NS-2 Secure cloud services with network controls
Use Private Endpoints, Service Endpoints, and firewall rules to restrict access to PaaS services from authorised networks only.
4
artefacts
2
held by a system
1
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Storage account firewall configuration · Identity provider / directory
- SQL firewall rules · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Public access disabled evidence · Cloud console / configuration management
governing documentDocuments that govern the control
- Private Endpoint inventory · Policy repository / GRC workspace
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- PaaS services with public endpoints
- Allow-all firewall rules
- DNS not configured for Private Endpoints
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetNS-1 Establish network segmentation boundaries · NS-3 Deploy firewall at the edge of enterprise network