Prowler (delta) 5.13.0
Test results for this specific product, vendor, and version combination
| Vendor | Prowler |
| Product | Prowler (delta) |
| Version | 5.13.0 |
Download Raw Results
Download the original OCSF or HTML result files used to generate this page
| File Name | Format | Action |
|---|---|---|
| azure-virtualnetwork-delta | OCSF |
Test Summary
Aggregate summary of all tests for this configuration result
| Resources In Configuration | 1 |
| Count of Tests | 2 |
| Passing Tests | 0 |
| Failing Tests | 2 |
| Catalogs Tested |
Control Catalog Summary
Summary of test results grouped by control catalog and resource
| Control Catalog | Resources | Total Tests | Passing | Failing | Tested Requirements | Missing Requirements |
|---|---|---|---|---|---|---|
| CCC.Core | NetworkWatcher_swede... | 1 | 0 | 1 | CCC.Core.CN01.AR01CCC.Core.CN01.AR02CCC.Core.CN01.AR03CCC.Core.CN01.AR07CCC.Core.CN01.AR08CCC.Core.CN02.AR01CCC.Core.CN03.AR01CCC.Core.CN03.AR02CCC.Core.CN03.AR03CCC.Core.CN03.AR04CCC.Core.CN05.AR01CCC.Core.CN05.AR02CCC.Core.CN05.AR03CCC.Core.CN05.AR04CCC.Core.CN05.AR05CCC.Core.CN05.AR06CCC.Core.CN06.AR01CCC.Core.CN06.AR02CCC.Core.CN07.AR01CCC.Core.CN07.AR02CCC.Core.CN08.AR01CCC.Core.CN08.AR02CCC.Core.CN09.AR02CCC.Core.CN10.AR01CCC.Core.CN11.AR01CCC.Core.CN11.AR02CCC.Core.CN11.AR03CCC.Core.CN11.AR04CCC.Core.CN11.AR05CCC.Core.CN11.AR06CCC.Core.CN13.AR01CCC.Core.CN13.AR02CCC.Core.CN13.AR03CCC.Core.CN14.AR01CCC.Core.CN14.AR02 | |
| CCC.LB | NetworkWatcher_swede... | 1 | 0 | 1 | ||
| CCC.Logging | NetworkWatcher_swede... | 2 | 0 | 2 | ||
| CCC.VPC | NetworkWatcher_swede... | 2 | 0 | 2 |
Test Mapping Summary
Summary of test mappings showing how event codes map to test requirements
| Control Catalog | Test Requirement | Mapped Tests (Event Code | Total | Passing | Failing) |
|---|---|---|
| CCC.Core | CCC.Core.CN04.AR01 When administrative access or configuration change is attempted on
the service or a child resource, the service MUST log the client
identity, time, and result of the attempt.
| network_flow_log_captured_sent101 |
| CCC.Core | CCC.Core.CN04.AR02 When any attempt is made to modify data on the service or a child
resource, the service MUST log the client identity, time, and
result of the attempt.
| network_flow_log_captured_sent101 |
| CCC.Core | CCC.Core.CN04.AR03 When any attempt is made to read data on the service or a child
resource, the service MUST log the client identity, time, and
result of the attempt.
| network_flow_log_captured_sent101 |
| CCC.Core | CCC.Core.CN09.AR01 When the service is operational, its logs and any child resource
logs MUST NOT be accessible from the resource they record access
to.
| network_flow_log_captured_sent101 |
| CCC.Core | CCC.Core.CN09.AR03 When the service is operational, any attempt to redirect logs for
the service or its child resources MUST NOT be possible without
halting operation of the corresponding resource and publishing
corresponding events to monitored channels.
| network_flow_log_captured_sent101 |
| CCC.LB | CCC.LB.CN01.AR02 When throttling is invoked, the load balancer MUST
record the event in the access log within 5 minutes
for alerting and trend analysis.
| network_flow_log_captured_sent101 |
| CCC.LB | CCC.LB.CN06.AR01 When more than 10 percent of targets change from healthy to
unhealthy within five minutes, an alert MUST be issued.
| network_flow_log_captured_sent101 |
| CCC.Logging | CCC.Logging.CN01.AR01 When a new cloud account is created, provider-level audit and network flow logging MUST be
enabled by default and directed to the central sink.
| network_flow_log_captured_sent101 |
| CCC.Logging | CCC.Logging.CN01.AR02 When a new cloud compute resource is deployed, it MUST be configured to forward all relevant
logs (e.g., OS, application, service logs) to the central log sink.
| network_flow_log_captured_sent101 |
| CCC.Logging | CCC.Logging.CN02.AR01 When a new log bucket or stream is created, its retention policy MUST be configured
in accordance with organisation's data retention policy.
| network_flow_log_more_than_90_days101 |
| CCC.Logging | CCC.Logging.CN02.AR02 When a query is performed to retrieve log events older than the number of days defined
in the organisation's data retention policy, it MUST return an empty result.
| network_flow_log_more_than_90_days101 |
| CCC.VPC | CCC.VPC.CN04.AR01 When any network traffic goes to or from an interface in the VPC,
the service MUST capture and log all relevant information.
| network_flow_log_captured_sent101 network_flow_log_more_than_90_days101 |
Resource Summary
Summary of all resources mentioned in OCSF results
| Resource Name | Resource Type | Control Catalogs | Total Tests | Passing | Failing |
|---|---|---|---|---|---|
NetworkWatcher_swedencentral | Network | 2 | 0 | 2 |
Test Results
OCSF test results filtered for entries with CCC compliance mappings
| Status | Finding | Resource Name | Resource Type | Message | Test Requirements |
|---|---|---|---|---|---|
| FAIL | Ensure that network flow logs are captured and fed into a central log analytics workspace. Network Watcher NetworkWatcher_swedencentral from subscription Azure subscription 1 has no flow logs | NetworkWatcher_swedencentral | Network | Network Watcher NetworkWatcher_swedencentral from subscription Azure subscription 1 has no flow logs | |
| FAIL | Ensure that Network Security Group Flow Log retention period is 0, 90 days or greater Network Watcher NetworkWatcher_swedencentral from subscription Azure subscription 1 has no flow logs | NetworkWatcher_swedencentral | Network | Network Watcher NetworkWatcher_swedencentral from subscription Azure subscription 1 has no flow logs |