Skip to content

Commit 2eee50e

Browse files
Merge pull request #218039 from TerryLanfear/sec-221110
Update due to freshness review
2 parents e63e917 + 9e7a49e commit 2eee50e

File tree

9 files changed

+25
-23
lines changed

9 files changed

+25
-23
lines changed

articles/security/fundamentals/code-integrity.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Platform code integrity - Azure Security
33
description: Learn how Microsoft ensures that only authorized software is running.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/10/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Platform code integrity

articles/security/fundamentals/encryption-atrest.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.subservice: security-fundamentals
1212
ms.topic: article
1313
ms.tgt_pltfrm: na
1414
ms.workload: na
15-
ms.date: 08/13/2020
15+
ms.date: 11/10/2022
1616
ms.author: mbaldwin
1717

1818
---
@@ -102,7 +102,7 @@ All Managed Disks, Snapshots, and Images are encrypted using Storage Service Enc
102102

103103
#### Custom encryption at rest
104104

105-
It is recommended that whenever possible, IaaS applications leverage Azure Disk Encryption and Encryption at Rest options provided by any consumed Azure services. In some cases, such as irregular encryption requirements or non-Azure based storage, a developer of an IaaS application may need to implement encryption at rest themselves. Developers of IaaS solutions can better integrate with Azure management and customer expectations by leveraging certain Azure components. Specifically, developers should use the Azure Key Vault service to provide secure key storage as well as provide their customers with consistent key management options with that of most Azure platform services. Additionally, custom solutions should use Azure-Managed Service Identities to enable service accounts to access encryption keys. For developer information on Azure Key Vault and Managed Service Identities, see their respective SDKs.
105+
It is recommended that whenever possible, IaaS applications leverage Azure Disk Encryption and Encryption at Rest options provided by any consumed Azure services. In some cases, such as irregular encryption requirements or non-Azure based storage, a developer of an IaaS application may need to implement encryption at rest themselves. Developers of IaaS solutions can better integrate with Azure management and customer expectations by leveraging certain Azure components. Specifically, developers should use the Azure Key Vault service to provide secure key storage as well as provide their customers with consistent key management options with that of most Azure platform services. Additionally, custom solutions should use Azure managed service identities to enable service accounts to access encryption keys. For developer information on Azure Key Vault and Managed Service Identities, see their respective SDKs.
106106

107107
## Azure resource providers encryption model support
108108

articles/security/fundamentals/firmware.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Firmware security - Azure Security
33
description: Learn how Microsoft secures Azure hardware and firmware.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/24/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Firmware security

articles/security/fundamentals/hypervisor.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Hypervisor security on the Azure fleet - Azure Security
33
description: Technical overview of hypervisor security on the Azure fleet.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/24/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Hypervisor security on the Azure fleet

articles/security/fundamentals/measured-boot-host-attestation.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Firmware measured boot and host attestation - Azure Security
33
description: Technical overview of Azure firmware measured boot and host attestation.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/24/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Measured boot and host attestation

articles/security/fundamentals/platform.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Azure platform integrity and security - Azure Security
33
description: Technical overview of Azure platform integrity and security.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/24/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Platform integrity and security overview

articles/security/fundamentals/project-cerberus.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Firmware integrity - Azure Security
33
description: Learn about cryptographic measurements to ensure firmware integrity.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/24/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Project Cerberus

articles/security/fundamentals/secure-boot.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
title: Firmware secure boot - Azure Security
33
description: Technical overview of Azure firmware secure boot.
44
author: yosharm
5-
ms.service: information-protection
6-
ms.subservice: aiplabels
5+
ms.service: security
6+
ms.subservice: security-fundamentals
77
ms.topic: article
88
ms.author: terrylan
99
manager: rkarlin
10-
ms.date: 06/24/2021
10+
ms.date: 11/10/2022
1111
---
1212

1313
# Secure Boot

articles/security/journey/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -205,6 +205,8 @@
205205
href: ../fundamentals/customer-lockbox-overview.md?toc=/azure/security/journey/toc.json&bc=/azure/security/breadcrumb/toc.json
206206
- name: Security baseline for Customer Lockbox
207207
href: /security/benchmark/azure/baselines/lockbox-security-baseline?toc=/azure/security/journey/toc.json&bc=/azure/security/breadcrumb/toc.json?toc=/azure/security/journey/TOC.json?toc=/azure/security/journey/TOC.json
208+
- name: Trusted Hardware Identity Management
209+
href: ../fundamentals/trusted-hardware-identity-management.md?toc=/azure/security/journey/toc.json&bc=/azure/security/breadcrumb/toc.json
208210
- name: Checklist
209211
href: /azure/architecture/framework/security/design-storage?toc=/azure/security/journey/toc.json&bc=/azure/security/breadcrumb/toc.json
210212

0 commit comments

Comments
 (0)