Skip to main content

Auditing Retention Is Less Than 90 Days

Overview

SQL Server Audit Retention should be configured to be greater than 90 days. Audit Logs can be used to check for anomalies and give insight into suspected breaches or misuse of information and access.

Vendor

Azure

Cloud Service

MsSqlDatabase

CIS Azure v2.0.0 4.1.6

References

https://docs.microsoft.com/en-us/azure/sql-database/sql-database-auditing, https://docs.microsoft.com/en-us/powershell/module/azurerm.sql/get-azurermsqlserverauditing?view=azurermps-5.2.0, https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-logging-threat-detection#lt-6-configure-log-storage-retention

Severity

3

Item Types

Microsoft.Sql.servers