Mastering Azure Governance and Compliance with Security Center and Compliance Manager

preview_player
Показать описание
Learn more about Azure Governance Security Center Regulatory Compliance.
This series is part of Free azure training - #33

Mastering Azure Governance and Compliance with Security Center and Compliance Manager
Achieving Regulatory Compliance in Azure: The Ultimate Guide
Azure Compliance Best Practices: Tips and Strategies for a Secure Cloud Environment
Azure Governance Security Center: How to Ensure Compliance in the Cloud
Compliance Manager: The Essential Tool for Managing Azure Regulatory Compliance
Maximizing Security in Azure: Best Practices for Regulatory Compliance
Azure Governance: Protecting Your Cloud Resources with Security Center and Compliance Manager
The Ultimate Guide to Azure Security and Compliance for Your Organization
Azure Security and Compliance: Best Practices and Strategies for Success
Ensuring Compliance in Azure: Tips and Strategies from the Experts.

Combines the detailed information provided by Microsoft to auditors and regulators as part of various third-party audits of Microsoft 's cloud services against various standards (for example, ISO 27001, ISO 27018, and NIST) and information that Microsoft compiles internally for its compliance with regulations (such as HIPAA and the EU General Data Protection Regulation, or GDPR) with your own self-assessment of your organization's compliance with these standards and regulations.

Enables you to assign, track, and record compliance and assessment-related activities, which can help your organization cross team barriers to achieve your organization's compliance goals.

Provides a Compliance Score to help you track your progress and prioritize the auditing controls that will help reduce your organization's exposure to risk.

Provides a secure repository for you to upload and manage evidence and other artifacts related to your compliance activities.

Azure Security Center helps streamline the process for meeting regulatory compliance requirements, using the regulatory compliance dashboard. In the dashboard, the Security Center provides insights into your compliance posture based on continuous assessments of your Azure environment. Security Center analyzes risk factors in your hybrid cloud environment according to security best practices. These assessments are mapped to compliance controls from a supported set of standards. In the regulatory compliance dashboard, you can see the status of all the assessments within your environment in the context of a particular standard or regulation. As you act on the recommendations and reduce risk factors in your environment, your compliance posture improves.

Meeting regulatory compliance obligations and complying with all the requirements of benchmark standards can be a significant challenge in a cloud or hybrid environment. Identifying which assessments to perform, evaluating the status, and resolving the gaps can be a very daunting task. Azure Security Center (ASC) now helps streamline this process with the new regulatory compliance dashboard.

Assess and improve your compliance posture
In the Azure Security Center regulatory compliance blade, you can get an overview of key portions of your compliance posture with respect to a set of supported standards. Currently supported standards are Azure CIS, PCI DSS 3.2, ISO 27001, and SOC TSP.

What is Compliance Manager?
Compliance Manager is a workflow-based risk assessment tool designed to help you manage regulatory compliance within the shared responsibility model of the cloud. Compliance Manager provides you with a dashboard view of standards and regulations and assessments that contain Microsoft's control implementation details and test results and customer control implementation guidance and tracking for your organization to enter. Compliance Manager provides certification assessment control definitions, guidance on implementation and testing of controls, risk-weighted scoring of controls, role-based access management, and an in-place control action assignment workflow to track control implementation, testing status and evidence management. Compliance Manager optimizes compliance workload by enabling customers to logically group assessments together and apply assessment control testing to identical or related controls, reducing the duplication of effort that might otherwise be required to satisfy identical control requirements across different certifications.
An Assessment is made of several components, which are:

In-Scope Services - Each assessment applies to a specific set of Microsoft services, which are listed in the In-Scope Cloud Services section.

Microsoft-Managed Controls - Microsoft implements and manages a set of controls as part of Microsoft's compliance with various standards and regulations. These controls are organized into control families that align with the structure from the corresponding certification or regulation that the Assessment is aligned to.
#paddyMaddy #azuretutorial #azuretraining
Рекомендации по теме