A healthcare organization stores patient records in an Azure Storage account. To meet HIPAA compliance requirements, all access to the storage account must be logged, and these logs must be immutable for auditing purposes. Additionally, the organization needs to detect any unusual access patterns or potential data exfiltration attempts. Which Azure Storage security features should be implemented?
- AAzure AD authentication with Role-Based Access Control (RBAC), Immutable Storage, Azure Monitor logs, and Microsoft Defender for Storage.
- BShared Access Signatures (SAS) with stored access policies, and Azure Security Center.
- CCustomer-managed encryption keys (CMK) in Azure Key Vault and Storage Analytics.
- DAzure Storage Firewalls and virtual networks, along with Azure Monitor logs.
Show answer & explanationAnswer & explanation
Correct answer: A. Azure AD authentication with Role-Based Access Control (RBAC), Immutable Storage, Azure Monitor logs, and Microsoft Defender for Storage.
Azure AD authentication with RBAC ensures proper access control. Immutable Storage (WORM - Write Once, Read Many) guarantees that logs cannot be altered, fulfilling the auditing requirement. Azure Monitor logs collect comprehensive audit logs for the storage account. Microsoft Defender for Storage provides advanced threat detection, including identifying unusual access patterns and potential data exfiltration, making this combination the most comprehensive solution for HIPAA compliance and threat detection.
Why the other options are wrong
- B. SAS tokens grant temporary access but don't inherently provide immutable logging or advanced threat detection capabilities for the storage account itself. Azure Security Center (now Defender for Cloud) helps, but SAS is not the primary control here.
- C. CMK encrypts data, and Storage Analytics provides basic metrics/logs, but neither offers immutable logging nor advanced threat detection for unusual access patterns or exfiltration.
- D. While important for network access, firewalls/VNets don't provide immutable logging or advanced threat detection for data exfiltration.
Azure Storage Security for Compliance
A combination of Azure features including Azure AD/RBAC for access, Immutable Storage for WORM compliance, Azure Monitor for logging, and Microsoft Defender for Storage for threat detection.
- Azure AD/RBAC: Granular access control.
- Immutable Storage: WORM for audit trails.
- Azure Monitor: Comprehensive logging.
- Defender for Storage: Advanced threat detection for unusual activity.
Memory trick: AD, Immutable, Monitor, Defender: The four pillars of secure, auditable storage.