What cloud platform(s) should this support?
Azure
What are some key tasks that should be performed?
Detect Manual NSG Changes
Compare current NSG rules with repo-managed desired state; flag discrepancies that indicate out-of-band changes.
Subnet Egress Validation
Confirm traffic flow from each subnet by testing NSG and VNet rule enforcement.
Log Activity Audit for NSG/Firewall Changes
Query activity logs to identify whether firewall/NSG changes were pushed through CI/CD pipeline vs. manual actors.
Any other helpful context?
No response
Contact
None