Azure_IAM_46

Ensure that DDoS Protection Standard should be enabled

Description

Protect virtual networks containing applications with public IPs by enabling DDoS protection service standard. DDoS protection enables mitigation of network volumetric and protocol attacks.

Remediation

Perform the following in the Azure Console:

  1. Create a DDoS protection plan
  2. Select Create a resource in the upper left corner of the Azure portal.
  3. Enter the name of the virtual network that you want to enable DDoS Protection Standard for in the Search resources, services, and docs box at the top of the portal. When the name of the virtual network appears in the search results, select it.
  4. Select DDoS protection, under SETTINGS.
  5. Select Standard. Under DDoS protection plan, select an existing DDoS protection plan and then select Save.

References:

  1. https://docs.microsoft.com/en-us/azure/virtual-network/manage-ddos-protection

Service

IAM

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!