3.1.4.3 Ensure that 'Agentless container vulnerability assessment' component status is 'On'

Information

Enable automatic vulnerability management for images stored in ACR or running in AKS clusters.

Rationale:

Agentless vulnerability scanning will examine container images - whether running or in storage - for vulnerable configurations.

Impact:

Agentless container vulnerability assessment requires licensing and is included in:

Defender CSPM

Defender for Containers plans.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Audit from Azure Portal

From the Azure Portal Home page, select Microsoft Defender for Cloud

Under Management select Environment Settings

Select a subscription

Under Settings > Defender Plans, click Settings & monitoring

Locate the row for Agentless container vulnerability assessment

Select On

Click Continue in the top left

Repeat the above for any additional subscriptions.

Default Value:

By default, Microsoft Defender for Containers is Off. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.

See Also

https://workbench.cisecurity.org/benchmarks/16820

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|3.1

Plugin: microsoft_azure

Control ID: 5827314e9e7312d3dbeae591408f58f85ab56853df5ee299813926b84bac8088