You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/security-center/update-regulatory-compliance-packages.md
+17-25Lines changed: 17 additions & 25 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,11 +22,9 @@ Azure Security Center continually compares the configuration of your resources w
22
22
23
23
## Overview of compliance packages
24
24
25
-
Compliance 'packages' are essentially initiatives defined in Azure Policy. To see compliance data mapped as assessments in your dashboard, add a compliance package to your management group or subscription from within the **Security policy** page.
25
+
Industry standards, regulatory standards, and benchmarks are represented in Security Center as *compliance packages*. Each package is an initiative defined in Azure Policy. To see compliance data mapped as assessments in your dashboard, add a compliance package to your management group or subscription from within the **Security policy** page. (Learn more about Azure Policy and initiatives in [Working with security policies](tutorial-security-policy.md).)
26
26
27
-
Adding a compliance package effectively assigns the regulatory compliance initiative to your selected scope. In this way, you can track newly published regulatory initiatives as compliance standards in your dashboard.
28
-
29
-
When you've onboarded a standard or benchmark, the standard appears in your regulatory compliance dashboard with all associated compliance data mapped as assessments. You can also download summary reports for any of the standards that have been onboarded.
27
+
When you've onboarded a standard or benchmark to your selected scope, the standard appears in your regulatory compliance dashboard with all associated compliance data mapped as assessments. You can also download summary reports for any of the standards that have been onboarded.
30
28
31
29
Microsoft also tracks the regulatory standards themselves and automatically improves its coverage in some of the packages over time. When Microsoft releases new content for the initiative (new policies that map to more controls in the standard), the additional content appears automatically in your dashboard.
32
30
@@ -36,9 +34,11 @@ Microsoft also tracks the regulatory standards themselves and automatically impr
36
34
37
35
## Available packages
38
36
39
-
You can add standards such as NIST SP 800-53 R4, SWIFT CSP CSCF-v2020, UK Official and UK NHS, Canada Federal PBMM, and Azure CIS 1.1.0 (new), which is a more complete representation of Azure CIS 1.1.0.
37
+
You can add standards such as NIST SP 800-53 R4, SWIFT CSP CSCF-v2020, UK Official and UK NHS, Canada Federal PBMM, and Azure CIS 1.1.0 (new) - a more complete representation of Azure CIS 1.1.0.
38
+
39
+
In addition, you can add **Azure Security Benchmark**, the Microsoft-authored, Azure-specific guidelines for security and compliance best practices based on common compliance frameworks. ([Learn more about Azure Security Benchmark](https://docs.microsoft.com/azure/security/benchmarks/introduction).)
40
40
41
-
In addition, you can add Azure Security Benchmark, the Microsoft-authored, Azure-specific guidelines for security and compliance best practices based on common compliance frameworks. Additional standards will be supported in the dashboard as they become available.
41
+
Additional standards will be supported in the dashboard as they become available.
42
42
43
43
44
44
## Adding a regulatory standard to your dashboard
@@ -57,41 +57,33 @@ The following steps explain how to add a package to monitor your compliance with
57
57
> [!TIP]
58
58
> We recommend selecting the highest scope for which the standard is applicable so that compliance data is aggregated and tracked for all nested resources.
59
59
60
-
1.Select standards relevant to you:
60
+
1.To add the standards relevant to your organization, click **Add more standards**.
61
61
62
-
- To update Azure CIS 1.1.0 with new content, select **Update now** alongside it in the Industry & regulatory standards section.
62
+
1. From the **Add regulatory compliance standards** page, you can search for packages for any of the available standards. Some of the standards available are:
63
63
64
-
- Optionally, click **Add more standards** to open the **Add regulatory compliance standards** page. There, you can search manually for packages for any of the available standards. Some of the standards available are:

73
71
74
-
75
72
1. From Security Center's sidebar, select **Regulatory compliance** again to go back to the regulatory compliance dashboard.
76
73
* Your new standard appears in your list of Industry & regulatory standards.
77
74
* If you've added **Azure CIS 1.1.0 (New)**, the original *static* view of your Azure CIS 1.1.0 compliance will also remain alongside it. It may be automatically removed in the future.
78
75
79
76
> [!NOTE]
80
77
> It may take a few hours for a newly added standard to appear in the compliance dashboard.
81
78
82
-
83
-
[](media/update-regulatory-compliance-packages/security-center-dynamic-regulatory-compliance-cis-old-and-new.png#lightbox)
84
-
79
+
[](media/update-regulatory-compliance-packages/regulatory-compliance-dashboard-with-asb.png#lightbox)
85
80
86
81
## Next steps
87
82
88
-
In this article, you learned:
89
-
90
-
* How to **upgrade the standards** shown in your regulatory compliance dashboard to the new *dynamic* packages
91
-
* How to **add compliance packages** to monitor your compliance with additional standards.
83
+
In this article, you learned how to **add compliance packages** to monitor your compliance with additional standards.
92
84
93
85
For other related material, see the following articles:
-[Security center regulatory compliance dashboard](security-center-compliance-dashboard.md)
96
-
-[Working with security policies](tutorial-security-policy.md)
97
-
-[Managing security recommendations in Azure Security Center](security-center-recommendations.md) - Learn how to use recommendations in Azure Security Center to help protect your Azure resources.
89
+
-[Working with security policies](tutorial-security-policy.md)
0 commit comments