|
1 | 1 | ---
|
2 | 2 | title: Regulatory compliance in Defender for Cloud
|
3 |
| -description: Learn about regulatory compliance standards and certification in Microsoft Defender for Cloud |
| 3 | +description: Learn about regulatory compliance standards and certification in Microsoft Defender for Cloud, and how it helps ensure compliance with industry regulations. |
4 | 4 | author: dcurwin
|
5 | 5 | ms.author: dacurwin
|
6 | 6 | ms.topic: concept-article
|
7 |
| -ms.date: 03/26/2024 |
| 7 | +ms.date: 03/31/2024 |
8 | 8 | #customer intent: As a cloud security professional, I want to understand how Defender for Cloud helps me meet regulatory compliance standards, so that I can ensure my organization is compliant with industry standards and regulations.
|
9 | 9 | ---
|
10 | 10 |
|
@@ -70,40 +70,39 @@ The following regulatory standards are available in Defender for Cloud:
|
70 | 70 |
|
71 | 71 | | Standards for Azure subscriptions | Standards for AWS accounts | Standards for GCP projects |
|
72 | 72 | |--|--|--|
|
73 |
| -| Australian Government ISM Protected | AWS Foundational Security Best Practices | Brazilian General Personal Data Protection Law (LGPD)| |
74 |
| -| Brazilian General Personal Data Protection Law (LGPD) | AWS Well-Architected Framework | California Consumer Privacy Act (CCPA)| |
75 |
| -| California Consumer Privacy Act (CCPA) | Brazilian General Personal Data Protection Law (LGPD) | CIS Controls| |
76 |
| -| Canada Federal PBMM | California Consumer Privacy Act (CCPA) | CIS GCP Foundations| |
77 |
| -| CIS Azure Foundations | CIS AWS Foundations | CIS Google Cloud Platform Foundation Benchmark| |
78 |
| -| CIS Controls | CRI Profile | CIS Google Kubernetes Engine (GKE) Benchmark| |
79 |
| -| CIS Google Cloud Platform Foundation Benchmark | CSA Cloud Controls Matrix (CCM) | CRI Profile| |
80 |
| -| CIS Google Kubernetes Engine (GKE) Benchmark | GDPR | CSA Cloud Controls Matrix (CCM)| |
81 |
| -| CMMC Level 3 | ISO/IEC 27001 | Cybersecurity Maturity Model Certification (CMMC)| |
82 |
| -| CRI Profile | ISO/IEC 27002 | FFIEC Cybersecurity Assessment Tool (CAT)| |
83 |
| -| CSA Cloud Controls Matrix (CCM) | NIST Cybersecurity Framework (CSF) | GDPR| |
84 |
| -| Cybersecurity Maturity Model Certification (CMMC) | NIST SP 800-172 | ISO 27001| |
85 |
| -| FedRAMP H | PCI-DSS | ISO/IEC 27001| |
86 |
| -| FedRAMP M | | ISO/IEC 27002| |
87 |
| -| FFIEC Cybersecurity Assessment Tool (CAT) | | ISO/IEC 27017| |
88 |
| -| GDPR | | NIST 800-53| |
89 |
| -| HIPAA/HITRUST | | NIST Cybersecurity Framework (CSF)| |
90 |
| -| ISO/IEC 27001:2013 | | NIST SP 800-171| |
91 |
| -| ISO/IEC 27002 | | NIST SP 800-172| |
92 |
| -| ISO/IEC 27017 | | PCI DSS| |
93 |
| -| New Zealand ISM Restricted | | Sarbanes Oxley Act (SOX)| |
94 |
| -| NIST Cybersecurity Framework (CSF) | | SOC 2| |
95 |
| -| NIST SP 800 171 R2 | | | |
96 |
| -| NIST SP 800-172 | | | |
97 |
| -| NIST SP 800-53 R4 | | | |
98 |
| -| NIST SP 800-53 R5 | | | |
99 |
| -| PCI DSS | | | |
100 |
| -| RMIT Malaysia | | | |
101 |
| -| Sarbanes Oxley Act (SOX) | | | |
102 |
| -| SOC 2 Type 2 | | | |
103 |
| -| SWIFT CSP CSCF | | | |
104 |
| -| UK OFFICIAL and UK NHS | | | |
105 |
| - |
106 |
| -## Next step |
107 |
| - |
108 |
| -> [!div class="nextstepaction"] |
109 |
| -> [Assign regulatory compliance standards](update-regulatory-compliance-packages.md) |
| 73 | + | Australian Government ISM Protected | AWS Foundational Security Best Practices | Brazilian General Personal Data Protection Law (LGPD)| |
| 74 | + | Brazilian General Personal Data Protection Law (LGPD) | AWS Well-Architected Framework | California Consumer Privacy Act (CCPA)| |
| 75 | + | California Consumer Privacy Act (CCPA) | Brazilian General Personal Data Protection Law (LGPD) | CIS Controls| |
| 76 | + | Canada Federal PBMM | California Consumer Privacy Act (CCPA) | CIS GCP Foundations| |
| 77 | + | CIS Azure Foundations | CIS AWS Foundations | CIS Google Cloud Platform Foundation Benchmark| |
| 78 | + | CIS Controls | CRI Profile | CIS Google Kubernetes Engine (GKE) Benchmark| |
| 79 | + | CIS Google Cloud Platform Foundation Benchmark | CSA Cloud Controls Matrix (CCM) | CRI Profile| |
| 80 | + | CIS Google Kubernetes Engine (GKE) Benchmark | GDPR | CSA Cloud Controls Matrix (CCM)| |
| 81 | + | CMMC Level 3 | ISO/IEC 27001 | Cybersecurity Maturity Model Certification (CMMC)| |
| 82 | + | CRI Profile | ISO/IEC 27002 | FFIEC Cybersecurity Assessment Tool (CAT)| |
| 83 | + | CSA Cloud Controls Matrix (CCM) | NIST Cybersecurity Framework (CSF) | GDPR| |
| 84 | + | Cybersecurity Maturity Model Certification (CMMC) | NIST SP 800-172 | ISO/IEC 27001| |
| 85 | + | FedRAMP H | PCI-DSS | ISO/IEC 27002| |
| 86 | + | FedRAMP M | | ISO/IEC 27017| |
| 87 | + | FFIEC Cybersecurity Assessment Tool (CAT) | | NIST 800-53| |
| 88 | + | GDPR | | NIST Cybersecurity Framework (CSF)| |
| 89 | + | HIPAA/HITRUST | | NIST SP 800-171| |
| 90 | + | ISO/IEC 27001:2013 | | NIST SP 800-172| |
| 91 | + | ISO/IEC 27002 | | PCI DSS| |
| 92 | + | ISO/IEC 27017 | | Sarbanes Oxley Act (SOX)| |
| 93 | + | New Zealand ISM Restricted | | SOC 2| |
| 94 | + | NIST Cybersecurity Framework (CSF) | | | |
| 95 | + | NIST SP 800 171 R2 | | | |
| 96 | + | NIST SP 800-172 | | | |
| 97 | + | NIST SP 800-53 R4 | | | |
| 98 | + | NIST SP 800-53 R5 | | | |
| 99 | + | PCI DSS | | | |
| 100 | + | RMIT Malaysia | | | |
| 101 | + | Sarbanes Oxley Act (SOX) | | | |
| 102 | + | SOC 2 Type 2 | | | |
| 103 | + | SWIFT CSP CSCF | | | |
| 104 | + | UK OFFICIAL and UK NHS | | | |
| 105 | + |
| 106 | +## Related content |
| 107 | + |
| 108 | +- [Assign regulatory compliance standards](update-regulatory-compliance-packages.md) |
0 commit comments