Skip to content

Commit 88c5bb6

Browse files
authored
Merge pull request #113325 from memildin/asc-melvyn-containerwork
Updated a graphic, tidied the procedure, added Azure Security Benchmark
2 parents 6fe5abe + 143a015 commit 88c5bb6

File tree

3 files changed

+20
-9
lines changed

3 files changed

+20
-9
lines changed
Loading

articles/security-center/update-regulatory-compliance-packages.md

Lines changed: 20 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -19,11 +19,11 @@ ms.author: memildin
1919

2020
Azure Security Center continually compares the configuration of your resources with requirements in industry standards, regulations, and benchmarks. The **regulatory compliance dashboard** provides insights into your compliance posture based on how you're meeting specific compliance controls and requirements.
2121

22-
One standard for which you can track your compliance posture is [Azure CIS 1.1.0](https://www.cisecurity.org/benchmark/azure/) (more formally, the "CIS Microsoft Azure Foundations Benchmark version 1.1.0").
22+
With the **dynamic compliance packages** feature, Security Center *automatically improves its coverage of industry standards over time*.
2323

24-
The representation of Azure CIS that initially appears in your compliance dashboard relies on a static set of rules that is included with Security Center.
24+
One standard for which you can track your compliance posture is [Azure CIS 1.1.0](https://www.cisecurity.org/benchmark/azure/) (more formally, the "CIS Microsoft Azure Foundations Benchmark version 1.1.0"). The representation of Azure CIS that initially appears in your compliance dashboard relies on a static set of rules that is included with Security Center.
2525

26-
With the **dynamic compliance packages** feature, Security Center automatically improves its coverage of industry standards over time. Compliance packages are essentially initiatives defined in Azure Policy. They can be assigned to your selected scope (subscription, management group, and so on). To see compliance data mapped as assessments in your dashboard, add a compliance package to your management group or subscription from within the Security Policy. Adding a compliance package effectively assigns the regulatory compliance initiative to your selected scope. In this way, you can track newly published regulatory initiatives as compliance standards in your dashboard. When Microsoft releases new content for the initiative (new policies that map to more controls in the standard), the additional content appears automatically in your dashboard.
26+
Compliance packages are essentially initiatives defined in Azure Policy. They can be assigned to your selected scope (subscription, management group, and so on). To see compliance data mapped as assessments in your dashboard, add a compliance package to your management group or subscription from within the Security Policy. Adding a compliance package effectively assigns the regulatory compliance initiative to your selected scope. In this way, you can track newly published regulatory initiatives as compliance standards in your dashboard. When Microsoft releases new content for the initiative (new policies that map to more controls in the standard), the additional content appears automatically in your dashboard.
2727

2828
The dynamic compliance package for the Azure CIS benchmark, **Azure CIS 1.1.0 (new)**, improves on the original *static* version by:
2929

@@ -38,22 +38,33 @@ The following steps explain how to add the dynamic package for monitoring your c
3838

3939
### Update to the Azure CIS 1.1.0 (new) dynamic compliance package
4040

41-
1. Open the **Security policy** page. This page shows the number of management groups, subscriptions, workspaces, and your management group structure.
41+
1. From Security Center's sidebar, select **Regulatory compliance** to open the regulatory compliance dashboard. Here you can see the compliance standards currently assigned to the currently selected subscriptions.
4242

43-
1. Select the subscription or management group for which you want to manage the regulatory compliance posture. We recommend selecting the highest scope for which the standard is applicable so that compliance data is aggregated and tracked for all nested resources.
43+
1. From the top of the page, select **Manage compliance policies**. This opens the Policy Management page.
44+
45+
1. Select the subscription or management group for which you want to manage the regulatory compliance posture.
46+
47+
> [!TIP]
48+
> We recommend selecting the highest scope for which the standard is applicable so that compliance data is aggregated and tracked for all nested resources.
4449
4550
1. In the Industry & regulatory standards section, you'll see that Azure CIS 1.1.0 can be updated for new content. Click **Update now**.
4651

47-
1. Optionally, click **Add more standards** to open the **Add regulatory compliance standards** page. There, you can search manually for **Azure CIS 1.1.0 (New)** and dynamic packages for other compliance standards such as **NIST SP 800-53 R4**, **SWIFT CSP CSCF-v2020**, **UKO and UK NHS**, and **Canada PBMM**.
52+
1. Optionally, click **Add more standards** to open the **Add regulatory compliance standards** page. There, you can search manually for **Azure CIS 1.1.0 (New)** and dynamic packages for other compliance standards such as:
53+
54+
- **Azure Security Benchmark** ([details here](https://docs.microsoft.com/azure/security/benchmarks/introduction))
55+
- **NIST SP 800-53 R4**
56+
- **SWIFT CSP CSCF-v2020**
57+
- **UKO and UK NHS**
58+
- **Canada PBMM**
4859

4960
> [!TIP]
5061
> Only users who are owner or policy contributor have the necessary permissions to add compliance standards.
5162
52-
![Adding regulatory packages to Azure Security Center's regulatory compliance dashboard](./media/update-regulatory-compliance-packages/security-center-dynamic-regulatory-compliance-additional-standards.png)
63+
![Adding regulatory packages to Azure Security Center's regulatory compliance dashboard](./media/update-regulatory-compliance-packages/dynamic-regulatory-compliance-additional-standards.png)
5364

5465

55-
1. From Security Center's sidebar, select **Regulatory compliance** to open the regulatory compliance dashboard.
56-
* Azure CIS 1.1.0 (New) now appears in your list of Industry & regulatory standards.
66+
1. From Security Center's sidebar, select **Regulatory compliance** again to go back to the regulatory compliance dashboard.
67+
* **Azure CIS 1.1.0 (New)** now appears in your list of Industry & regulatory standards.
5768
* The original *static* view of your Azure CIS 1.1.0 compliance will also remain alongside it. It may be automatically removed in the future.
5869

5970
> [!NOTE]

0 commit comments

Comments
 (0)