|
1 | 1 | ---
|
2 | 2 | title: CIS Microsoft Azure Foundations Benchmark blueprint sample controls
|
3 | 3 | description: Recommendation mapping of the CIS Microsoft Azure Foundations Benchmark blueprint sample to Azure Policy.
|
4 |
| -ms.date: 11/04/2019 |
| 4 | +ms.date: 05/01/2020 |
5 | 5 | ms.topic: sample
|
6 | 6 | ---
|
7 | 7 | # Recommendation mapping of the CIS Microsoft Azure Foundations Benchmark blueprint sample
|
8 | 8 |
|
9 | 9 | The following article details how the Azure Blueprints CIS Microsoft Azure Foundations Benchmark
|
10 | 10 | blueprint sample maps to the CIS Microsoft Azure Foundations Benchmark recommendations. For more
|
11 |
| -information about the recommendations, see |
12 |
| -[CIS Microsoft Azure Foundations Benchmark](https://www.cisecurity.org/benchmark/azure/). |
| 11 | +information about the recommendations, see [CIS Microsoft Azure Foundations Benchmark](https://www.cisecurity.org/benchmark/azure/). |
13 | 12 |
|
14 | 13 | The following mappings are to the **CIS Microsoft Azure Foundations Benchmark v1.1.0**
|
15 |
| -recommendations. Use the navigation on the right to jump directly to a specific recommendation |
16 |
| -mapping. Many of the mapped recommendations are implemented with an |
17 |
| -[Azure Policy](../../../policy/overview.md) initiative. To review the complete initiative, open |
18 |
| -**Policy** in the Azure portal and select the **Definitions** page. Then, find and select the |
19 |
| -**\[Preview\] Audit CIS Microsoft Azure Foundations Benchmark v1.1.0 recommendations and deploy |
20 |
| -specific VM Extensions to support audit requirements** built-in policy initiative. |
21 |
| - |
22 |
| -> [!IMPORTANT] Each control below is associated with one or more |
23 |
| -> [Azure Policy](../../../policy/overview.md) definitions. These policies may help you |
24 |
| -> [assess compliance](../../../policy/how-to/get-compliance-data.md) with the control; however, |
25 |
| -> there often is not a 1:1 or complete match between a control and one or more policies. As such, |
26 |
| -> **Compliant** in Azure Policy refers only to the policies themselves; this doesn't ensure you're |
27 |
| -> fully compliant with all requirements of a control. In addition, the compliance standard includes |
28 |
| -> controls that aren't addressed by any Azure Policy definitions at this time. Therefore, compliance |
29 |
| -> in Azure Policy is only a partial view of your overall compliance status. The associations between |
30 |
| -> controls and Azure Policy definitions for this compliance blueprint sample may change over time. |
31 |
| -> To view the change history, see the |
| 14 | +recommendations. Use the navigation on the right to jump directly to a specific recommendation mapping. |
| 15 | +Many of the mapped recommendations are implemented with an [Azure Policy](../../../policy/overview.md) |
| 16 | +initiative. To review the complete initiative, open **Policy** in the Azure portal and select the |
| 17 | +**Definitions** page. Then, find and select the **\[Preview\] Audit CIS Microsoft Azure Foundations |
| 18 | +Benchmark v1.1.0 recommendations and deploy specific VM Extensions to support audit requirements** |
| 19 | +built-in policy initiative. |
| 20 | + |
| 21 | +> [!IMPORTANT] |
| 22 | +> Each control below is associated with one or more [Azure Policy](../../../policy/overview.md) |
| 23 | +> definitions. These policies may help you [assess compliance](../../../policy/how-to/get-compliance-data.md) |
| 24 | +> with the control; however, there often is not a 1:1 or complete match between a control and one or |
| 25 | +> more policies. As such, **Compliant** in Azure Policy refers only to the policies themselves; this |
| 26 | +> doesn't ensure you're fully compliant with all requirements of a control. In addition, the |
| 27 | +> compliance standard includes controls that aren't addressed by any Azure Policy definitions at |
| 28 | +> this time. Therefore, compliance in Azure Policy is only a partial view of your overall compliance |
| 29 | +> status. The associations between controls and Azure Policy definitions for this compliance |
| 30 | +> blueprint sample may change over time. To view the change history, see the |
32 | 31 | > [GitHub Commit History](https://github.com/MicrosoftDocs/azure-docs/commits/master/articles/governance/blueprints/samples/cis-azure-1.1.0/control-mapping.md).
|
33 | 32 |
|
34 | 33 | ## 1.1 Ensure that multi-factor authentication is enabled for all privileged users
|
|
0 commit comments