[RULE] Defender for cloud opened security alerts for High and Medium severity #3238
Labels
feature: in-flight-export
Issues that related to exporting resource data for in-flight analysis.
pillar: operational-execellence
Aligned to the Operational Excellence pillar.
Existing rule
No response
Suggested rule
Exporting the list of current Security Alerts in Defender for Cloud using the Export-AzRuleData script and highlighting opened High and Medium severity alerts will help customers understand that there are current security risks opened without proper governance in place.
Pillar
Operational Excellence
Additional context
This risk could be added to the security pillar in WAF, however as it's an operations activity, it could be also added to the operational excellence pillar.
https://learn.microsoft.com/en-us/azure/defender-for-cloud/managing-and-responding-alerts
The text was updated successfully, but these errors were encountered: