Assessing network and firewall settings
With network and firewall settings, it’s important to have clarity of environment isolation requirements, which resources are deployed in an environment, network traffic requirements, and governance over routing tables and defining subnets.
For our walk-through in this section, our control testing will determine whether traffic logging and alerting have been enabled to detect anomalies with connectivity and network traffic. Please review the compliance frameworks that we referenced in Chapter 2, Effective Techniques for Preparing to Audit Cloud Environments, as these may guide you to additional methods for gathering test evidence. In our example, we will walk through one simple method to obtain this information within the Azure cloud environment; however, please keep in mind that there are often many other ways of collecting the same information. Let’s review one option to do this within Microsoft Azure.