permission](https://pan.dev/prisma-cloud/api/cspm/permission-search-v-4/) endpoint is now available to get the permissions grouped by certain fields.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Widgets APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.3.2</mark></p>           | <p>The following Widget API endpoints are now accessible to roles with the <code>Alerts\_READ</code> permission:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-alert-metrics-resolution-reason/"><code>/api/v1/metrics/alert-count-by-resolution-reason</code></a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/value-widgets-alert-metrics/"><code>/api/v1/metrics/alert-mean-resolution-time</code></a></li></ul>                                                                                                                                                                                                                                                                                           |

## Deprecation Notice

| **Change**                                                                                                                               | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Redundant V1 Errors Endpoints in Application Security</strong></p><p><mark style="background-color:orange;">24.3.2</mark></p> | <p>The following v1 errors endpoints in Application Security for which v2 endpoints were released previously are now deprecated:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/code/get-errors-in-file/">List All Errors in File Path</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/get-errors-files/">Lists Files with Errors</a></li></ul><p>You must use the following APIs released previously that provide the same functionality:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/code/get-periodic-findings/">Get Code Issues from Periodic Scans</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/get-cicd-findings/">Get Code Issues from Pull Requests Scans and CICD Runs</a></li></ul> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-march-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
