|
1 | 1 | ---
|
2 |
| -title: Regulatory compliance standards in Microsoft Defender for Cloud |
3 |
| -description: Learn about regulatory compliance standards in Microsoft Defender for Cloud |
4 |
| -ms.topic: conceptual |
5 |
| -ms.date: 11/27/2023 |
| 2 | +title: Regulatory compliance in Defender for Cloud |
| 3 | +description: Learn about regulatory compliance standards and certification in Microsoft Defender for Cloud, and how it helps ensure compliance with industry regulations. |
| 4 | +author: dcurwin |
| 5 | +ms.author: dacurwin |
| 6 | +ms.topic: concept-article |
| 7 | +ms.date: 03/31/2024 |
| 8 | +#customer intent: As a cloud security professional, I want to understand how Defender for Cloud helps me meet regulatory compliance standards, so that I can ensure my organization is compliant with industry standards and regulations. |
6 | 9 | ---
|
7 | 10 |
|
8 |
| -# Regulatory compliance standards |
| 11 | +# Regulatory compliance standards in Microsoft Defender for Cloud |
9 | 12 |
|
10 | 13 | Microsoft Defender for Cloud streamlines the regulatory compliance process by helping you to identify issues that are preventing you from meeting a particular compliance standard, or achieving compliance certification.
|
11 | 14 |
|
@@ -61,7 +64,34 @@ By default, when you enable Defender for Cloud, the following standards are enab
|
61 | 64 | - For **AWS**: [Microsoft Cloud Security Benchmark (MCSB)](concept-regulatory-compliance.md) and [AWS Foundational Security Best Practices standard](https://docs.aws.amazon.com/securityhub/latest/userguide/fsbp-standard.html).
|
62 | 65 | - For **GCP**: [Microsoft Cloud Security Benchmark (MCSB)](concept-regulatory-compliance.md) and **GCP Default**.
|
63 | 66 |
|
64 |
| -## Next steps |
| 67 | +## Available regulatory standards |
| 68 | + |
| 69 | +The following regulatory standards are available in Defender for Cloud: |
| 70 | + |
| 71 | +| Standards for Azure subscriptions | Standards for AWS accounts | Standards for GCP projects | |
| 72 | +|--|--|--| |
| 73 | +| Australian Government ISM Protected | AWS Foundational Security Best Practices | Brazilian General Personal Data Protection Law (LGPD)| |
| 74 | +| Canada Federal PBMM | AWS Well-Architected Framework | California Consumer Privacy Act (CCPA)| |
| 75 | +| CIS Azure Foundations | Brazilian General Personal Data Protection Law (LGPD) | CIS Controls| |
| 76 | +| CMMC | California Consumer Privacy Act (CCPA) | CIS GCP Foundations| |
| 77 | +| FedRAMP ‘H’ & ‘M’ | CIS AWS Foundations | CIS Google Cloud Platform Foundation Benchmark| |
| 78 | +| HIPAA/HITRUST | CRI Profile | CIS Google Kubernetes Engine (GKE) Benchmark| |
| 79 | +| ISO/IEC 27001 | CSA Cloud Controls Matrix (CCM) | CRI Profile| |
| 80 | +| New Zealand ISM Restricted | GDPR | CSA Cloud Controls Matrix (CCM)| |
| 81 | +| NIST SP 800-171 | ISO/IEC 27001 | Cybersecurity Maturity Model Certification (CMMC)| |
| 82 | +| NIST SP 800-53 | ISO/IEC 27002 | FFIEC Cybersecurity Assessment Tool (CAT)| |
| 83 | +| PCI DSS | NIST Cybersecurity Framework (CSF) | GDPR| |
| 84 | +| RMIT Malaysia | NIST SP 800-172 | ISO/IEC 27001| |
| 85 | +| SOC 2 | PCI DSS | ISO/IEC 27002| |
| 86 | +| SWIFT CSP CSCF | | ISO/IEC 27017| |
| 87 | +| UK OFFICIAL and UK NHS | | NIST Cybersecurity Framework (CSF)| |
| 88 | +| | | NIST SP 800-53 | |
| 89 | +| | | NIST SP 800-171| |
| 90 | +| | | NIST SP 800-172| |
| 91 | +| | | PCI DSS| |
| 92 | +| | | Sarbanes Oxley Act (SOX)| |
| 93 | +| | | SOC 2| |
| 94 | + |
| 95 | +## Related content |
65 | 96 |
|
66 | 97 | - [Assign regulatory compliance standards](update-regulatory-compliance-packages.md)
|
67 |
| -- [Improve regulatory compliance](regulatory-compliance-dashboard.md) |
|
0 commit comments