You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/security/fundamentals/infrastructure.md
+5-28Lines changed: 5 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: The article describes how Microsoft works to secure our Azure datac
4
4
services: security
5
5
documentationcenter: na
6
6
author: TerryLanfear
7
-
manager: barbkess
7
+
manager: rkarlin
8
8
editor: TomSh
9
9
10
10
ms.assetid: 61e95a87-39c5-48f5-aee6-6f90ddcd336e
@@ -14,14 +14,15 @@ ms.devlang: na
14
14
ms.topic: article
15
15
ms.tgt_pltfrm: na
16
16
ms.workload: na
17
-
ms.date: 07/06/2018
17
+
ms.date: 10/18/2019
18
18
ms.author: terrylan
19
19
20
20
---
21
21
22
22
# Azure infrastructure security
23
23
Microsoft Azure runs in datacenters managed and operated by Microsoft. These geographically dispersed datacenters comply with key industry standards, such as ISO/IEC 27001:2013 and NIST SP 800-53, for security and reliability. The datacenters are managed, monitored, and administered by Microsoft operations staff. The operations staff has years of experience in delivering the world’s largest online services with 24 x 7 continuity.
24
24
25
+
## Securing the Azure infrastructure
25
26
This series of articles provides information about what Microsoft does to secure the Azure infrastructure. The articles address:
26
27
27
28
-[Physical security](physical-security.md)
@@ -35,32 +36,8 @@ This series of articles provides information about what Microsoft does to secure
35
36
-[Integrity](infrastructure-integrity.md)
36
37
-[Data protection](protection-customer-data.md)
37
38
38
-
## Shared responsibility model
39
-
It’s important to understand the division of responsibility between you and Microsoft. On-premises, you own the whole stack, but as you move to the cloud, some responsibilities transfer to Microsoft. The following graphic illustrates the areas of responsibility, according to the type of deployment of your stack (software as a service [SaaS], platform as a service [PaaS], infrastructure as a service [IaaS], and on-premises).
You are always responsible for the following, regardless of the type of deployment:
44
-
45
-
- Data
46
-
- Endpoints
47
-
- Account
48
-
- Access management
49
-
50
-
Be sure that you understand the division of responsibility between you and Microsoft in a SaaS, PaaS, and IaaS deployment. For more information, see [Shared responsibilities for cloud computing](https://gallery.technet.microsoft.com/Shared-Responsibilities-81d0ff91/file/225237/1/Shared%20Responsibilities%20for%20Cloud%20Computing%20(2017-04-03).pdf).
51
-
52
39
## Next steps
53
-
To learn more about what Microsoft does to help secure the Azure infrastructure, see:
54
-
55
-
-[Azure facilities, premises, and physical security](physical-security.md)
-[Azure customer data protection](protection-customer-data.md)
65
40
41
+
- Understand your [shared responsibility in the cloud](shared-responsibility.md).
66
42
43
+
- Learn how [Azure Security Center](https://azure.microsoft.com/services/security-center/) can help you prevent, detect, and respond to threats with increased visibility and control over the security of your Azure resources.
Copy file name to clipboardExpand all lines: articles/security/fundamentals/overview.md
+5-8Lines changed: 5 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.devlang: na
14
14
ms.topic: article
15
15
ms.tgt_pltfrm: na
16
16
ms.workload: na
17
-
ms.date: 10/17/2019
17
+
ms.date: 10/18/2019
18
18
ms.author: TomSh
19
19
20
20
---
@@ -89,9 +89,9 @@ Azure Monitor logs can be a useful tool in forensic and other security analysis,
89
89
[Azure Advisor](../../advisor/index.yml) is a personalized cloud consultant that helps you to optimize your Azure deployments. It analyzes your resource configuration and usage telemetry. It then recommends solutions to help improve the [performance](../../advisor/advisor-performance-recommendations.md), [security](../../advisor/advisor-security-recommendations.md), and [high availability](../../advisor/advisor-high-availability-recommendations.md) of your resources while looking for opportunities to [reduce your overall Azure spend](../../advisor/advisor-cost-recommendations.md). Azure Advisor provides security recommendations, which can significantly improve your overall security posture for solutions you deploy in Azure. These recommendations are drawn from security analysis performed by [Azure Security Center.](../../security-center/security-center-intro.md)
90
90
91
91
### Azure Security Center
92
-
[Azure Security Center](../../security-center/security-center-intro.md) helps you prevent, detect, and respond to threats with increased visibility into and control over the security of your Azure resources. It provides integrated security monitoring and policy management across your Azure subscriptions, helps detect threats that might otherwise go unnoticed, and works with a broad ecosystem of security solutions.
92
+
[Security Center](../../security-center/security-center-intro.md) helps you prevent, detect, and respond to threats with increased visibility into and control over the security of your Azure resources. It provides integrated security monitoring and policy management across your Azure subscriptions, helps detect threats that might otherwise go unnoticed, and works with a broad ecosystem of security solutions.
93
93
94
-
In addition, Azure Security Center helps with security operations by providing you a single dashboard that surfaces alerts and recommendations that can be acted upon immediately. Often, you can remediate issues with a single click within the Azure Security Center console.
94
+
In addition, Security Center helps with security operations by providing you a single dashboard that surfaces alerts and recommendations that can be acted upon immediately. Often, you can remediate issues with a single click within the Security Center console.
95
95
## Applications
96
96
The section provides additional information regarding key features in application security and summary information about these capabilities.
97
97
@@ -282,7 +282,7 @@ You can enable the following diagnostic log categories for NSGs:
282
282
283
283
- Rules counter: Contains entries for how many times each NSG rule is applied to deny or allow traffic.
284
284
285
-
### Azure Security Center
285
+
### Security Center
286
286
[Azure Security Center](../../security-center/security-center-intro.md) continuously analyzes the security state of your Azure resources for network security best practices. When Security Center identifies potential security vulnerabilities, it creates [recommendations](../../security-center/security-center-recommendations.md) that guide you through the process of configuring the needed controls to harden and protect your resources.
287
287
288
288
## Compute
@@ -317,10 +317,7 @@ Virtual machines need network connectivity. To support that requirement, Azure r
317
317
Patch Updates provide the basis for finding and fixing potential problems and simplify the software update management process, both by reducing the number of software updates you must deploy in your enterprise and by increasing your ability to monitor compliance.
318
318
319
319
### Security policy management and reporting
320
-
[Azure Security Center](../../security-center/security-center-intro.md) helps you prevent, detect, and respond to threats, and provides you increased visibility into, and control over, the security of your Azure resources. It provides integrated Security monitoring and policy management across your Azure subscriptions, helps detect threats that might otherwise go unnoticed, and works with a broad ecosystem of security solutions.
321
-
322
-
### Azure Security Center
323
-
Security Center helps you prevent, detect, and respond to threats with increased visibility into and control over the security of your Azure resources. It provides integrated security monitoring and policy management across your Azure subscriptions, helps detect threats that might otherwise go unnoticed, and works with a broad ecosystem of security solutions.
320
+
[Security Center](../../security-center/security-center-intro.md) helps you prevent, detect, and respond to threats, and provides you increased visibility into, and control over, the security of your Azure resources. It provides integrated Security monitoring and policy management across your Azure subscriptions, helps detect threats that might otherwise go unnoticed, and works with a broad ecosystem of security solutions.
324
321
325
322
## Identity and access management
326
323
Securing systems, applications, and data begins with identity-based access controls. The identity and access management features that are built into Microsoft business products and services help protect your organizational and personal information from unauthorized access while making it available to legitimate users whenever and wherever they need it.
0 commit comments