Skip to content

Commit 14026f2

Browse files
authored
Merge pull request #270210 from ElazarK/WI236546-compliance-standards
added standards table
2 parents 18bfac7 + 6bd241e commit 14026f2

File tree

2 files changed

+40
-32
lines changed

2 files changed

+40
-32
lines changed

articles/defender-for-cloud/concept-regulatory-compliance-standards.md

Lines changed: 37 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,14 @@
11
---
2-
title: Regulatory compliance standards in Microsoft Defender for Cloud
3-
description: Learn about regulatory compliance standards in Microsoft Defender for Cloud
4-
ms.topic: conceptual
5-
ms.date: 11/27/2023
2+
title: Regulatory compliance in Defender for Cloud
3+
description: Learn about regulatory compliance standards and certification in Microsoft Defender for Cloud, and how it helps ensure compliance with industry regulations.
4+
author: dcurwin
5+
ms.author: dacurwin
6+
ms.topic: concept-article
7+
ms.date: 03/31/2024
8+
#customer intent: As a cloud security professional, I want to understand how Defender for Cloud helps me meet regulatory compliance standards, so that I can ensure my organization is compliant with industry standards and regulations.
69
---
710

8-
# Regulatory compliance standards
11+
# Regulatory compliance standards in Microsoft Defender for Cloud
912

1013
Microsoft Defender for Cloud streamlines the regulatory compliance process by helping you to identify issues that are preventing you from meeting a particular compliance standard, or achieving compliance certification.
1114

@@ -61,7 +64,34 @@ By default, when you enable Defender for Cloud, the following standards are enab
6164
- For **AWS**: [Microsoft Cloud Security Benchmark (MCSB)](concept-regulatory-compliance.md) and [AWS Foundational Security Best Practices standard](https://docs.aws.amazon.com/securityhub/latest/userguide/fsbp-standard.html).
6265
- For **GCP**: [Microsoft Cloud Security Benchmark (MCSB)](concept-regulatory-compliance.md) and **GCP Default**.
6366

64-
## Next steps
67+
## Available regulatory standards
68+
69+
The following regulatory standards are available in Defender for Cloud:
70+
71+
| Standards for Azure subscriptions | Standards for AWS accounts | Standards for GCP projects |
72+
|--|--|--|
73+
| Australian Government ISM Protected | AWS Foundational Security Best Practices | Brazilian General Personal Data Protection Law (LGPD)|
74+
| Canada Federal PBMM | AWS Well-Architected Framework | California Consumer Privacy Act (CCPA)|
75+
| CIS Azure Foundations | Brazilian General Personal Data Protection Law (LGPD) | CIS Controls|
76+
| CMMC | California Consumer Privacy Act (CCPA) | CIS GCP Foundations|
77+
| FedRAMP ‘H’ & ‘M’ | CIS AWS Foundations | CIS Google Cloud Platform Foundation Benchmark|
78+
| HIPAA/HITRUST | CRI Profile | CIS Google Kubernetes Engine (GKE) Benchmark|
79+
| ISO/IEC 27001 | CSA Cloud Controls Matrix (CCM) | CRI Profile|
80+
| New Zealand ISM Restricted | GDPR | CSA Cloud Controls Matrix (CCM)|
81+
| NIST SP 800-171 | ISO/IEC 27001 | Cybersecurity Maturity Model Certification (CMMC)|
82+
| NIST SP 800-53 | ISO/IEC 27002 | FFIEC Cybersecurity Assessment Tool (CAT)|
83+
| PCI DSS | NIST Cybersecurity Framework (CSF) | GDPR|
84+
| RMIT Malaysia | NIST SP 800-172 | ISO/IEC 27001|
85+
| SOC 2 | PCI DSS | ISO/IEC 27002|
86+
| SWIFT CSP CSCF | | ISO/IEC 27017|
87+
| UK OFFICIAL and UK NHS | | NIST Cybersecurity Framework (CSF)|
88+
| | | NIST SP 800-53 |
89+
| | | NIST SP 800-171|
90+
| | | NIST SP 800-172|
91+
| | | PCI DSS|
92+
| | | Sarbanes Oxley Act (SOX)|
93+
| | | SOC 2|
94+
95+
## Related content
6596

6697
- [Assign regulatory compliance standards](update-regulatory-compliance-packages.md)
67-
- [Improve regulatory compliance](regulatory-compliance-dashboard.md)

articles/defender-for-cloud/release-notes.md

Lines changed: 3 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -220,31 +220,9 @@ Learn more about [automated remediation scripts](implement-security-recommendati
220220

221221
March 6, 2024
222222

223-
Based on customer feedback, we've added the following compliance standards in preview to our compliance dashboard. As shown, these are for reviewing the compliance status of AWS and GCP resources protected by Defender for Cloud.
224-
225-
| Compliance standard | Version | AWS | GCP |
226-
| ----------------------------------------------------- | ---------- | ------------------------------- | ------------------------------- |
227-
| AWS Well-Architected Framework | N/A | :white_check_mark: | :x: |
228-
| Brazilian General Personal Data Protection Law (LGPD) | 53/2018 | :white_check_mark: | :white_check_mark: |
229-
| California Consumer Privacy Act (CCPA) | 2018 | :white_check_mark: | :white_check_mark: |
230-
| CIS Controls | v8 | :x: | :white_check_mark: |
231-
| CIS Google Cloud Platform Foundation Benchmark | v2.0.0 | :x: | :white_check_mark: |
232-
| CIS Google Kubernetes Engine (GKE) Benchmark | v1.5.0 | :x: | :white_check_mark: |
233-
| CPS 234 (APRA) | 2019 | :x: | :white_check_mark: |
234-
| CRI Profile | v1.2.1 | :white_check_mark: | :white_check_mark: |
235-
| CSA Cloud Controls Matrix (CCM) | v4.0.10 | :white_check_mark: | :white_check_mark: |
236-
| Cybersecurity Maturity Model Certification (CMMC) | v2.0 | :x: | :white_check_mark: |
237-
| FFIEC Cybersecurity Assessment Tool (CAT) | 2017 | :x: | :white_check_mark: |
238-
| GDPR | 2016/679 | :white_check_mark: | :white_check_mark: |
239-
| ISO/IEC 27001 | 27001:2022 | :white_check_mark: | :white_check_mark: **(Update)** |
240-
| ISO/IEC 27002 | 27002:2022 | :white_check_mark: | :white_check_mark: |
241-
| ISO/IEC 27017 | 27017:2015 | :x: | :white_check_mark: |
242-
| NIST Cybersecurity Framework (CSF) | v1.1 | :white_check_mark: | :white_check_mark: |
243-
| NIST SP 800-171 | Revision 2 | :x: | :white_check_mark: |
244-
| NIST SP 800-172 | 2021 | :white_check_mark: | :white_check_mark: |
245-
| PCI-DSS | v4.0.0 | :white_check_mark: **(Update)** | :white_check_mark: **(Update)** |
246-
| Sarbanes Oxley Act (SOX) | 2002 | :x: | :white_check_mark: |
247-
| SOC 2 | 2017 | :x: | :white_check_mark: |
223+
Based on customer feedback, we've added compliance standards in preview to Defender for Cloud.
224+
225+
Check out the [full list of supported compliance standards](concept-regulatory-compliance-standards.md#available-regulatory-standards)
248226

249227
We are continuously working on adding and updating new standards for Azure, AWS, and GCP environments.
250228

0 commit comments

Comments
 (0)