> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-september-2024.md).

# Features Introduced in September 2024

Learn what’s new on Prisma® Cloud in September 2024.

* [Announcement](#announcement)
* [New Features](#new-features)
* [Updates to Terraform Template](#terraform-template-updates)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notice](#deprecation-notice)

## Announcement

| **Feature**                                                                                                                                                                           | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>Lifecycle Support Update</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">33.00.169</mark></p> | <p>Prisma Cloud officially guarantees backward compatibility with up to two previous major versions (N-2).</p><p>Although the support lifecycle remains unchanged, starting from version 33.xx, Prisma Cloud will not restrict the usage of Defender versions or REST API calls from up to three major releases before the current version (upto N-3 major releases).</p><p>For example, with the current version at 33.xx, API calls and Defenders from version 30.xx will be allowed. However, support and complete backward compatibility is guaranteed for the 32.xx and 31.xx releases.</p> |

## New Features

| **Feature**                                                                                                                                                                                                               | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Package Operational Risks</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                        | [Package Operational Risk](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/visibility/sbom/sbom#package-op-risk) assesses the operational risk and potential impact of each open-source package in your codebase. This analysis results in package operational risk severity levels categorized into **High**, **Medium**, and **Low**. By prioritizing risks based on these categories, you can effectively focus remediation efforts on the most critical issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>DSPM Integration with Attack Path and Asset Inventory</strong></p><p><mark style="background-color:orange;">Secure the Data</mark></p><p><mark style="background-color:orange;">24.9.2</mark></p>              | <p>If an Attack Path has access to a data store, you can now view the sensitivity, sensitivity label, data types, and record of data for the data store in that Attack Path. Prisma Cloud decorates the data store that contains sensitive data with a crown jewel icon. Note that the icon is displayed for individual assets and not for grouped nodes.</p><p>Prisma Cloud supports the following list of assets that are currently in the attack path and in the DSPM module:</p><ul><li>AWS: S3, EC2 Instance, RDS, DynamoDB, Redshift</li><li>Azure: Azure Blob Storage, Cosmos DB, Azure Virtual Machine</li><li>GCP: Cloud SQL, Spanner, Cloud Storage, Bigtable</li></ul><p><img src="/files/cyFspQsNiVq15K0CmF8I" alt="" data-size="original"></p><p>Additionally, when you select an asset on the Asset Inventory page a new <strong>Data</strong> tab in the asset sidecar displays data findings such as data types and labels.</p><p><img src="/files/rqrtP3pi7yU8vjAIMEKd" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Improved Shared Views</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                    | <p>Enhancements to Saved Views in Prisma Cloud allow you to share custom views with ease. If you are the creator of a custom view, you can now set the default visibility of view when you share it. Navigate to <strong>Home > Alerts > Manage Views</strong> and use the checkbox option to <strong>Make this dashboard visible for all viewers</strong>. Previously, publicly shared views were hidden by default even when shared, and visibility had to toggled on individually. Views can also be toggled off if desired. Learn more about <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/alerts/saved-views">Saved Views</a>.</p><p><img src="/files/j8DZ2Yjw2TGb695IpU5D" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Jira Integration Support for Versions 9.0 and Above</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;">24.9.1</mark></p>      | Prisma Cloud has enhanced its Prisma Cloud Technical Documentation [Jira integration](https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrate-prisma-cloud-with-jira) to work with all Jira Cloud and Jira On-Premise versions including 9.0 and above. This enhancement will enable you to receive Prisma Cloud alert notifications in your Jira accounts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Transition from OVAL to VEX Format for Red Hat Security Data</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">33.00.169</mark></p> | <p>Prisma Cloud is transitioning from the OVAL format to the new VEX format that Red Hat has introduced and adopted for reporting security data and vulnerabilities in Red Hat artifacts.</p><p><strong>Pre-33.00</strong>: Until you upgrade to a 33.xx release, Prisma Cloud will continue using OVAL for vulnerability scanning with no expected impact.</p><p><strong>33.xx</strong>: After upgrading your Console and Defenders to version 33.00 or later, Prisma Cloud will switch to the VEX format for vulnerability reporting. This transition might result in a change in the number of reported CVEs due to the inherent differences between the VEX and OVAL content.</p><p><strong>Comparison Between OVAL and VEX Formats</strong>: With the OVAL format, Prisma Cloud reports vulnerabilities for each binary found during the scan. However, with the new VEX format, Prisma Cloud will report one vulnerability for the source package and provide information on related binaries.</p><p>This means that the number of vulnerabilities with the same CVE ID will be reduced, as Prisma Cloud will report one vulnerability for the RPM package instead of multiple reports for each binary.</p><p><strong>Continued Support</strong>: Prisma Cloud will continue to support OVAL format for two major versions—v33.xx and v34.xx—to maintain compatibility with Defenders in pre-33.xx releases, as long as Red Hat continues to produce OVAL files.</p><p><strong>Expected Console Loading Time in the 33.xx release</strong>: For new Consoles paired with new Defenders, the Console loading time after a restart event will be approximately 1-2 minutes.</p><p><strong>Console Memory Usage in the 33.XX release</strong>: For on-premise users upgrading to the latest Console, the Console memory requirement is 8 GB. This requirement is only for the self-hosted editions.</p><p>For a more detailed explanation of this transition, see the <a href="https://docs.prismacloud.io/en/compute-edition/assets/pdf/lookahead-transition-to-vex-format.pdf">Transition from Oval to VEX Files</a> document. For details on how CVEs are reported in the new VEX format as compared to the OVAL format, see <a href="https://docs.prismacloud.io/en/compute-edition/assets/pdf/oval-vex-cves-comparison.pdf">CVEs Comparison between Oval and VEX</a>.</p><p>If you have any concerns or need additional information about this transition, contact <a href="mailto:support@paloaltonetworks.com"><support@paloaltonetworks.com></a>.</p> |
| <p><strong>Enhancement to WAAS Agentless Support</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">33.00.169</mark></p>                        | <p>WAAS agentless rules now support traffic inspection for AWS Application Load Balancers (ALBs) in addition to AWS EC2 instances. Ensure your AWS account is onboarded to the Prisma Cloud console and then configure the ALB rule.</p><p>To add the ALB rule access <strong>Defend > WAAS > Add Rule > Add Configuration</strong>. Ensure your CloudFormation template is applied with the necessary permissions to your onboarded AWS account in the region where the ALB resides. You can view the scan results in the Prisma Cloud console to monitor and manage your ALB traffic inspection.</p><p>This feature is enabled on request. Please contact your Account team for more details.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |

## Updates to Terraform Template

| **Updates to Terraform Template**                                                        | **Description**                                                                                                                                                                                                                                                                                                                                          |
| ---------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Azure</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p> | <p>The following Azure permissions have been removed from the Prisma Cloud Azure Terraform template since they were deprecated by Azure:</p><ul><li><code>Microsoft.MachineLearning/commitmentPlans/read</code></li><li><code>Microsoft.MachineLearning/webServices/read</code></li><li><code>Microsoft.MachineLearning/workspaces/read</code></li></ul> |

## Changes in Existing Behavior

| **Feature**                                                                                                    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| -------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Audit Logs Retention Period</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p> | <p>The Audit logs from AWS, Azure, GCP Cloud providers, and Prisma Cloud are purged from the live system after 120 days or when the total number of logs exceeds 1.2 billion, whichever comes first. Once the logs are purged, they are no longer accessible via RQL queries on the <strong>Investigate</strong> page in Prisma Cloud. However, the data on the logs are retained in an archived, encrypted format for the duration of your contract.</p><p><strong>Impact—</strong> Once the logs are purged, they will not be accessible via RQL queries on the <strong>Investigate</strong> page in Prisma Cloud. However, the data on the logs will be retained in an archived, encrypted format for the duration of your contract.</p><p>To retrieve any purged data, contact your Prisma Cloud Customer Success Representative.</p>                                                                                                                                                                                                                        |
| <p><strong>Audit Logs Warning</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>          | <p>If you have configured your AWS account or organization to ingest audit logs through EventBridge, you might see a warning message stating: <code>Rule \<prisma-cloud-your-tenant-id-audit-logs-rule> does not exist on EventBus default in \<region></code></p><p>This warning is due to performance enhancements in the EventBridge rule configuration, which do not affect system functionality. To resolve the warning, download the CloudFormation Template (CFT) from <strong>Misconfigurations > Near Real-Time Visibility > Edit</strong>, and update your CFT stack in AWS. For detailed instructions, see <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/connect/connect-cloud-accounts/onboard-aws/configure-audit-logs#:~:text=Time%20Visibility.-,Configure%20Details.,-Click%20Download%20EventBridge">Configure Audit Logs</a>.</p><p><strong>Impact—</strong> Updating the CFT will result in an increase in the number of EventBridge rules enabling Prisma Cloud to ingest only the relevant audit logs.</p> |

## API Ingestions

| **Service**                                                                                                                                                           | **API Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                                     | <p><strong>aws-bedrock-model-invocation-logging-configuration</strong></p><p>Additional permission required:</p><ul><li><code>bedrock:GetModelInvocationLoggingConfiguration</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                                     | <p><strong>aws-bedrock-provisioned-model-throughput</strong></p><p>Additional permissions required:</p><ul><li><code>bedrock:ListProvisionedModelThroughputs</code></li><li><code>bedrock:GetProvisionedModelThroughput</code></li><li><code>bedrock:ListTagsForResource</code></li></ul><p>The Security Audit role includes the <code>bedrock:ListTagsForResource</code> permission.</p><p>The Security Audit role does not include the <code>bedrock:ListProvisionedModelThroughputs</code> and <code>bedrock:GetProvisionedModelThroughput</code> permissions. You must manually add them to the CFT template to enable them.</p>                                                                                                                                                                        |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                                     | <p><strong>aws-bedrock-model-customization-job</strong></p><p>Additional permissions required:</p><ul><li><code>bedrock:ListModelCustomizationJobs</code></li><li><code>bedrock:GetModelCustomizationJob</code></li><li><code>bedrock:ListTagsForResource</code></li></ul><p>The Security Audit role includes the <code>bedrock:ListTagsForResource</code> permission.</p><p>The Security Audit role does not include the <code>bedrock:ListModelCustomizationJobs</code> and <code>bedrock:GetModelCustomizationJob</code> permissions. You must manually add them to the CFT template to enable them.</p>                                                                                                                                                                                                 |
| <p><strong>Amazon Bedrock</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                                     | <p><strong>aws-bedrock-knowledgebase</strong></p><p>Additional permissions required:</p><ul><li><code>bedrock:ListKnowledgeBases</code></li><li><code>bedrock:GetKnowledgeBase</code></li><li><code>bedrock:ListTagsForResource</code></li></ul><p>The Security Audit role includes the <code>bedrock:ListTagsForResource</code> permission.</p><p>The Security Audit role does not include the <code>bedrock:ListKnowledgeBases</code> and <code>bedrock:GetKnowledgeBase</code> permissions. You must manually add them to the CFT template to enable them.</p>                                                                                                                                                                                                                                           |
| <p><mark style="background-color:orange;">Update</mark> <strong>Amazon Dynamo DB</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>              | <p><strong>aws-dynamodb-describe-table</strong></p><p>The <code>aws-dynamodb-describe-table</code> is updated to include a new CSP API <code>GetResourcePolicy</code> which ingests resource based policy information.</p><p>Additional permission required:</p><ul><li><code>dynamodb:GetResourcePolicy</code></li></ul><p>The Security Audit role does not include the above permission. You must manually add the permission to the CFT template to enable it.</p>                                                                                                                                                                                                                                                                                                                                       |
| <p><mark style="background-color:orange;">Update</mark> <strong>Amazon APIs</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                   | <p>The resource JSON for the following APIs are updated to include a new field <code>BucketName</code>:</p><ul><li><strong>aws-glue-job</strong></li><li><strong>aws-emr-studio</strong></li><li><strong>aws-sagemaker-domain</strong></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Amazon Redshift</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                                    | <p><strong>aws-redshift-serverless-workgroup</strong></p><p>Additional permission required:</p><ul><li><code>redshift-serverless:ListWorkgroups</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>AWS Security Hub</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                                   | <p><strong>aws-securityhub-enabled-products-for-import</strong></p><p>Additional permission required:</p><ul><li><code>securityhub:ListEnabledProductsForImport</code></li></ul><p>The Security Audit role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><mark style="background-color:orange;">Update</mark> <strong>Google BigQuery Data Transfer</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p> | <p><strong>gcloud-bigquery-data-transfer-config</strong></p><p>Additional permission required:</p><ul><li><code>bigquery.transfers.get</code></li></ul><p>The Viewer role includes the above permission.</p><p><mark style="background-color:orange;">NOTE:</mark> API has been updated to ingest resources from all supported regions except the region <code>me-central2 due</code> to platform dependencies.</p>                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>OCI Web Application Firewall</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                                       | <p><strong>oci-loadbalancer-waf</strong></p><p>Additional permissions required:</p><ul><li><code>WEB\_APP\_FIREWALL\_INSPECT</code></li><li><code>WEB\_APP\_FIREWALL\_READ</code></li></ul><p>The Reader role includes the above permissions.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Azure Databricks</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                                                   | <p><strong>azure-databricks-access-connectors</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Databricks/accessConnectors/read</code></li></ul><p>The Reader role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                                             | <p><strong>azure-active-directory-admin-consent-request-policy</strong></p><p>Additional permission required:</p><ul><li><code>Policy.Read.All</code></li></ul><p>The Global Reader role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                                             | <p><strong>azure-active-directory-cross-tenant-access-default-settings</strong></p><p>Additional permission required:</p><ul><li><code>Policy.Read.All</code></li></ul><p>The Global Reader role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                                             | <p><strong>azure-active-directory-configured-external-identity-provider</strong></p><p>Additional permission required:</p><ul><li><code>IdentityProvider.Read.All</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Google Cloud Batch Job</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                                             | <p><strong>gcloud-cloud-batch-job</strong></p><p>Additional permission required:</p><ul><li><code>batch.jobs.list</code></li></ul><p>The Viewer role includes the above permission.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>Google Kubernetes Engine</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p>                                                           | <p><strong>gcloud-container-describe-clusters</strong></p><p>Additional permission required:</p><ul><li><code>container.clusters.getCredentials</code></li></ul><p>You must manually add the permission to a Custom role.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p>WAAS Agentless - Support AWS LB</p><p><mark style="background-color:orange;">33.00.169</mark></p>                                                                  | <p>The <a href="https://pan.dev/prisma-cloud/api/cwpp/put-policies-firewall-app-agentless/">Set Agentless App Firewall Policy</a> API request is updated to support AWS Application Load Balancers (ALBs):</p><ul><li><p>The “trafficMirroring > vpcConfig” property is modified to include three new fields for ALBs:</p><ul><li>lbARN - ARN of the observed load balancer.</li><li>lbName - Load balancer name.</li><li>lbType - Load balance type.</li></ul></li><li><p>The following existing fields are now applicable as follows:</p><ul><li>instanceNames - used only in EC2 rules.</li><li>subnetID - used only in EC2 rules.</li><li>tags - used only in EC2 rules.</li><li>vpcID - must be empty (””) for ALB rules.</li><li>autoScalingEnabled - must be true for ALB rules.</li></ul></li></ul> |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>AWS S3 bucket used for storing AWS Bedrock Custom model training artifacts</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies the AWS S3 bucket used for storing AWS Bedrock Custom model training job output.</p><p>S3 buckets hold the results and artifacts generated from training models in AWS Bedrock. Ensuring proper configuration and access control is crucial to maintaining the security and integrity of the training output. Improperly secured S3 buckets used for storing AWS Bedrock training output can lead to unauthorized access and potential exposure of model information.</p><p>It is recommended to implement strict access controls, enable encryption, and audit permissions to secure AWS S3 buckets for AWS Bedrock training job output and ensure compliance.</p><p>This policy is designed to identify the S3 buckets utilized for storing results and storing artifacts generated from training custom models in AWS Bedrock. It does not signify any detected misconfiguration or security risk.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-s3api-get-bucket-acl' as X; config from cloud.resource where api.name = 'aws-bedrock-custom-model' as Y; filter ' $.Y.outputDataConfig.bucketName equals $.X.bucketName'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS S3 bucket is utilized for AWS Bedrock Custom model training data</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies the AWS S3 bucket utilized for AWS Bedrock Custom model training job data.</p><p>S3 buckets store the datasets required for training Custom models in AWS Bedrock. Proper configuration and access control are essential to ensure the security and integrity of the training data. Improperly configured S3 buckets used for AWS Bedrock Custom model training data can lead to unauthorized access, data breaches, and potential loss of sensitive information.</p><p>It is recommended to implement strict access controls, enable encryption, and audit permissions to secure AWS S3 buckets for AWS Bedrock Custom model training data and ensure compliance.</p><p>This policy is designed to identify the S3 buckets utilized for training custom models in AWS Bedrock. It does not signify any detected misconfiguration or security risk.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-s3api-get-bucket-acl' as X; config from cloud.resource where api.name = 'aws-bedrock-custom-model' as Y; filter ' $.Y.trainingDataConfig.bucketName equals $.X.bucketName'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Bedrock Custom model encrypted with Customer Managed Key (CMK) is not enabled for regular rotation</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies AWS Bedrock Custom model encrypted with Customer Managed Key (CMK) is not enabled for regular rotation.</p><p>AWS KMS (Key Management Service) allows customers to create master keys to encrypt the Custom model. Not enabling regular rotation for AWS Bedrock custom model key rotation failure can result in potential compliance violations.</p><p>As a security best practice, it is important to rotate the keys periodically so that if the keys are compromised, the data in the underlying service is still secure with the new keys.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-bedrock-custom-model' as X; config from cloud.resource where api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.keyState equals Enabled and keyMetadata.keyManager equal ignore case CUSTOMER and keyMetadata.origin equals AWS_KMS and (rotation_status.keyRotationEnabled is false or rotation_status.keyRotationEnabled equals "null") as Y; filter '$.X.modelKmsKeyArn equals $.Y.key.keyArn'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure DNS Zone having dangling DNS Record vulnerable to subdomain takeover associated with Azure Storage account blob</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies DNS records within an Azure DNS zone that point to Azure Storage Account blobs that no longer exist.</p><p>A dangling DNS attack happens when a DNS record points to a cloud resource that has been deleted or is inactive, making the subdomain vulnerable to takeover. An attacker can exploit this by creating a new resource with the same name and taking control of the subdomain to serve malicious content. This allows attackers to host harmful content under your subdomain, which could lead to phishing attacks, data breaches, and damage to your reputation. The risk arises because the DNS record still references a non-existent resource, which unauthorized individuals can re-associate with their own resources.</p><p>As a security best practice, it is recommended to routinely audit DNS zones and remove or update DNS records pointing to non-existing Azure Storage Account blobs.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-dns-recordsets' AND json.rule = type contains CNAME and properties.CNAMERecord.cname contains "web.core.windows.net" as X; config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and properties.primaryEndpoints.web exists as Y; filter 'not ($.Y.properties.primaryEndpoints.web contains $.X.properties.CNAMERecord.cname) '; show X;
</code></pre></td></tr><tr><td><p><strong>Azure DNS Zone having dangling DNS Record vulnerable to subdomain takeover associated with Web App Service</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies DNS records within an Azure DNS zone that point to Azure Web App Services that no longer exist.</p><p>A dangling DNS attack happens when a DNS record points to a cloud resource that has been deleted or is inactive, making the subdomain vulnerable to takeover. An attacker can exploit this by creating a new resource with the same name and taking control of the subdomain to serve malicious content. This allows attackers to host harmful content under your subdomain, which could lead to phishing attacks, data breaches, and damage to your reputation. The risk arises because the DNS record still references a non-existent resource, which unauthorized individuals can re-associate with their own resources.</p><p>As a security best practice, it is recommended to routinely audit DNS zones and remove or update DNS records pointing to non-existing Web App Services.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-dns-recordsets' AND json.rule = type contains CNAME and properties.CNAMERecord.cname contains "azurewebsites.net" as X; config from cloud.resource where api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running as Y;  filter 'not ($.Y.properties.hostNames contains $.X.properties.CNAMERecord.cname) '; show X;
</code></pre></td></tr><tr><td><p><strong>GCP Storage bucket CMEK not rotated every 90 days</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies GCP Storage bucket with CMEK that are not rotated every 90 days</p><p>A CMEK (Customer-Managed Encryption Key), which is configured for a GCP bucket becomes vulnerable over time due to prolonged use. Without regular rotation, the key is at greater risk of being compromised, which could lead to unauthorized access to the encrypted data in the bucket. This can undermine the security of your data and increase the chances of a breach if the key is exposed or exploited.</p><p>It is recommended to configure rotation less than 90 days for CMEKs used for GCP buckets.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-kms-crypto-keys-list' AND json.rule = primary.state equals "ENABLED" and (rotationPeriod does not exist or rotationPeriod greater than 7776000) as X; config from cloud.resource where api.name = 'gcloud-storage-buckets-list' as Y; filter ' $.X.name equals $.Y.encryption.defaultKmsKeyName'; show Y;
</code></pre></td></tr><tr><td><p><strong>GCP Storage bucket using a disabled CMEK</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies GCP Storage buckets that are using a disabled CMEK.</p><p>CMEK (Customer-Managed Encryption Keys) for GCP buckets allows you to use your own encryption keys to secure data stored in Google Cloud Storage. If a CMEK defined for a GCP bucket is disabled, the data in that bucket becomes inaccessible, as the encryption keys are no longer available to decrypt the data. This can lead to data loss and operational disruption. If not properly managed, CMEK can also introduce risks such as accidental key deletion or mismanagement, which could compromise data availability and security.</p><p>It is recommended to review the state of CMEK and enable it to keep the data in the bucket accessible.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-kms-crypto-keys-list' AND json.rule = primary.state does not equal "ENABLED" as X; config from cloud.resource where api.name = 'gcloud-storage-buckets-list' as Y; filter ' $.X.name equals $.Y.encryption.defaultKmsKeyName'; show Y;
</code></pre></td></tr><tr><td><p><strong>GCP VM instance is assigned with public IP</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies GCP VM instances that are assigned a public IP.</p><p>Using a public IP with a GCP VM exposes it directly to the internet, increasing the risk of unauthorized access and attacks. This makes the VM vulnerable to threats such as brute force attempts, DDoS attacks, and other malicious activities. To mitigate these risks, it’s safer to use private IPs and secure access methods like VPNs or load balancers.</p><p>It is recommended to avoid assigning public IPs to VM instances.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-instances-list' AND json.rule = name does not start with "gke-" and (networkInterfaces[*].accessConfigs exists or networkInterfaces.ipv6AccessConfigs exists)
</code></pre></td></tr><tr><td><p><strong>GCP VM instance with Shielded VM Secure Boot disabled</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies GCP VM instances that have Shielded VM Secure Boot disabled.</p><p>Secure Boot is a security feature that ensures only trusted, digitally signed software runs during the boot process of a computer. Enabling it helps protect against malware and unauthorized software by verifying the integrity of the bootloader and operating system. Without Secure Boot, systems are vulnerable to rootkits, bootkits, and other malicious code that can compromise the system from the start, making it difficult to detect and remove such threats.</p><p>It is recommended to enable Shielded VM secure boot for GCP VM instances.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-instances-list' AND json.rule = status equals RUNNING and name does not start with "gke-" and (shieldedInstanceConfig does not exist or shieldedInstanceConfig.enableSecureBoot is false )
</code></pre></td></tr><tr><td><p><strong>GCP OS Image is publicly accessible</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies GCP OS Images that are publicly accessible.</p><p>Custom GCP OS images are user-created operating system images tailored to specific needs and configurations. Making these images public can expose sensitive data, proprietary software, and security vulnerabilities. This can lead to unauthorized access, data breaches, and system exploitation, compromising your infrastructure’s security and integrity.</p><p>It is recommended to keep OS images private unless required for organizational needs.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-compute-image' AND json.rule = iamPolicy.bindings[?any( members contains "allAuthenticatedUsers" )] exists
</code></pre></td></tr><tr><td><p><strong>OCI Compute Instance with Secure Boot disabled</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p>This policy identifies OCI compute instances in which Secure Boot is disabled.</p><p>Secure Boot serves as a security standard ensuring that a machine exclusively boots using Original Equipment Manufacturer (OEM) trusted software. Without the activation of Secure Boot, a compute instance becomes susceptible to booting unauthorized or malicious software, posing a threat to the integrity and security of the instance. Consequently, this vulnerability can lead to unauthorized access, data breaches, or other malicious activities within the instance.</p><p>As a security best practice, enabling Secure Boot on all compute instances is strongly recommended to guarantee the exclusive execution of trusted software during the boot process.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'oci' AND api.name = 'oci-compute-instance' AND json.rule = lifecycleState equal ignore case running AND (platformConfig does not exist OR platformConfig equal ignore case "null" OR platformConfig.isSecureBootEnabled is false)
</code></pre></td></tr><tr><td><p><strong>AWS IAM user is not a member of any IAM group</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies an AWS IAM user as not being a member of any IAM group.</p><p>It is generally a best practice to assign IAM users to at least one IAM group. If the IAM users are not in a group, it complicates permission management and auditing, increasing the risk of privilege mismanagement and security oversights. It also leads to higher operational overhead and potential non-compliance with security best practices.</p><p>It is recommended to ensure all IAM users are part of at least one IAM group according to your business requirement to simplify permission management, enforce consistent security policies, and reduce the risk of privilege mismanagement.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-iam-list-users' AND json.rule = groupList is empty
</code></pre></td></tr><tr><td><p><strong>AWS KMS Customer Managed Key (CMK) is disabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies the AWS KMS Customer Managed Key (CMK) that is disabled.</p><p>Ensuring that your Amazon Key Management Service (AWS KMS) key is enabled is important because it determines whether the key can be used to perform cryptographic operations. If an AWS KMS Key is disabled, any operations dependent on that key, such as encryption or decryption of data, will fail. This can lead to application downtime, data access issues, and potential data loss if not addressed promptly.</p><p>It is recommended to enable the AWS KMS Customer Managed Key (CMK) if it is used in the application, to restore cryptographic operations and ensure your applications and services can access encrypted data.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-kms-get-key-rotation-status' AND json.rule = keyMetadata.enabled is false
</code></pre></td></tr><tr><td><p><strong>Azure Cognitive Services account hosted with OpenAI is not configured with data loss prevention</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Cognitive Services accounts hosted with OpenAI that are not configured with data loss prevention.</p><p>Azure AI services offer data loss prevention capabilities that allow customers to configure the list of outbound URLs their Azure AI services resources can access.</p><p>As a best practice, it is recommended to enable the data loss prevention feature in OpenAI-hosted Azure Cognitive Services accounts to prevent data loss.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-cognitive-services-account' AND json.rule = kind equal ignore case OpenAI and properties.provisioningState equal ignore case Succeeded and (properties.restrictOutboundNetworkAccess does not exist or properties.restrictOutboundNetworkAccess is false or (properties.restrictOutboundNetworkAccess is true and properties.allowedFqdnList is empty))
</code></pre></td></tr><tr><td><p><strong>Azure Storage account diagnostic setting for blob is disabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Storage account blobs that have diagnostic logging disabled.</p><p>By enabling diagnostic settings, you can capture various types of activities and events occurring within these storage account blobs. These logs provide valuable insights into the operations, performance, and security of the storage account blobs.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-blob-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Storage account diagnostic setting for file is disabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Storage account files that have diagnostic logging disabled.</p><p>By enabling diagnostic settings, you can capture various types of activities and events occurring within these storage account files. These logs provide valuable insights into the operations, performance, and security of the storage account files.</p><p>As a best practice, it is recommended to enable diagnostic logs on all storage account files.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-file-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Storage account diagnostic setting for queue is disabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Storage account queues that have diagnostic logging disabled.</p><p>By enabling diagnostic settings, you can capture various types of activities and events occurring within these storage account queues. These logs provide valuable insights into the operations, performance, and security of the storage account queues.</p><p>As a best practice, it is recommended to enable diagnostic logs on all storage account queues.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-queue-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Storage account diagnostic setting for table is disabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Storage account tables that have diagnostic logging disabled.</p><p>By enabling diagnostic settings, you can capture various types of activities and events occurring within these storage account tables. These logs provide valuable insights into the operations, performance, and security of the storage account tables.</p><p>As a best practice, it is recommended to enable diagnostic logs on all storage account tables.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded as X; config from cloud.resource where api.name = 'azure-storage-account-table-diagnostic-settings' AND json.rule = properties.logs[*].enabled all true as Y; filter 'not($.X.name equal ignore case $.Y.StorageAccountName)'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Application Gateway listener not secured with SSL profile</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Application Gateway listeners that are not secured with an SSL profile.</p><p>An SSL profile provides a secure channel by encrypting the data transferred between the client and the application gateway. Without SSL profiles, the data transferred is vulnerable to interception, posing security risks. This could lead to potential data breaches and compromise sensitive information.</p><p>As a security best practice, it is recommended to secure all Application Gateway listeners with SSL profiles. This ensures data confidentiality and integrity by encrypting traffic.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-application-gateway' AND json.rule = ['properties.provisioningState'] equal ignore case Succeeded AND ['properties.httpListeners'][].['properties.provisioningState'] equal ignore case Succeeded AND ['properties.httpListeners'][].['properties.protocol'] equal ignore case Https AND ['properties.httpListeners'][*].['properties.sslProfile'].['id'] does not exist
</code></pre></td></tr><tr><td><p><strong>Azure Virtual Desktop workspace diagnostic log is disabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Virtual Desktop workspaces where diagnostic logs are not enabled.</p><p>Diagnostic logs are vital for monitoring and troubleshooting Azure Virtual Desktop, which offers virtual desktops and remote app services. They help detect and resolve issues, optimize performance, and meet security and compliance standards. Without these logs, it’s difficult to track activities and detect anomalies, potentially jeopardizing security and efficiency.</p><p>As a best practice, it is recommended to enable diagnostic logs for Azure Virtual Desktop workspaces.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' and api.name = 'azure-virtual-desktop-workspace' AND json.rule = diagnostic-settings[?none( properties.logs[?any( enabled is true )] exists )] exists
</code></pre></td></tr><tr><td><p><strong>Azure Virtual Desktop disk encryption not configured with Customer Managed Key (CMK)</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Virtual Desktop environments where disk encryption is not configured using a Customer Managed Key (CMK).</p><p>Disk encryption is crucial for protecting data in Azure Virtual Desktop environments. By default, disks may be encrypted with Microsoft-managed keys, which might not meet specific security requirements. Using Customer Managed Keys (CMKs) offers better control over encryption, allowing organizations to manage key rotation, access, and revocation, thereby enhancing data security and compliance.</p><p>As a best practice, it is recommended to configure disk encryption for Azure Virtual Desktop with a Customer Managed Key (CMK).</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-vm-list' AND json.rule = ['Extensions'].['Microsoft.PowerShell.DSC'].['settings'].['properties'].['hostPoolName'] exists and powerState contains running as X; config from cloud.resource where api.name = 'azure-disk-list' AND json.rule = provisioningState equal ignore case Succeeded and (encryption.type does not contain "EncryptionAtRestWithCustomerKey" or encryption.diskEncryptionSetId does not exist) as Y; filter ' $.X.id equal ignore case $.Y.managedBy '; show Y;
</code></pre></td></tr><tr><td><p><strong>Azure Virtual Machine not protected with Azure Backup</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p>This policy identifies Azure Virtual Machines that are not protected by Azure Backup.</p><p>Without Azure Backup, VMs are at risk of data loss due to accidental deletion, corruption, or ransomware attacks. Unprotected VMs may also not comply with organizational data retention policies and regulatory requirements.</p><p>As a best practice, it is recommended to configure Azure Backup for all VMs to ensure data protection and enable recovery options in case of unexpected failures or incidents.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-recovery-service-backup-protected-item' AND json.rule = properties.workloadType equal ignore case VM as X; config from cloud.resource where api.name = 'azure-vm-list' AND json.rule = powerState contains running as Y; filter 'not $.Y.id equal ignore case $.X.properties.virtualMachineId'; show Y;
</code></pre></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Updates</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>GCP GKE unsupported Master node version</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p><strong>Changes—</strong> The policy RQL and recommendation steps are updated to support GKE version 1.31.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentMasterVersion starts with "1.27." or currentMasterVersion starts with "1.28." or currentMasterVersion starts with "1.29." or currentMasterVersion starts with "1.30." )
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentMasterVersion starts with "1.27." or currentMasterVersion starts with "1.28." or currentMasterVersion starts with "1.29." or currentMasterVersion starts with "1.30." or currentMasterVersion starts with "1.31." )
</code></pre><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low. Existing alerts where the GKE version is 1.31 will be resolved.</p></td></tr><tr><td><p><strong>GCP GKE unsupported node version</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p><strong>Changes—</strong> The policy RQL and recommendation steps are updated to support GKE version 1.31.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentNodeVersion starts with "1.27." or currentNodeVersion starts with "1.28." or currentNodeVersion starts with "1.29." or currentNodeVersion starts with "1.30." )
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-container-describe-clusters' AND json.rule = NOT ( currentNodeVersion starts with "1.27." or currentNodeVersion starts with "1.28." or currentNodeVersion starts with "1.29." or currentNodeVersion starts with "1.30."  or currentNodeVersion starts with "1.31.")
</code></pre><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low. Existing alerts where the GKE version is 1.31 will be resolved.</p></td></tr><tr><td><p><strong>GCP User managed service account keys are not rotated for 90 days</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to exclude disabled service accounts</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-iam-service-accounts-keys-list' AND json.rule = 'name contains iam.gserviceaccount.com and (_DateTime.ageInDays($.validAfterTime) > 90) and keyType equals USER_MANAGED'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-iam-service-accounts-keys-list' AND json.rule = 'disabled is false and name contains iam.gserviceaccount.com and (_DateTime.ageInDays($.validAfterTime) > 90) and keyType equals USER_MANAGED'
</code></pre><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low. Existing alerts are resolved for the disabled service accounts.</p></td></tr><tr><td><p><strong>Azure Key Vault Firewall is not enabled</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p><strong>Changes—</strong> The policy RQL is updated to reduce false positives and only generate alerts if public access is enabled.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-key-vault-list' AND json.rule = properties.networkAcls.ipRules[*].value does not exist AND properties.publicNetworkAccess does not equal ignore case "disabled"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-key-vault-list' AND json.rule = (properties.publicNetworkAccess does not equal ignore case disabled and properties.networkAcls does not exist) or (properties.publicNetworkAccess does not equal ignore case disabled and properties.networkAcls.defaultAction equal ignore case allow )
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low. Open alerts where the public access is enabled and network ACLs default action is denied will be resolved.</p></td></tr><tr><td><p><strong>Azure App Service Web app doesn’t use latest TLS version</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p><strong>Changes—</strong> The updated Policy RQL will not alert for minTlsVersion of 1.3.</p><p><strong>Current Description—</strong> This policy identifies Azure web apps which are not set with latest version of TLS encryption. App service currently allows the web app to set TLS versions 1.0, 1.1 and 1.2. It is highly recommended to use the latest TLS 1.2 version for web app secure connections.</p><p><strong>Updated Description—</strong> This policy identifies Azure web apps that are not configured with the latest version of TLS encryption. Azure Web Apps provide a platform to host and manage web applications securely.</p><p>Using the latest TLS version is crucial for maintaining secure connections. Older versions of TLS, such as 1.0 and 1.1, have known vulnerabilities that can be exploited by attackers. Upgrading to newer versions like TLS 1.2 or 1.3 ensures that the web app is better protected against modern security threats.</p><p>It is highly recommended to use the latest TLS version (greater than 1.1) for secure web app connections.</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = kind starts with "app" AND config.minTlsVersion does not equal "1.2"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = kind starts with app and config.minTlsVersion is member of ('1.0', '1.1')
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Impact—</strong> Low. Alert for Azure App Service Web app with minTlsVersion equals 1.3 will be resolved.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><p><strong>AWS SageMaker endpoint data encryption at rest not configured with CMK</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p></td><td><p><strong>Changes—</strong> The policy severity level is updated.</p><p><strong>Current Policy Severity—</strong> High</p><p><strong>Updated Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> Low</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                               | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>TX-RAMP Level 1 and Level 2</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                         | <p>Prisma Cloud now supports the latest version of Texas Risk and Authorization Management Program (TX-RAMP ) Level 1 and Level 2. TX-RAMP is designed to enhance the security and resilience of cloud services used by Texas state agencies by establishing rigorous cybersecurity standards for cloud service providers.</p><p>You can view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                                                                                                                                                                                                                                          |
| <p><strong>NYDFS 23 CRR-NY 500.0</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                                               | <p>New Policy mappings are added for CIS Controls v7.1 & CIS Controls v8.0</p><p><strong>Impact—</strong> No impact on existing alerts. The compliance score may vary as new mappings are added.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CIS Controls v7.1 & CIS Controls v8.0</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>                               | <p>New Policy mappings are introduced to the 'NYDFS 23 CRR-NY 500.0' compliance standard across all clouds.</p><p><strong>Impact—</strong> No impact on existing alerts. The compliance score may vary as new mappings are added.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Framework for Adoption of Cloud Services by SEBI Regulated Entities</strong></p><p><mark style="background-color:orange;">24.9.1</mark></p> | <p>Prisma Cloud now supports Consolidated Cybersecurity and Cyber Resilience Framework (CSCRF) released by the Securities and Exchange Board of India (SEBI) for all major cloud providers. CSCRF aims to establish a unified framework that encompasses various strategies to safeguard REs (Regulated Entities) and Market Infrastructure Institutions (MIIs) against cyber risks and incidents. Framework of adoption is part of the SEBI’s overall CSRF standard.</p><p>You can view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p><p><strong>Impact</strong>— As new mappings are introduced, compliance scoring might vary.</p> |

## REST API Updates

| **Change**                                                                                                        | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><strong>Asset Explorer APIs</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>            | Added `dataSecurity` response objects to support DSPM API integration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>AWS Logging Account APIs</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p>       | New [AWS logging account APIs](https://pan.dev/prisma-cloud/api/cspm/aws-logging-accounts/) are introduced to configure and manage AWS logging accounts that are necessary for AWS flow log ingestion.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Vulnerabilities Dashboard APIs</strong></p><p><mark style="background-color:orange;">24.9.2</mark></p> | <p>The following new UVE POST endpoints have been introduced, offering enhanced filtering capabilities. These serve as alternatives to the deprecated UVE GET endpoints.</p><ul><li><a href="https://pan-dev-f1b58—​pr741-5260bkvi.web.app/prisma-cloud/api/cspm/vulnerability-impact-by-stage-v-2/">Get Vulnerability Impact by Stage - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/vulnerable-assets-v-2/">Get Vulnerable Assets - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/top-prioritised-vulnerability-v-3/">Get Top Impacting Vulnerabilities - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability-dashboard-overview-v-4/">Get Vulnerability Overview - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-5/">Get Prioritized Vulnerabilities - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview-v-3/">Get CVE Overview - POST</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/list-vulnerable-assets-cve-v-2/">Get Vulnerable Assets by CVE - POST</a></li></ul><p>A new <a href="https://pan.dev/prisma-cloud/api/cspm/c-2-c-trace-api/">C2C Trace Asset Graph endpoint</a> is introduced to get details about the source of the vulnerability that is displayed in the C2C tracing graph in the UI.</p> |

## Deprecation Notice

| **Change**                                                                                                                                                                                                                                                                                        | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><mark style="background-color:orange;"><strong>End of support for Azure Active Directory v1 API</strong></mark></p><p><mark style="background-color:orange;">This change was first announced in 24.6.2 Look ahead notice</mark></p><p><mark style="background-color:orange;">24.9.2</mark></p> | <p><code>azure-active-directory-credential-user-registration-details</code> API is has been deprecated. Due to this change, Prisma Cloud will no longer ingest metadata for <code>azure-active-directory-credential-user-registration-details API</code>.</p><p>In RQL, the key will not be available in the <code>api.name</code> attribute auto-completion. As a replacement, it is recommended to use the <code>azure-active-directory-user-registration-details</code> API.</p><p><strong>Impact</strong>—If you have a saved search or custom policies based on this API, you must delete those manually. The policy alerts will be resolved as <strong>Policy\_Deleted</strong>.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-september-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
