Skip to content

Commit b3dd472

Browse files
Update nist-sp-800-53-r5.md
Enterprises are getting caught up in trying to meet the MS version of these controls and we need to help them understand that it is OK and encouraged to tailor this approach to meet their needs.
1 parent 3739d3f commit b3dd472

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

articles/governance/policy/samples/nist-sp-800-53-r5.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,16 @@ initiative definition.
3333
> definitions for this compliance standard may change over time. To view the change history, see the
3434
> [GitHub Commit History](https://github.com/Azure/azure-policy/commits/master/built-in-policies/policySetDefinitions/Regulatory%20Compliance/NIST_SP_800-53_R5.json).
3535

36+
>[!IMPORTANT]
37+
> These Azure Policies are an opinionated view of implementing the NIST 800-53 Rev. 5 controls. Not
38+
> every policy may be required to meet the controls for your organization. This initiative assumes
39+
> your orgnization is using Microsoft tools and properties. Some policies may prefer some Azure features
40+
> over other Azure features that equally implement the security required to meet the controls.
41+
> This is a choice the Enterprise can make by creating their own initiative.
42+
>
43+
> As such, most enterprises will need to create their own version of this initative and tailor it
44+
> to their environment and replace some polices with custom versions to implement the controls required.
45+
3646
## Access Control
3747

3848
### Policy and Procedures

0 commit comments

Comments
 (0)