| Source | Azure Portal | |||||||||||||||||||||||||||||||||
| Display name | Microsoft Managed Control 1645 - Cryptographic Key Establishment And Management | Symmetric Keys | |||||||||||||||||||||||||||||||||
| Id | afbd0baf-ff1a-4447-a86f-088a97347c0c | |||||||||||||||||||||||||||||||||
| Version | 1.0.0 Details on versioning |
|||||||||||||||||||||||||||||||||
| Versioning |
Versions supported for Versioning: 0 Built-in Versioning [Preview] |
|||||||||||||||||||||||||||||||||
| Category | Regulatory Compliance Microsoft Learn |
|||||||||||||||||||||||||||||||||
| Description | Microsoft implements this System and Communications Protection control | |||||||||||||||||||||||||||||||||
| Cloud environments | AzureCloud = true AzureUSGovernment = true AzureChinaCloud = unknown |
|||||||||||||||||||||||||||||||||
| Available in AzUSGov | The Policy is available in AzureUSGovernment cloud. Version: '1.0.0' Repository: Azure-Policy afbd0baf-ff1a-4447-a86f-088a97347c0c |
|||||||||||||||||||||||||||||||||
| Additional metadata |
Name/Id: ACF1645 / Microsoft Managed Control 1645 Category: System and Communications Protection Title: Cryptographic Key Establishment And Management | Symmetric Keys Ownership: Customer, Microsoft Description: The organization produces, controls, and distributes symmetric cryptographic keys using NIST FIPS-compliant key management technology and processes. Requirements: Azure encrypts storage keys using symmetric cryptography and follows the below defined key management process: * Key Generation: RDFE generates keys using Random Generator Algorithm. * Key Distribution: Storage keys are distributed over TLS encrypted communication channel. * Key Storage: Storage keys are stored in an encrypted format using AES 256 algorithm. * Key Recovery: In case of a key compromise, lost or stolen, a new key is generated and replaced in the Storage account. There is a backup key that is stored in Storage used for operation while the new key is generated. |
|||||||||||||||||||||||||||||||||
| Mode | Indexed | |||||||||||||||||||||||||||||||||
| Type | Static | |||||||||||||||||||||||||||||||||
| Preview | False | |||||||||||||||||||||||||||||||||
| Deprecated | False | |||||||||||||||||||||||||||||||||
| Effect | Fixed audit |
|||||||||||||||||||||||||||||||||
| RBAC role(s) | none | |||||||||||||||||||||||||||||||||
| Rule aliases | none | |||||||||||||||||||||||||||||||||
| Rule resource types | IF (2) |
|||||||||||||||||||||||||||||||||
| Compliance |
The following 2 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1645 - Cryptographic Key Establishment And Management | Symmetric Keys' (afbd0baf-ff1a-4447-a86f-088a97347c0c)
| |||||||||||||||||||||||||||||||||
| Initiatives usage |
|
|||||||||||||||||||||||||||||||||
| History | none | |||||||||||||||||||||||||||||||||
| JSON compare | n/a | |||||||||||||||||||||||||||||||||
| JSON |
|