Skip to main content

Auditing Retention Is Less Than 90 Days

Overview​

SQL Server Audit Retention should be configured to be greater than 90 days. Audit Logs can be used to check for anomalies and give insight into suspected breaches or misuse of information and access.

Vendor​

Azure

Cloud Service​

MsSqlDatabase

CIS Azure v2.0.0 4.1.6

References​

https://docs.microsoft.com/en-us/azure/sql-database/sql-database-auditing, https://docs.microsoft.com/en-us/powershell/module/azurerm.sql/get-azurermsqlserverauditing?view=azurermps-5.2.0, https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-logging-threat-detection#lt-6-configure-log-storage-retention

Severity​

3

Item Types​

Microsoft.Sql.servers