> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-may-2024.md).

# Features Introduced in May 2024

Learn what’s new on Prisma® Cloud in May 2024.

* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Changes in Existing Behavior](#changes-in-existing-behavior)

## New Features

| **Feature**                                                                                                                                                                                                                                    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Visualize and Resolve Identity Based Threats</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p>                 | <p>The out-of-the-box (OOTB) dashboards now include the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-identity">Identity dashboard</a> to empower your teams to proactively detect and mitigate identity-based threats. This Dashboard provides in-depth visualizations to help you answer the following questions:</p><ul><li>How do I get critical insights into user activity, permissions, and potential risks, enabling teams to prioritize vulnerabilities and take timely action?</li><li>What are my Top Identity and Access Management Risks relative to my cloud assets?</li><li>What are the risk categories that require my immediate attention?</li><li>How can I see key Identity and Access Management benchmarks that I can track and report to the rest of my team?</li></ul><p><img src="/files/JcdrrNAinILt4lFbSwgu" alt="" data-size="original"></p>                                                         |
| <p><strong>RQL Available to Investigate Over-Privileged Access</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p>          | The Permissions [queries](https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/permissions-queries/permissions-query-attributes) are enhanced to include a new **grantedby.cloud.policy.isExcessive** attribute to identify excessive access in IAM policies across your AWS, Azure, and GCP cloud environments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Prisma Cloud Surfaces Third Party Vendor Account Information</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p> | <p>Enhancements to Prisma Cloud’s Search and Investigate functionality allow you to identify third-party vendors that may have access to service accounts and roles in your cloud environment. Explore and investigate third party vendor accounts in AWS with ease, leveraging account number to vendor matching look up. Use the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/permissions-queries/permissions-query-attributes">RQL query</a> examples to fine tune your search to surface vendor account information.</p><ul><li>To retrieve all known vendor accounts that have access to your environment:</li></ul><p><code>config from iam where source.cloud.account.isvendor = true</code></p><ul><li>To retrieve all vendor accounts with environment access that start with Red:</li></ul><p><code>config from iam where source.cloud.account STARTS WITH 'Red' and source.cloud.account.isvendor = true</code></p> |
| <p><strong>Risk Factors to Prioritize Your Code-to-Cloud Security</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p><p><mark style="background-color:orange;">Secure the Source</mark></p>               | Prisma Cloud now includes [Risk Factors](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/risk-management/risk-indicators) (Indicators) that help you prioritize security vulnerabilities by identifying critical elements within your development environment. Risk Factors focus specifically on deployed container images and the runtime-connected repositories they rely on. This prioritization is crucial because external exposure can increase the risk of unauthorized access, data breaches, and exploitation of vulnerabilities.                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Custom Fix PR Titles and Branch Names</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p><p><mark style="background-color:orange;">Secure the Source</mark></p>                                | You can now customize your [pull request titles and branch names](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/risk-management/monitor-and-manage-code-build/fix-code-issues) for suggested fixes. This enables organizations to enforce a consistent naming convention, ensuring clear and contextual information about the purpose of the fix and makes it easier for team members to understand the changes being made.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Integration with Amazon Security Lake</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p>                        | Integrate Prisma Cloud with [Amazon Security Lake](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-amazon-security-lake) to help your security analysts protect their cloud workloads, applications, and data with greater visibility and context into cloud security issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Login Experience Enhancements</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p>                                | <p>Enhanced Prisma Cloud <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/get-started/access-prisma-cloud#id3c964e17-24c6-4e7c-9a47-adae096cc88d">login experience</a> provides support for all available authentication options (excluding IdP-initiated SAML SSO) including:</p><ul><li>SSO Login page update to clearly identify OIDC SSO login and add provide support Palo Alto Networks SSO login.</li><li>Fixed an issue with deep link resolution. Accessing Prisma Cloud deep links without a valid browser session now redirects to the Prisma Cloud login page.</li></ul><p><img src="/files/YouESJ60KH3NWmYYYPMZ" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                            |
| <p><strong>Enhanced Cloud Network Analyzer</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p>                              | <p>The Cloud Network Analyzer (CNA) includes the following enhancements:</p><ul><li>Improved handling of internet exposure caused by assets deployed in VPCs that use public <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/search-and-investigate/network-queries/network-config-query-attributes">CIDR</a> blocks.</li><li><em>AWS EC2 instance with unrestricted outbound access to internet</em> policy now generates alerts when a device is configured as a NAT.</li><li>Support for Azure Service tags IP ranges in path exposure calculation.</li><li>Azure OOTB policy that detects inbound exposure now supports DestinationAddressPrefix analysis in Azure NSG.</li></ul>                                                                                                                                                                                                                                                                    |
| <p><strong>Enhanced Vulnerability Assessment</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                   | To enhance the accuracy of vulnerability assessments, Prisma Cloud has incorporated support for the 'Running On/With' configuration as outlined by NVD. This configuration, which integrates nodes based on both vulnerable and non-vulnerable criteria, requires specific conditions to be met, such as relevant packages or operating systems, for a vulnerability to be applicable. This enhancement allows Prisma Cloud to consider 'Running On/With' configurations that were not previously assessed. However, it is important to note that the impact of this enhancement is contingent on whether the CVE is assessed through NVD, as vulnerability information from the vendor feed is prioritized.                                                                                                                                                                                                                                                                            |
| <p><strong>Serverless Defender support for Java 17 and 21</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                      | Added support for deploying Serverless Defender on Java 17 and Java 21 runtimes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Support for Blocking Kubernetes cri-o Containers</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                    | <p>For Kubernetes versions employing the latest versions of cri-o runtime, crun replaces runc for launching containers. To manage user-defined vulnerability and compliance blocking rules, however, Prisma Cloud uses, when such rules are present, a binary written in the Go language to proxy the crun runtime. This proxy blocks containers whenever vulnerabilities or compliance issues, as per user-defined rules, are detected. Prisma Cloud uses the original crun runtime for all other functionalities.</p><p>If you want to run containers with a minimal number of processes, you cannot set a low PIDs limit, because the Go binary generates multiple threads. The original crun runtime does not have this limitation, as it is written in C.</p>                                                                                                                                                                                                                      |
| <p><strong>OS-specific Evaluation for Go Packages</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                              | <p>Prisma Cloud now evaluates operating system (OS) data for vulnerabilities detected in Go packages. This enhancement ensures that vulnerabilities are reported only if they meet the OS-specific criteria. For example, if vulnerabilities are detected in Go packages that are specific to Windows, they are reported only for Windows-based systems. They are not flagged for UNIX-based systems.</p><p>To view a detailed list of identified vulnerabilities, go to <strong>Monitor > Vulnerabilities > Vulnerability Explorer.</strong></p>                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>New Console Environment Variable for System Load Management</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>         | <p>A new Console environment variable, REFRESH\_INTERVAL\_SECONDS, has been added to prevent system overload issues when using the TAS applications with Defender.</p><p>Previously, Defender checked the state of TAS applications and containers every 10 seconds through an API call to the BBS server. However, frequent changes or restarts in applications within this duration could lead to system overload as Defender scanned all the apps that were impacted by the changes.</p><p>By setting a higher value for REFRESH\_INTERVAL\_SECONDS, users can now reduce system load by decreasing the scanning frequency. For example, if REFRESH\_INTERVAL\_SECONDS is set to 600 seconds, Defender checks for changes every 600 seconds, leading to a decrease in system load.</p><p>Restart Defender for the REFRESH\_INTERVAL\_SECONDS environment variable to take effect.</p>                                                                                                |
| <p><strong>Support for Google Registry Scanning</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                | When onboarding GCP cloud accounts, Prisma Cloud now supports scanning of Google Container Registry (GCR) and Google Artifact Registry (GAR).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Cloud Account Management</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p>                                            | <p>Introduced the <strong>Account Origin</strong> filter on the <strong>Cloud Accounts</strong> page in <strong>Runtime Security</strong>. This feature includes three statuses:</p><ul><li><strong>Compute:</strong> Cloud accounts created in Runtime Security only (and not in the Prisma Cloud console).</li><li><strong>Prisma - Manually imported:</strong> Cloud accounts that were manually imported from Prisma Cloud console to Runtime Security prior to the Lagrange release (end of 2022).</li><li><strong>Prisma - Auto imported:</strong> Cloud accounts that originated from Prisma Cloud console and seamlessly imported into Runtime Security.</li></ul>                                                                                                                                                                                                                                                                                                              |

## API Ingestions

| **Service**                                                                                                                                                                                        | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>AWS Network Firewall</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                           | <p><strong>aws-network-firewall-logging-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>network-firewall:DescribeLoggingConfiguration</code></li><li><code>network-firewall:ListFirewalls</code></li></ul><p>The Security Audit Policy role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>AWS Migration Hub</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                              | <p><strong>aws-migration-hub-home-region-control</strong></p><p>Additional permission required:</p><ul><li><code>mgh:DescribeHomeRegionControls</code></li></ul><p>You must manually add the permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                              | <p><strong>azure-app-service-basic-publishing-credentials-policies</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/sites/Read</code></li><li><code>Microsoft.Web/sites/basicPublishingCredentialsPolicies/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Azure Analysis Services</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                        | <p><strong>azure-analysisservices-servers-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.AnalysisServices/servers/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Azure API Management Services</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                  | <p><strong>azure-api-management-service-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.ApiManagement/service/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                              | <p><strong>azure-app-service-environment-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/hostingEnvironments/Read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Azure Machine Learning</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                         | <p><strong>azure-machine-learning-compute</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.MachineLearningServices/workspaces/read</code></li><li><code>Microsoft.MachineLearningServices/workspaces/computes/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                    |
| <p><strong>Google Workspace</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                               | <p><strong>gcloud-domain-user-last-login-time</strong></p><p>No additional permissions required for this API.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Google Dataproc Clusters</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                       | <p><strong>gcloud-dataproc-cluster-job</strong></p><p>Additional permissions required:</p><ul><li><code>dataproc.jobs.list</code></li><li><code>dataproc.jobs.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                    | <p><strong>gcloud-vertex-ai-aiplatform-feature-online-store</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.featureOnlineStores.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                    | <p><strong>gcloud-vertex-ai-aiplatform-feature-group</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.featureGroups.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Google Cloud Support</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p>                                                                           | <p><strong>gcloud-cloud-support-case</strong></p><p>Additional permission required:</p><ul><li><code>cloudsupport.techCases.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Amazon EC2</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                                     | <p><strong>aws-ec2-vpc-ipam</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeIpams</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Amazon FSx</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                                     | <p><strong>aws-fsx-backup</strong></p><p>Additional permission required:</p><ul><li><code>fsx:DescribeBackups</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>AWS Network Manager</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                            | <p><strong>aws-network-manager-global-network</strong></p><p>Additional permission required:</p><ul><li><code>networkmanager:DescribeGlobalNetworks</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>AWS Network Manager</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                            | <p><strong>aws-network-manager-core-network</strong></p><p>Additional permissions required:</p><ul><li><code>networkmanager:GetCoreNetwork</code></li><li><code>networkmanager:ListCoreNetworks</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Amazon SNS</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                                     | <p><strong>aws-sns-data-protection-policy</strong></p><p>Additional permissions required:</p><ul><li><code>sns:ListTopics</code></li><li><code>sns:GetDataProtectionPolicy</code></li></ul><p>The Security Audit role includes the <code>sns:ListTopics</code> permission. You must manually add the <code>sns:GetDataProtectionPolicy</code> permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                                                   |
| <p><strong>Azure Cognitive Services</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                       | <p><strong>azure-cognitive-services-account-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.CognitiveServices/accounts/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>Azure Express Route</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                            | <p><strong>azure-express-route-circuit-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Network/expressRouteCircuits/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Azure Relay</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                                    | <p><strong>azure-relay-namespaces</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Relay/Namespaces/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>Azure Synapse Analytics</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                                                                        | <p><strong>azure-synapse-workspace-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Synapse/workspaces/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                                                                                                                                                                                       |
| <p><mark style="background-color:orange;">Update</mark> <strong>Azure Cognitive Services</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>                  | <p>The <strong>Asset Type</strong> for <code>azure-cognitive-search-service-diagnostic-settings</code> API resources in the <strong>Inventory > Inventory Assets > Azure</strong> page is updated as follows:</p><ul><li>Previous name— <strong>Azure Cognitive Services Account Diagnostic Settings</strong></li><li>New name— <strong>Azure Cognitive Search Service Diagnostic Settings</strong></li></ul>                                                                                                                                                                                                                                                    |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google AlloyDB for PostgreSQL Permissions</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p> | <p>Prisma Cloud no longer needs access to <code>alloydb.locations.list</code> permission for the following APIs:</p><ul><li><code>gcloud-alloydb-cluster</code></li><li><code>gcloud-alloydb-cluster-instance</code></li><li><code>gcloud-alloydb-cluster-user</code></li><li><code>gcloud-alloydb-backup</code></li></ul>                                                                                                                                                                                                                                                                                                                                       |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google Dataplex Permissions</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p>               | <p>Prisma Cloud no longer needs access to <code>dataplex.locations.list</code> permission for the following APIs:</p><ul><li><code>gcloud-dataplex-lake-zone-entity</code></li><li><code>gcloud-dataplex-lake-zone-asset-action</code></li><li><code>gcloud-dataplex-lake-zone-asset</code></li><li><code>gcloud-dataplex-lake-zone-action</code></li><li><code>gcloud-dataplex-lake-environment</code></li><li><code>gcloud-dataplex-lake-zone</code></li><li><code>gcloud-dataplex-lake-task</code></li><li><code>gcloud-dataplex-lake-contentitem</code></li><li><code>gcloud-dataplex-lake-action</code></li><li><code>gcloud-dataplex-lake</code></li></ul> |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>AWS OpenSearch domain does not have the latest service software version</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Amazon OpenSearch Service domains that have service software updates available but not installed for the domain.</p><p>Amazon OpenSearch Service is a managed solution for deploying, managing, and scaling OpenSearch clusters. Service software updates deliver the most recent platform fixes, enhancements, and features for the environment, ensuring domain security and availability. To minimize service disruption, it’s advisable to schedule updates during periods of low domain traffic.</p><p>It is recommended to keep OpenSearch regularly updated to maintain system security, while also accessing the latest features and improvements.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' and api.name= 'aws-es-describe-elasticsearch-domain' AND json.rule = serviceSoftwareOptions.updateAvailable exists and serviceSoftwareOptions.updateAvailable is true
</code></pre></td></tr><tr><td><p><strong>AWS Neptune DB clusters have backup retention period less than 7 days</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Amazon Neptune DB clusters lacking sufficient backup retention tenure.</p><p>AWS Neptune DB is a fully managed graph database service. The backup retention period denotes the duration for storing automated backups of the Neptune DB clusters. Inadequate retention periods heighten the risk of data loss, and compliance issues, and hinder effective recovery in security breaches or system failures.</p><p>It is recommended to ensure a backup retention period of at least 7 days or according to your business and compliance requirements.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-neptune-db-cluster' AND json.rule = Status equals "available" and (BackupRetentionPeriod does not exist or BackupRetentionPeriod less than 7)
</code></pre></td></tr><tr><td><p><strong>AWS Neptune DB cluster does not publish audit logs to CloudWatch Logs</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Amazon Neptune DB clusters where audit logging is disabled or audit logs are not published to Amazon CloudWatch Logs.</p><p>Neptune DB integrates with Amazon CloudWatch for performance metric gathering and analysis, supporting CloudWatch Alarms. While Neptune DB provides customizable audit logs for monitoring database operations, these logs are not automatically sent to CloudWatch Logs, limiting centralized monitoring and analysis of database activities.</p><p>It is recommended to configure the Neptune DB cluster to enable audit logs and publish audit logs to CloudWatch logs.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-neptune-db-cluster' AND json.rule = Status equals "available" as X; config from cloud.resource where api.name = 'aws-neptune-db-cluster-parameter-group' AND json.rule = parameters.neptune_enable_audit_log.ParameterValue exists and parameters.neptune_enable_audit_log.ParameterValue equals 0 as Y; filter '($.X.EnabledCloudwatchLogsExports.member does not contain "audit") or $.X.DBClusterParameterGroup equals $.Y.DBClusterParameterGroupName' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS DocumentDB cluster does not publish audit logs to CloudWatch Logs</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Amazon DocumentDB cluster where audit logging is disabled or audit logs are not published to Amazon CloudWatch Logs.</p><p>DocumentDB integrates with Amazon CloudWatch for performance metric gathering and analysis, supporting CloudWatch Alarms. While DocumentDB provides customizable audit logs for monitoring database operations, these logs are not automatically sent to CloudWatch Logs, limiting centralized monitoring and analysis of database activities.</p><p>It is recommended to configure the DocumentDB cluster to enable audit logs and publish audit logs to CloudWatch logs.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-docdb-db-cluster' AND json.rule = Status equals "available" as X; config from cloud.resource where api.name = 'aws-docdb-db-cluster-parameter-group' AND json.rule = parameters.audit_logs.ParameterValue is member of ( 'disabled','none') as Y; filter '($.X.EnabledCloudwatchLogsExports.member does not contain "audit") or $.X.DBClusterParameterGroup equals $.Y.DBClusterParameterGroupName' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Network Firewall delete protection is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies the AWS Network Firewall for which delete protection is disabled. AWS Network Firewall manages inbound and outbound traffic for the AWS resources within Virtual Private Clouds (VPCs).</p><p>The deletion protection setting protects against accidental deletion of the firewall. Deletion of a firewall increases the risk of unauthorized access, data breaches, and compliance issues.</p><p>It is recommended to enable deletion protection for a network firewall to safeguard against accidental deletion.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-networkfirewall-firewall' AND json.rule = FirewallStatus.Status equals READY and Firewall.DeleteProtection is false
</code></pre></td></tr><tr><td><p><strong>AWS Application Load Balancer (ALB) is not configured to drop HTTP headers</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies AWS Application Load Balancers that are not configured to drop HTTP headers.</p><p>AWS Application Load Balancers distribute incoming HTTP/HTTPS traffic across multiple targets such as EC2 instances, containers, and Lambda functions, based on routing rules and health checks. By default, ALBs are not configured to drop invalid HTTP header values, which can leave the load balancer vulnerable to HTTP desync attacks. HTTP desync attacks manipulate request headers to exploit inconsistencies between servers, potentially leading to security vulnerabilities and unauthorized access.</p><p>It is recommended to enable this feature, to prevent the load balancer from forwarding requests with invalid HTTP headers to mitigate potential security vulnerabilities.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and ['attributes'].['routing.http.drop_invalid_header_fields.enabled'] is false
</code></pre></td></tr><tr><td><p><strong>Azure Storage account with cross tenant replication enabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Azure Storage accounts that are enabled with cross tenant replication.</p><p>Azure Storage account cross tenant replication allows data to be replicated across multiple Azure tenants. Though this feature is beneficial for data availability it also poses a significant security risk if not properly managed. Possible risks include unauthorized access to data, data leaks, and compliance violations. Disabling Cross Tenant Replication reduces the risk of unauthorized data access and prevents the accidental sharing of sensitive information.</p><p>As best practice, it is recommended to disable cross tenant replication on your storage accounts.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.allowCrossTenantReplication exists and properties.allowCrossTenantReplication is true
</code></pre></td></tr><tr><td><p><strong>Azure App service HTTP logging is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Azure App services that have HTTP logging disabled.</p><p>By enabling HTTP logging for your app service, you can collect log information and use it to monitor and troubleshoot your app, as well as identify any potential security issues or threats. This can help to ensure that your app is running smoothly and is secure from potential attacks.</p><p>As best practice, it is recommended to enable HTTP logging on your app service.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running and config.httpLoggingEnabled exists and config.httpLoggingEnabled is false
</code></pre></td></tr><tr><td><p><strong>Azure App Service Environment configured with weak TLS cipher suites</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p>This policy identifies Azure App Service Environments that are configured with weak TLS Cipher suites.</p><p>Azure App Service Environments host web applications and APIs in a dedicated and isolated environment. When these environments are configured with weak TLS Cipher suites, they can expose sensitive data to potential security risks. Weak cipher suites may allow attackers to intercept and decrypt communication between clients and the App Service Environment, leading to unauthorized access, data breaches, and potential compliance violations. The recommended cipher suites are TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256.</p><p>As best practice, it is recommended to avoid using weak TLS Cipher suites to enhance security and protect sensitive data.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service-environment' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.clusterSettings exists and properties.clusterSettings[?any(name equal ignore case FrontEndSSLCipherSuiteOrder)] does not exist
</code></pre></td></tr><tr><td><p><strong>AWS DocumentDB clusters have backup retention period less than 7 days</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies Amazon DocumentDB (DocDB) clusters lacking sufficient backup retention periods.</p><p>The backup retention period denotes the duration for storing automated backups of the DocumentDB cluster. Inadequate retention periods heighten the risk of data loss, compliance issues, and hinder effective recovery in security breaches or system failures.</p><p>The best practice is to ensure that there is a substantial backup retention period for DocDB clusters retaining at least 7 days of backups or according to your business and compliance requirements.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-docdb-db-cluster' AND json.rule = Status equals available and ( BackupRetentionPeriod does not exist or BackupRetentionPeriod less than 7 )
</code></pre></td></tr><tr><td><p><strong>AWS DMS replication instance auto minor version upgrade is not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies the AWS DMS(Database Migration Service) replication instance does not enable auto minor version upgrade.</p><p>A replication instance in DMS is a compute resource used to replicate data between a source and target database during the migration or ongoing replication process. Failure to enable automatic minor upgrades in AWS DMS can leave your database instances vulnerable to security risks stemming from outdated software.</p><p>It is recommended to enable automatic minor version upgrades on DMS replication instances for instances that receive timely patches and updates, reducing the risk of security vulnerabilities and improving overall performance and stability.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-dms-replication-instance' AND json.rule = replicationInstanceStatus equals "available" and autoMinorVersionUpgrade is false
</code></pre></td></tr><tr><td><p><strong>AWS DynamoDB table deletion protection is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies AWS DynamoDB tables with deletion protection disabled.</p><p>DynamoDB is a fully managed NoSQL database that provides a highly reliable, scalable, low-latency database solution for applications that require consistent, single-digit millisecond latency at any scale. Deletion protection feature allows authorised administrators to prevent accidental deletion of DynamoDB tables. Enabling deletion protection helps reduce the risk of data loss, maintain data integrity, ensure compliance, and protect DynamoDB tables across different environments.</p><p>It is recommended to enable deletion protection on DynamoDB tables to prevent unintended data loss.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-dynamodb-describe-table' AND json.rule = tableStatus equal ignore case ACTIVE and deletionProtectionEnabled is false
</code></pre></td></tr><tr><td><p><strong>AWS DynamoDB table Auto Scaling not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies AWS DynamoDB tables with auto-scaling disabled.</p><p>DynamoDB is a fully managed NoSQL database that provides a highly reliable, scalable, low-latency database solution for applications that require consistent, single-digit millisecond latency at any scale. Auto-scaling functionality allows you to dynamically alter the allocated throughput capacity for your DynamoDB tables based on current traffic patterns. This feature employs the Application Auto Scaling service to automatically boost provisioned read and write capacity to manage unexpected traffic increases and reduce throughput when the workload falls in order to avoid paying for wasted supplied capacity.</p><p>It is recommended to enable auto-scaling for the DynamoDB table to ensure efficient resource utilisation, cost optimisation, improved performance, simplified management, and scalability.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where Resource.status = Active AND api.name = 'aws-application-autoscaling-scaling-policy' as Y; config from cloud.resource where api.name = 'aws-dynamodb-describe-table' AND json.rule = tableStatus equal ignore case ACTIVE AND billingModeSummary.billingMode does not equal PAY_PER_REQUEST as X; filter 'not($.Y.ResourceName equals $.X.tableName)'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Network ACL is not in use</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies AWS Network ACLs that are not in use.</p><p>AWS Network Access Control Lists (NACLs) serve as a firewall mechanism to regulate traffic flow within and outside VPC subnets. A recommended practice is to assign NACLs to specific subnets to effectively manage network traffic. Unassigned NACLs with inadequate rules might inadvertently get linked to subnets, posing a security risk by potentially allowing unauthorized access.</p><p>It is recommended to regularly review and remove unused and inadequate NACLs to improve security, network performance, and resource management.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-ec2-describe-network-acls' AND json.rule = associations[*] size less than 1
</code></pre></td></tr><tr><td><p><strong>AWS AppSync has field-level logging disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies an AWS AppSync GraphQL API not configured with field-level logging.</p><p>AWS AppSync is a managed GraphQL service that simplifies the development of scalable APIs. "field-level" security offers a fine-grained approach to defining permissions and access control for individual fields within a GraphQL schema. It allows precisely regulate which users or clients can read or modify specific fields in an API. This level of control ensures that sensitive data is protected and that access is restricted only to those with appropriate authorization.</p><p>Without field-level security, control over specific fields within the schema is lost, causing the risk of sensitive data exposure. Additionally, the absence of this feature limits the implementation of fine-grained access control policies based on user roles or contextual information, thereby undermining the overall security of the application.</p><p>It is recommended to enable field-level security to mitigate the risks by enforcing access control at a granular level, ensuring that only authorized users can access or modify specific fields based on your defined policies and requirements.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-appsync-graphql-api' AND json.rule = logConfig.fieldLogLevel is not member of ('ERROR','ALL')
</code></pre></td></tr><tr><td><p><strong>AWS Elastic Beanstalk environment logging not configured</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies the Elastic Beanstalk environments not configured to send logs to CloudWatch Logs.</p><p>An Elastic Beanstalk environment is a configuration of AWS resources where you can deploy your application. The environment logs refer to the logs generated by various components of your application, which can provide valuable insights into any errors or issues that may arise during operation. Failing to enable logging in an Elastic Beanstalk environment reduces visibility, hinders incident detection and response, and increases vulnerability to security breaches.</p><p>It is recommended to configure AWS Elastic Beanstalk environments to send logs to CloudWatch to ensure security and meet compliance requirements.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-elasticbeanstalk-environment' AND json.rule = status does not equal "Terminated" as X; config from cloud.resource where api.name = 'aws-elasticbeanstalk-configuration-settings' AND json.rule = configurationSettings[*].optionSettings[?any( optionName equals "StreamLogs" and value equals "false" )] exists as Y; filter ' $.X.environmentName equals $.Y.configurationSettings[*].environmentName and $.X.applicationName equals $.Y.configurationSettings[*].applicationName'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Certificate Manager (ACM) RSA certificate key length less than 2048</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies the RSA certificates managed by AWS Certificate Manager with a key length of less than 2048 bits.</p><p>AWS Certificate Manager (ACM) is a service for managing SSL/TLS certificates. RSA certificates are cryptographic keys used for securing communications over networks. Shorter key lengths may be susceptible to attacks such as brute force or factorization, where an attacker could potentially decrypt the encrypted data by finding the prime factors of the key.</p><p>It is recommended that the RSA certificates imported on ACM utilise a minimum key length of 2048 bits or greater to ensure a sufficient level of security.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-acm-describe-certificate' AND json.rule = status equals "ISSUED" and keyAlgorithm starts with "RSA-" and keyAlgorithm equals RSA-1024
</code></pre></td></tr><tr><td><p><strong>AWS Macie is not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies the AWS Macie that is not enabled in specific regions.</p><p>AWS Macie is a data security service that automatically discovers, classifies, and protects sensitive data in AWS, enhancing security and compliance posture. Failure to activate AWS Macie increases the risk of potentially missing out on automated detection and protection of sensitive data, leaving your organization more vulnerable to data breaches and compliance violations.</p><p>It is recommended to enable Macie in all regions for comprehensive adherence to security and compliance requirements.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-macie2-session' AND json.rule = status equals "ENABLED" as X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Asset Inventory is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies GCP accounts where GCP Cloud Asset Inventory is disabled.</p><p>GCP Cloud Asset Inventory is a metadata inventory service that allows you to view, monitor, and analyze Google Cloud and Anthos assets across projects and services. This data can prove to be crucial in security analysis, resource change tracking, and compliance auditing.</p><p>It is recommended to enable GCP Cloud Asset Inventory for centralized visibility and control over your cloud assets.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-services-list' AND json.rule = services[?any( name ends with "/cloudasset.googleapis.com" and state equals "ENABLED" )] does not exist
</code></pre></td></tr><tr><td><p><strong>GCP External Load Balancer logging is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies GCP External Load Balancers using any of the protocols like HTTP, HTTPS, and HTTP/2 having logging disabled.</p><p>GCP external load balancers distribute incoming traffic across multiple instances or services hosted on Google Cloud Platform. Feature "logging" for external load balancers captures and records detailed information about the traffic flowing through the load balancers. This includes data such as incoming requests, responses, errors, latency metrics, and other relevant information. By enabling logging for external load balancers, you gain visibility into the performance, health, and security of the applications. Logged data comes handy for troubleshooting an incident, monitoring, analysis, and compliance purposes.</p><p>It is recommended to enable logging for all external load balancers.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-external-backend-service' AND json.rule = backends exists and ( protocol equal ignore case "HTTP" or protocol equal ignore case "HTTPS" or protocol equal ignore case "HTTP2" ) and ( logConfig.enable does not exist or logConfig.enable is false )
</code></pre></td></tr><tr><td><p><strong>GCP VM instance Confidential VM service disabled</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>This policy identifies GCP VM instances that have confidential VM services disabled.</p><p>GCP VM encrypts data at rest and in transit, but the data must be decrypted before processing. Confidential VM service (Confidential Computing) allows GCP VM to keep in-memory data secure by utilizing hardware-based memory encryption. This protects any sensitive data leakage in case the VM is compromised.</p><p>It is recommended to enable confidential VM services on GCP VMs to enhance the confidentiality and integrity of in-memory data on the VMs.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-instances-list' AND json.rule = status equal ignore case "RUNNING" and (machineType contains "machineTypes/n2d-" or machineType contains "machineTypes/c2d-") and (confidentialInstanceConfig.enableConfidentialCompute does not exist or confidentialInstanceConfig.enableConfidentialCompute is false)
</code></pre></td></tr><tr><td><p><strong>New Configuration Build Policies</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p><p><mark style="background-color:orange;">Secure the Source</mark></p></td><td><p>The following default policies are added within the <strong>Build</strong> subtype of <strong>Configuration</strong> policies under <strong>Governance</strong> for enhanced continuous integration and deployment pipeline security.</p><p><strong>Ansible Compute Policies</strong></p><ul><li>Usage of packages with unauthenticated or missing signatures allowed</li><li>Usage of the force parameter disabling signature validation allowed</li></ul><p><strong>Ansible General Policies</strong></p><ul><li>DNF usage of packages with untrusted or missing GPG signatures allowed</li></ul><p><strong>Ansible Monitoring Policies</strong></p><ul><li>Missing 'Rescue' section in Ansible block tasks</li></ul><p><strong>Ansible Networking Policies</strong></p><ul><li>Disabled Ansible URI certificate validation</li><li>HTTPS url not used with Ansible uri</li><li>HTTPS url not used with Ansible get_url module</li><li>SSL validation disabled within Ansible DNF module</li><li>Certificate validation disabled within Ansible DNF module</li><li>Certificate validation disabled with Ansible get_url module</li><li>SSL certificate validation disabled in Ansible Yum Tasks</li><li>SSL certificate validation disabled with Ansible Yum</li></ul><p><strong>PANOS Policies</strong></p><ul><li>End-of-session logging disabled on Palo Alto Networks security policies</li><li>IPsec profile uses insecure authentication algorithms on Palo Alto Networks devices</li><li>IPsec profile uses insecure authentication protocols on Palo Alto Networks devices</li><li>Security zone on Palo Alto Networks devices does not have an associated Zone Protection Profile</li><li>Include ACL (Access Control List) not defined for a security zone in Palo Alto Networks devices with User-ID enabled</li><li>Logging at session start enabled on Palo Alto Networks devices</li><li>Security rules apply to all zones on Palo Alto Networks devices</li><li>Plain-text management HTTP enabled for Interface Management Profile in Palo Alto Networks devices</li><li>Plain-text management Telnet enabled for Interface Management Profile in Palo Alto Networks devices</li><li>Disable Server Response Inspection (DSRI) enabled in security policies for Palo Alto Networks devices</li><li>Security rule allows any application on Palo Alto Networks devices</li><li>Security rule permits any service on Palo Alto Networks devices</li><li>Security Rule in Palo Alto Networks devices with overly broad Source and Destination IPs</li><li>Security policies missing descriptions in Palo Alto Networks devices</li><li>Log Forwarding Profile not selected for a Palo Alto Networks device security policy rule</li><li>Security rules have source_zone and destination_zone containing values of any</li></ul><p><strong>Impact—</strong> You will view policy violations for these policies on Prisma Cloud switcher <strong>Application Security > Projects</strong>. Enforcement levels for IaC Misconfigurations will now be applied to pipelines with these findings. You are required to enable the additional modules on <strong>Application Security > Settings</strong> to view violations and alerts for these policies.</p></td></tr><tr><td><p><strong>New IAM OOTB Policies</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p></td><td><p>The following new OOTB IAM policies are added in Prisma Cloud. You can also find these policies in JSON format on this <a href="https://github.com/PaloAltoNetworks/prisma-cloud-policies/tree/master/policies">GitHub Repo</a>. To see a comprehensive list of all the policies added, check the <a href="https://github.com/PaloAltoNetworks/prisma-cloud-policies/blob/master/CHANGELOG.md">changelog.md</a> file. The name of each policy in the changelog matches the filename for each policy. Within each policy file, the JSON field names clearly describe the characteristics they represent.</p><ul><li>AWS Administrators with IAM permissions are unused for 90 days</li><li>AWS Groups and IAM Roles with Administrative Permissions</li><li>AWS IAM Groups and Roles with Excessive Policies</li><li>AWS IAM Groups and Roles with IAM Data Read permissions are unused for 90 days</li><li>AWS IAM Groups and Roles with IAM Data Write permissions are unused for 90 days</li><li>AWS IAM Groups and Roles with IAM Metadata Read permissions are unused for 90 days</li><li>AWS IAM Groups and Roles with IAM Metadata Write permissions are unused for 90 days</li><li>AWS Users and Machine Identities with Administrative Permissions</li><li>AWS Users and Machine Identities with Excessive Policies</li><li>AWS Users and Machine Identities with IAM Data Read permissions are unused for 90 days</li><li>AWS Users and Machine Identities with IAM Data Write permissions are unused for 90 days</li><li>AWS Users and Machine Identities with IAM Metadata Read permissions are unused for 90 days</li><li>AWS Users and Machine Identities with IAM Metadata Write permissions are unused for 90 days</li><li>Azure AD Groups, Service Principals and Managed Identities with Administrative Permissions</li><li>Azure AD Groups, Service Principals and Managed Identities with Excessive Policies</li><li>Azure AD Groups, Service Principals and Managed Identities with IAM Data Read permissions are unused for 90 days</li><li>Azure AD Groups, Service Principals and Managed Identities with IAM Data Write permissions are unused for 90 days</li><li>Azure AD Groups, Service Principals and Managed Identities with IAM Metadata Read permissions are unused for 90 days</li><li>Azure AD Groups, Service Principals and Managed Identities with IAM Metadata Write permissions are unused for 90 days</li><li>Azure Administrators with IAM permissions are unused for 90 days</li><li>Azure Users and Machine Identities with Administrative Permissions</li><li>Azure Users and Machine Identities with Excessive Policies</li><li>Azure Users and Machine Identities with IAM Data Read permissions are unused for 90 days</li><li>Azure Users and Machine Identities with IAM Data Write permissions are unused for 90 days</li><li>Azure Users and Machine Identities with IAM Metadata Read permissions are unused for 90 days</li><li>Azure Users and Machine Identities with IAM Metadata Write permissions are unused for 90 days</li><li>GCP Administrators with IAM permissions are unused for 90 days</li><li>GCP Groups and Service Accounts with Administrative Permissions</li><li>GCP Groups and Service Accounts with Excessive Policies</li><li>GCP Groups and Service Accounts with IAM Data Read permissions are unused for 90 days</li><li>GCP Groups and Service Accounts with IAM Data Write permissions are unused for 90 days</li><li>GCP Groups and Service Accounts with IAM Metadata Read permissions are unused for 90 days</li><li>GCP Groups and Service Accounts with IAM Metadata Write permissions are unused for 90 days</li><li>GCP Users and Machine Identities with Administrative Permissions</li><li>GCP Users and Machine Identities with Excessive Policies</li><li>GCP Users and Machine Identities with IAM Data Read permissions are unused for 90 days</li><li>GCP Users and Machine Identities with IAM Data Write permissions are unused for 90 days</li><li>GCP Users and Machine Identities with IAM Metadata Read permissions are unused for 90 days</li><li>GCP Users and Machine Identities with IAM Metadata Write permissions are unused for 90 days</li><li>Third-party service account can assume a service account with high privileges</li><li>Third-party service account with a Lateral Movement Through Lambda Edit</li><li>Third-party service account with a Lateral Movement to Data Services Through Redshift Cluster Creation</li><li>Third-party Service Account With Lateral Movement Through CloudFormation Stack Creation</li></ul></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>Azure Storage account encryption key configured by access policy with privileged operations</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p><strong>Changes</strong>— The policy RQL will be updated to check if the key vault will use Role-Based Access Control (RBAC) for authorization of data actions or not.</p><p><strong>Severity</strong>— Medium</p><p><strong>Policy Type</strong>— Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.encryption.keySource equal ignore case "Microsoft.Keyvault" as X; config from cloud.resource where api.name = 'azure-key-vault-list' and json.rule = properties.accessPolicies[*].permissions exists and (properties.accessPolicies[*].permissions.keys[*] intersects ('Decrypt', 'Encrypt', 'Release', 'Purge', 'all') or properties.accessPolicies[*].permissions.secrets[*] intersects ('Purge', 'all') or properties.accessPolicies[*].permissions.certificates[*] intersects ('Purge', 'all')) as Y; filter '$.Y.properties.vaultUri contains $.X.properties.encryption.keyvaultproperties.keyvaulturi'; show X;
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.encryption.keySource equal ignore case "Microsoft.Keyvault" as X; config from cloud.resource where api.name = 'azure-key-vault-list' and json.rule = properties.enableRbacAuthorization is false and properties.accessPolicies[*].permissions exists and (properties.accessPolicies[*].permissions.keys[*] intersects ('Decrypt', 'Encrypt', 'Release', 'Purge', 'all') or properties.accessPolicies[*].permissions.secrets[*] intersects ('Purge', 'all') or properties.accessPolicies[*].permissions.certificates[*] intersects ('Purge', 'all')) as Y; filter '$.Y.properties.vaultUri contains $.X.properties.encryption.keyvaultproperties.keyvaulturi'; show X;
</code></pre><p><strong>Impact</strong>— Low.</p></td></tr><tr><td><p><strong>Azure Virtual Network subnet is not configured with a Network Security Group</strong></p><p><mark style="background-color:orange;"><strong>24.5.2</strong></mark></p></td><td><p><strong>Changes</strong>— The policy description and RQL are updated.</p><p><strong>Severity</strong>— Low</p><p><strong>Policy Type</strong>— Config</p><p><strong>Current Description—</strong> This policy identifies Azure Virtual Network (VNet) subnets that are not associated with a Network Security Group (NSG). While binding an NSG to a network interface of a Virtual Machine (VM) enables fine-grained control to the VM, associating a NSG to a subnet enables better control over network traffic to all resources within a subnet. As a best practice, associate an NSG with a subnet so that you can protect your VMs on a subnet-level.</p><p>For more information, see <a href="https://learn.microsoft.com/en-gb/archive/blogs/igorpag/azure-network-security-groups-nsg-best-practices-and-lessons-learned">Azure Network Security Groups (NSG) - Best Practices and Lessons Learned</a> and <a href="https://learn.microsoft.com/en-us/azure/private-link/private-endpoint-overview#limitations">What is a private endpoint? - Azure Private Link</a>.</p><p>This policy will not report for subnets used by Azure Firewall, Gateway, NetApp File Share, RouteServerSubnet, Private endpoints and Private links as Azure recommends not to configure Network Security Group (NSG) for these services.</p><p><strong>Updated Description—</strong> This policy identifies Azure Virtual Network (VNet) subnets that are not associated with a Network Security Group (NSG).</p><p>While binding an NSG to a network interface of a Virtual Machine (VM) enables fine-grained control of the VM, associating an NSG to a subnet enables better control over network traffic to all resources within a subnet.</p><p>It is recommended to associate an NSG with a subnet so that you can protect your VMs on a subnet-level.</p><p>For more information, see <a href="https://learn.microsoft.com/en-gb/archive/blogs/igorpag/azure-network-security-groups-nsg-best-practices-and-lessons-learned">Azure Network Security Groups (NSG) - Best Practices and Lessons Learned</a> and <a href="https://learn.microsoft.com/en-us/azure/private-link/private-endpoint-overview#limitations">What is a private endpoint? - Azure Private Link</a>.</p><p>This policy will not report for subnets used by Azure Firewall Subnet, Azure Firewall Management Subnet, Gateway Subnet, NetApp File Share, Route Server Subnet, Private endpoints and Private links as Azure recommends not to configure Network Security Group (NSG) for these services.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-subnet-list' AND json.rule = networkSecurityGroupId does not exist and name does not equal ignore case "GatewaySubnet" and name does not equal ignore case "RouteServerSubnet" and name does not equal ignore case "AzureFirewallSubnet" and ['properties.delegations'][*].['properties.serviceName'] does not equal "Microsoft.Netapp/volumes"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-network-subnet-list' AND json.rule = networkSecurityGroupId does not exist and name does not equal ignore case "GatewaySubnet" and name does not equal ignore case "RouteServerSubnet" and name does not equal ignore case "AzureFirewallSubnet" and name does not equal ignore case "AzureFirewallManagementSubnet" and ['properties.delegations'][*].['properties.serviceName'] does not equal "Microsoft.Netapp/volumes"
</code></pre><p><strong>Impact</strong>— Low. Alert for Azure Virtual Network (VNet) subnets used by <code>AzureFirewallManagementSubnet</code> will be resolved.</p></td></tr><tr><td><p><strong>Azure Microsoft Defender for Cloud set to Off for DNS</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to check if the legacy DNS plan is deprecated.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any(name equals VirtualMachines and properties.pricingTier equal ignore case Standard and properties.subPlan equal ignore case P2)] does not exist or pricings[?any(name equals Dns and properties.pricingTier does not equal Standard)] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-security-center-settings' AND json.rule = pricings[?any(name equals VirtualMachines and properties.pricingTier equal ignore case Standard and properties.subPlan equal ignore case P2)] does not exist or pricings[?any(name equals Dns and properties.deprecated is false and properties.pricingTier does not equal Standard)] exists
</code></pre><p><strong>Impact—</strong> Low. Alerts generated by the deprecated DNS plan will be resolved.</p></td></tr><tr><td><p><strong>AWS Application Load Balancer (ALB) is not using the latest predefined security policy</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p><strong>Changes—</strong> The policy description, RQL, and remediation steps are updated.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners[?any(protocol equals HTTPS and sslPolicy exists and (sslPolicy does not contain ELBSecurityPolicy-TLS13-1-2-2021-06))] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners[?any(protocol equals HTTPS and sslPolicy exists and sslPolicy is not member of ('ELBSecurityPolicy-TLS13-1-2-2021-06','ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04'))] exists
</code></pre><p><strong>Impact—</strong> Low. Alerts generated for Application Load Balancers(ALB) using predefined FIPS security policy <code>ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04</code> will be resolved.</p></td></tr><tr><td><strong>Policy Updates—Configuration Build</strong></td><td></td></tr><tr><td><p><strong>Configuration Build Policies</strong></p><p><mark style="background-color:orange;"><strong>24.5.1</strong></mark></p></td><td><p>The following policies now support Ansible framework:</p><ul><li>EC2 EBS is not optimized</li><li>AWS EC2 instances with public IP and associated with security groups have Internet access</li></ul><p><strong>Impact—</strong> You will view policy violations for these policies on Prisma Cloud switcher <strong>Application Security > Projects</strong>. Enforcement levels for IaC Misconfigurations will now be applied to pipelines with these findings. You are required to enable the additional modules on <strong>Application Security > Settings</strong> to view violations and alerts for these policies.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                            | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>Policy Mapping Update for HIPAA</strong></p><p><mark style="background-color:orange;">24.5.2</mark></p>  | <p>New Policy mappings are added to the HIPAA compliance standard.</p><p><strong>Impact—</strong> As new mappings are introduced, compliance scoring might vary.</p>                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Support for NIST CSF v2.0</strong></p><p><mark style="background-color:orange;">24.5.2</mark></p>        | <p>Prisma Cloud has integrated support for the NIST CSF v2.0 compliance standard. This version has new controls and the new Prisma Cloud policies are mapped to the controls increasing the overall coverage.</p><p>You can now view this built-in standard and the associated policies on <strong>Compliance > Standards</strong>. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                          |
| <p><strong>CIS GCP Foundation benchmark 3.0</strong></p><p><mark style="background-color:orange;">24.5.1</mark></p> | <p>Prisma Cloud now supports CIS Google Cloud Platform Foundation Benchmark version 3.0. This latest version has new controls and new Prisma Cloud policies are mapped to the controls increasing the overall compliance coverage.</p><p>You can now view this built-in standard and associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track the compliance standard over time.</p> |

## REST API Updates

| **Change**                                                                                          | **Description**                                                                                                                                                                                                                                                                             |
| --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Integration APIs</strong></p><p><mark style="background-color:orange;">24.5.1</mark></p> | Integration APIs now support [integration with Amazon Security Lake](https://pan.dev/prisma-cloud/api/cspm/api-integration-config/#amazon-security-lake) to ingest Prisma Cloud Open Cybersecurity Schema Framework (OCSF) compliant vulnerability security data into Amazon Security Lake. |

## Changes in Existing Behavior

| **Feature**        | **Description**                                                                                                                         |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------- |
| **Alert Info API** | The Alert Info [GET alert/:id](https://pan.dev/prisma-cloud/api/cspm/get-alert/) response now includes a new `connectionDetails` field. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-may-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
