StarterKit/Definitions-GitHub-Flow/policyAssignments/security-baseline-assignments.jsonc (63 lines of code) (raw):
{
"$schema": "https://raw.githubusercontent.com/Azure/enterprise-azure-policy-as-code/main/Schemas/policy-assignment-schema.json",
"nodeName": "/Security/",
"parameterFile": "security-baseline-parameters.csv",
"definitionEntryList": [
{
"policySetId": "/providers/Microsoft.Authorization/policySetDefinitions/1f3afdf9-d0c9-4c3d-847f-89da613e70a8",
"displayName": "Azure Security Benchmark",
"assignment": {
"append": true,
"name": "asb",
"displayName": "Azure Security Benchmark",
"description": "Azure Security Benchmark Initiative."
}
},
{
"policySetId": "/providers/Microsoft.Authorization/policySetDefinitions/179d1daa-458f-4e47-8086-2a68d0d6c38f",
"displayName": "NIST SP 800-53 Rev. 5",
"assignment": {
"append": true,
"name": "nist-800-53-r5",
"displayName": "NIST SP 800-53 Rev. 5",
"description": "NIST SP 800-53 Rev. 5 Initiative."
}
}
],
"children": [
{
"nodeName": "Prod/",
"assignment": {
"name": "pr-",
"displayName": "Prod ",
"description": "Prod Environment controls enforcement with "
},
"parameterSelector": "prod",
"scope": {
"epac-dev": [
"/providers/Microsoft.Management/managementGroups/mg-epac-dev-prod"
],
"tenant": [
"/providers/Microsoft.Management/managementGroups/mg-prod"
]
}
},
{
"nodeName": "Nonprod/",
"assignment": {
"name": "tst-",
"displayName": "Nonprod ",
"description": "Nonprod Environment controls enforcement with "
},
"parameterSelector": "nonprod",
"scope": {
"epac-dev": [
"/providers/Microsoft.Management/managementGroups/epac-dev-nonprod"
],
"tenant": [
"/providers/Microsoft.Management/managementGroups/mg-nonprod"
]
}
}
]
}