You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/regulatory-compliance-dashboard.md
+14-23Lines changed: 14 additions & 23 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Improve regulatory compliance in Microsoft Defender for Cloud
3
3
description: Learn how to improve regulatory compliance in Microsoft Defender for Cloud.
4
4
ms.topic: tutorial
5
-
ms.date: 06/18/2023
5
+
ms.date: 02/11/2024
6
6
---
7
7
8
8
# Improve regulatory compliance
@@ -19,24 +19,19 @@ When you add any standard to your compliance dashboard (including compliance sta
19
19
20
20
Compliance Manager thus provides improvement actions and status across your cloud infrastructure and all other digital assets in this central tool. For more information, see [multicloud support in Microsoft Purview Compliance Manager](/microsoft-365/compliance/compliance-manager-multicloud).
21
21
22
-
23
-
24
-
25
22
## Before you start
26
23
27
24
- By default, when you enable Defender for Cloud on an Azure subscription, AWS account, or GCP plan, the MCSB plan is enabled
28
-
- You can add additional non-default compliance standards when at least one paid plan is enabled in Defender for Cloud.
25
+
- You can add more non-default compliance standards when at least one paid plan is enabled in Defender for Cloud.
29
26
- You must be signed in with an account that has reader access to the policy compliance data. The **Reader** role for the subscription has access to the policy compliance data, but the **Security Reader** role doesn't. At a minimum, you need to have **Resource Policy Contributor** and **Security Admin** roles assigned.
30
27
31
-
32
28
## Assess regulatory compliance
33
29
34
30
The **Regulatory compliance** dashboard shows which compliance standards are enabled. It shows the controls within each standard, and security assessments for those controls. The status of these assessments reflects your compliance with the standard.
35
31
36
32
The dashboard helps you to focus on gaps in standards, and to monitor compliance over time.
37
33
38
-
39
-
1. In the Defender for Cloud portal open the **Regulatory compliance** page.
34
+
1. In the Defender for Cloud portal, open the **Regulatory compliance** page.
40
35
41
36
:::image type="content" source="./media/regulatory-compliance-dashboard/compliance-drilldown.png" alt-text="Screenshot that shows the exploration of the details of compliance with a specific standard." lightbox="media/regulatory-compliance-dashboard/compliance-drilldown.png":::
42
37
@@ -60,15 +55,15 @@ You can use information in the dashboard to investigate issues that might affect
60
55
61
56
1. Select **Control details**.
62
57
63
-
:::image type="content" source="media/regulatory-compliance-dashboard/control-detail.png" alt-text="Screenshot that shows you where to navigate to select control details on the screen.":::
58
+
:::image type="content" source="media/regulatory-compliance-dashboard/control-detail.png" alt-text="Screenshot that shows you where to navigate to select control details on the screen." lightbox="media/regulatory-compliance-dashboard/control-detail.png":::
64
59
65
60
- Select **Overview** to see the specific information about the Control you selected.
66
61
- Select **Your Actions** to see a detailed view of automated and manual actions you need to take to improve your compliance posture.
67
62
- Select **Microsoft Actions** to see all the actions Microsoft took to ensure compliance with the selected standard.
68
63
69
64
1. Under **Your Actions**, you can select a down arrow to view more details and resolve the recommendation for that resource.
70
65
71
-
:::image type="content" source="media/regulatory-compliance-dashboard/down-arrow.png" alt-text="Screenshot that shows you where the down arrow is on the screen.":::
66
+
:::image type="content" source="media/regulatory-compliance-dashboard/down-arrow.png" alt-text="Screenshot that shows you where the down arrow is on the screen." lightbox="media/regulatory-compliance-dashboard/down-arrow.png":::
72
67
73
68
For more information about how to apply recommendations, see [Implementing security recommendations in Microsoft Defender for Cloud](review-security-recommendations.md).
74
69
@@ -79,7 +74,6 @@ You can use information in the dashboard to investigate issues that might affect
79
74
80
75
The regulatory compliance has both automated and manual assessments that might need to be remediated. Using the information in the regulatory compliance dashboard, improve your compliance posture by resolving recommendations directly within the dashboard.
81
76
82
-
83
77
1. In the Defender for Cloud portal, open **Regulatory compliance**.
84
78
85
79
1. Select a regulatory compliance standard, and select a compliance control to expand it.
@@ -88,24 +82,22 @@ The regulatory compliance has both automated and manual assessments that might n
88
82
89
83
1. Select a particular resource to view more details and resolve the recommendation for that resource. <br>For example, in the **Azure CIS 1.1.0** standard, select the recommendation **Disk encryption should be applied on virtual machines**.
90
84
91
-
:::image type="content" source="./media/regulatory-compliance-dashboard/sample-recommendation.png" alt-text="Screenshot that shows that selecting a recommendation from a standard leads directly to the recommendation details page.":::
85
+
:::image type="content" source="./media/regulatory-compliance-dashboard/sample-recommendation.png" alt-text="Screenshot that shows that selecting a recommendation from a standard leads directly to the recommendation details page." lightbox="media/regulatory-compliance-dashboard/sample-recommendation.png":::
92
86
93
87
1. In this example, when you select **Take action** from the recommendation details page, you arrive in the Azure Virtual Machine pages of the Azure portal, where you can enable encryption from the **Security** tab:
94
88
95
-
:::image type="content" source="./media/regulatory-compliance-dashboard/encrypting-vm-disks.png" alt-text="Screenshot that shows the take action button on the recommendation details page leads to the remediation options.":::
89
+
:::image type="content" source="./media/regulatory-compliance-dashboard/encrypting-vm-disks.png" alt-text="Screenshot that shows the take action button on the recommendation details page leads to the remediation options." lightbox="media/regulatory-compliance-dashboard/encrypting-vm-disks.png":::
96
90
97
91
For more information about how to apply recommendations, see [Implementing security recommendations in Microsoft Defender for Cloud](review-security-recommendations.md).
98
92
99
93
1. After you take action to resolve recommendations, you'll see the result in the compliance dashboard report because your compliance score improves.
100
94
101
-
102
-
Assessments run approximately every 12 hours, so you will see the impact on your compliance data only after the next run of the relevant assessment.
95
+
Assessments run approximately every 12 hours, so you'll see the impact on your compliance data only after the next run of the relevant assessment.
103
96
104
97
## Remediate a manual assessment
105
98
106
99
The regulatory compliance has automated and manual assessments that might need to be remediated. Manual assessments are assessments that require input from the customer to remediate them.
107
100
108
-
109
101
1. In the Defender for Cloud portal, open **Regulatory compliance**.
110
102
111
103
1. Select a regulatory compliance standard, and select a compliance control to expand it.
@@ -126,21 +118,20 @@ The regulatory compliance has automated and manual assessments that might need t
126
118
127
119
The report provides a high-level summary of your compliance status for the selected standard based on Defender for Cloud assessments data. The report's organized according to the controls of that particular standard. The report can be shared with relevant stakeholders, and might provide evidence to internal and external auditors.
128
120
129
-
:::image type="content" source="./media/regulatory-compliance-dashboard/download-report.png" alt-text="Screenshot that shows using the toolbar in Defender for Cloud's regulatory compliance dashboard to download compliance reports.":::
121
+
:::image type="content" source="./media/regulatory-compliance-dashboard/download-report.png" alt-text="Screenshot that shows using the toolbar in Defender for Cloud's regulatory compliance dashboard to download compliance reports." lightbox="media/regulatory-compliance-dashboard/download-report.png":::
130
122
131
123
1. To download Azure and Dynamics **certification reports** for the standards applied to your subscriptions, use the **Audit reports** option.
132
124
133
-
:::image type="content" source="media/release-notes/audit-reports-regulatory-compliance-dashboard.png" alt-text="Screenshot that shows using the toolbar in Defender for Cloud's regulatory compliance dashboard to download Azure and Dynamics certification reports.":::
125
+
:::image type="content" source="media/release-notes/audit-reports-regulatory-compliance-dashboard.png" alt-text="Screenshot that shows using the toolbar in Defender for Cloud's regulatory compliance dashboard to download Azure and Dynamics certification reports." lightbox="media/release-notes/audit-reports-regulatory-compliance-dashboard.png":::
134
126
135
127
1. Select the tab for the relevant reports types (PCI, SOC, ISO, and others) and use filters to find the specific reports you need:
136
128
137
-
:::image type="content" source="media/release-notes/audit-reports-list-regulatory-compliance-dashboard-ga.png" alt-text="Screenshot that shows filtering the list of available Azure Audit reports using tabs and filters.":::
129
+
:::image type="content" source="media/release-notes/audit-reports-list-regulatory-compliance-dashboard-ga.png" alt-text="Screenshot that shows filtering the list of available Azure Audit reports using tabs and filters." lightbox="media/release-notes/audit-reports-list-regulatory-compliance-dashboard-ga.png":::
138
130
139
131
For example, from the PCI tab you can download a ZIP file containing a digitally signed certificate demonstrating Microsoft Azure, Dynamics 365, and Other Online Services' compliance with ISO22301 framework, together with the necessary collateral to interpret and present the certificate.
140
132
141
-
142
133
When you download one of these certification reports, you'll be shown the following privacy notice:
143
-
134
+
144
135
_By downloading this file, you are giving consent to Microsoft to store the current user and the selected subscriptions at the time of download. This data is used in order to notify you in case of changes or updates to the downloaded audit report. This data is used by Microsoft and the audit firms that produce the certification/reports only when notification is required._
145
136
146
137
### Check compliance offerings status
@@ -172,7 +163,7 @@ Use continuous export data to an Azure Event Hubs or a Log Analytics workspace:
172
163
:::image type="content" source="media/regulatory-compliance-dashboard/export-compliance-data-snapshot.png" alt-text="Screenshot that shows how to continuously export a weekly snapshot of regulatory compliance data." lightbox="media/regulatory-compliance-dashboard/export-compliance-data-snapshot.png":::
173
164
174
165
> [!TIP]
175
-
> You can also manually export reports about a single point in time directly from the regulatory compliance dashboard. Generate these **PDF/CSV reports** or **Azure and Dynamics certification reports** using the **Download report** or **Audit reports** toolbar options.
166
+
> You can also manually export reports about a single point in time directly from the regulatory compliance dashboard. Generate these **PDF/CSV reports** or **Azure and Dynamics certification reports** using the **Download report** or **Audit reports** toolbar options.
176
167
177
168
## Trigger a workflow when assessments change
178
169
@@ -187,5 +178,5 @@ For example, you might want Defender for Cloud to email a specific user when a c
187
178
To learn more, see these related pages:
188
179
189
180
-[Customize the set of standards in your regulatory compliance dashboard](update-regulatory-compliance-packages.md) - Learn how to select which standards appear in your regulatory compliance dashboard.
190
-
-[Managing security recommendations in Defender for Cloud](review-security-recommendations.md) - Learn how to use recommendations in Defender for Cloud to help protect your Azure resources.
181
+
-[Managing security recommendations in Defender for Cloud](review-security-recommendations.md) - Learn how to use recommendations in Defender for Cloud to help protect your multicloud resources.
191
182
- Check out [common questions](faq-regulatory-compliance.yml) about regulatory compliance.
0 commit comments