Azure SQL監査ポリシーの保持期間の確認

必要な活動記録が調査前に削除されないようにしてください。

説明

必要になる前に監査ログが削除されると、過去のデータベース活動を再構成しにくくなります。保持期間はサービスと組織の要件に合わせて決めます。retention_in_days = 0は、Blob Storageの監査ポリシーで無期限に保持する設定です。

想定される影響

保持期間が不足すると、過去のアクセスや変更を調査する証拠が失われるおそれがあります。

対処方法

サーバーまたはデータベースの監査ポリシーのretention_in_daysを必要な期間に設定してください。実際のログ保存先の有効期限ルールも、同じ保持目標に合っているか確認してください。

例

以下は監査ポリシーを独立したリソースで定義し、保持期間を20日から95日に変更する例です。この期間や例示のパスワードを、検討せずに本番の標準として使わないでください。

変更前

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "mssqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "mradministrator"
  administrator_login_password = "thisIsDog11"

}

resource "azurerm_mssql_server_extended_auditing_policy" "example" {
  server_id = azurerm_mssql_server.example.id
  blob_storage_endpoint                        = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key              = azurerm_storage_account.example.primary_access_key
  storage_account_access_key_is_secondary = false
  retention_in_days                       = 20
}

変更後

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "mssqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "mradministrator"
  administrator_login_password = "thisIsDog11"

}

resource "azurerm_mssql_server_extended_auditing_policy" "example" {
  server_id = azurerm_mssql_server.example.id
  blob_storage_endpoint                        = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key              = azurerm_storage_account.example.primary_access_key
  storage_account_access_key_is_secondary = false
  retention_in_days                       = 95
}

参考資料