Skip to content

Commit 832653e

Browse files
authored
Update documentation-government-impact-level-5.md
1 parent 49d2d26 commit 832653e

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

articles/azure-government/documentation-government-impact-level-5.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ To include a service in Impact Level 5 scope, there are two key areas that will
3434

3535
### Compute isolation
3636

37-
The SRG focuses on segmentation of compute when 'processing' data for Impact Level 5. This means ensuring that a virtual machine that compromises the physical host cannot impact a DoD workload. To remove the risk of runtime attacks and ensure long running workloads are not compromised from other workloads on the same host, all Impact Level 5 virtual machines should be isolated using Azure Dedicated Host
37+
The SRG focuses on segmentation of compute when 'processing' data for Impact Level 5. This means ensuring that a virtual machine that compromises the physical host cannot impact a DoD workload. To remove the risk of runtime attacks and ensure long running workloads are not compromised from other workloads on the same host, all Impact Level 5 virtual machines should be isolated using Azure Dedicated Hosts
3838
which provides a dedicated physical server to host your Azure VMs for Windows and Linux.
3939

4040
For services where the compute processes are obfuscated from access by the owner and stateless in their processing of data; isolation will be accomplished by focusing on the data being processed and how it is stored and retained. This approach ensures that the data in question is stored in protected mediums and not present on these services for extended periods unless also encrypted as necessary.
@@ -217,7 +217,7 @@ Current Dedicated Host SKUs (VM series and Host Type) that offer necessary compu
217217

218218
#### Isolated Virtual Machines
219219

220-
Virtual machine scale sets are not currently supported on Azure Dedicated Hosts. Specific VM types when deployed consume the entire physical host for that VM. Each of the above VM types can be deployed leveraging virtual machine scale sets to provide proper compute isolation with all the benefits of virtual machine scale sets in place. When configuring your scale set, select the appropriate SKU. To encrypt the data at rest, see the next section for supportable encryption options.
220+
Virtual machine scale sets are not currently supported on Azure Dedicated Hosts. However, specific VM types when deployed consume the entire physical host for that VM. Each of the above VM types can be deployed leveraging virtual machine scale sets to provide proper compute isolation with all the benefits of virtual machine scale sets in place. When configuring your scale set, select the appropriate SKU. To encrypt the data at rest, see the next section for supportable encryption options.
221221

222222
Current VM SKUs that offer necessary compute isolation include specific offerings from our VM families:
223223

@@ -318,7 +318,7 @@ Azure DevTest Labs can be used in Azure Government supporting Impact Level 5 wor
318318

319319
Azure Stack Edge can be used in Azure Government supporting Impact Level 5 workloads with no additional configuration in the following regions:
320320

321-
You can protect data via storage accounts as your device is associated with a storage account that's used as a destination for your data in Azure. Access to the storage account is controlled by the subscription and two 512-bit storage access keys associated with that storage account. (https://docs.microsoft.com/azure/databox-online/data-box-edge-security#protect-your-data)
321+
You can protect data via storage accounts as your device is associated with a storage account that's used as a destination for your data in Azure. Access to the storage account is controlled by the subscription and FIPS compliant storage access keys associated with that storage account. (https://docs.microsoft.com/azure/databox-online/data-box-edge-security#protect-your-data)
322322

323323
| **Service** | **USGov VA** | **USGov IA** | **USGov TX** | **USGov AZ** | **USDoD East** | **USDoD Cent** |
324324
| --- | --- | --- | --- | --- | --- | --- |
@@ -441,7 +441,7 @@ Azure Cost Management can be used in Azure Government supporting Impact Level 5
441441

442442
Azure Managed Applications can be used in Azure Government supporting Impact Level 5 workloads in the following configurations:
443443

444-
Bring your own storage for the managed application definition and store your managed application definition within a storage account provided by you during creation so that it's location and access can be fully managed by you for your regulatory needs. (https://docs.microsoft.com/azure/azure-resource-manager/managed-applications/publish-service-catalog-app#bring-your-own-storage-for-the-managed-application-definition)
444+
You can store your managed application definition within a storage account provided by you during creation so that it's location and access can be fully managed by you for your regulatory needs. (https://docs.microsoft.com/azure/azure-resource-manager/managed-applications/publish-service-catalog-app#bring-your-own-storage-for-the-managed-application-definition)
445445

446446
| **Service** | **USGov VA** | **USGov IA** | **USGov TX** | **USGov AZ** | **USDoD East** | **USDoD Cent** |
447447
| --- | --- | --- | --- | --- | --- | --- |
@@ -465,7 +465,7 @@ Azure Policy can be used in Azure Government supporting Impact Level 5 workloads
465465

466466
### [Microsoft Azure portal](https://azure.microsoft.com/features/azure-portal/)
467467

468-
Microsoft Azure portal can be used in Azure Government supporting Impact Level 5 workloads in the following configurations:
468+
Microsoft Azure portal can be used in Azure Government supporting Impact Level 5 workloads with no additional configuration in the following regions:
469469

470470
You can add a markdown tile to your Azure dashboards to display custom, static content. For example, you can show basic instructions, an image, or a set of hyperlinks on a markdown tile (https://docs.microsoft.com/azure/azure-portal/azure-portal-markdown-tile)
471471

0 commit comments

Comments
 (0)