You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/security-center/update-regulatory-compliance-packages.md
+22-15Lines changed: 22 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,28 +15,35 @@ ms.date: 11/04/2019
15
15
ms.author: memildin
16
16
17
17
---
18
-
# Using dynamic compliance packages in your Regulatory Compliance dashboard
18
+
# Customizing the set of standards in your regulatory compliance dashboard
19
19
20
20
Azure Security Center continually compares the configuration of your resources with requirements in industry standards, regulations, and benchmarks. The **regulatory compliance dashboard** provides insights into your compliance posture based on how you're meeting specific compliance controls and requirements.
21
21
22
-
With the **dynamic compliance packages** feature, Security Center *automatically improves its coverage of industry standards over time*.
23
22
24
-
One standard for which you can track your compliance posture is [Azure CIS 1.1.0](https://www.cisecurity.org/benchmark/azure/) (more formally, the "CIS Microsoft Azure Foundations Benchmark version 1.1.0"). The representation of Azure CIS that initially appears in your compliance dashboard relies on a static set of rules that is included with Security Center.
23
+
## Overview of compliance packages
25
24
26
-
Compliance packages are essentially initiatives defined in Azure Policy. They can be assigned to your selected scope (subscription, management group, and so on). To see compliance data mapped as assessments in your dashboard, add a compliance package to your management group or subscription from within the Security Policy. Adding a compliance package effectively assigns the regulatory compliance initiative to your selected scope. In this way, you can track newly published regulatory initiatives as compliance standards in your dashboard. When Microsoft releases new content for the initiative (new policies that map to more controls in the standard), the additional content appears automatically in your dashboard.
25
+
Compliance 'packages' are essentially initiatives defined in Azure Policy. To see compliance data mapped as assessments in your dashboard, add a compliance package to your management group or subscription from within the **Security policy** page.
27
26
28
-
The dynamic compliance package for the Azure CIS benchmark, **Azure CIS 1.1.0 (new)**, improves on the original *static* version by:
27
+
Adding a compliance package effectively assigns the regulatory compliance initiative to your selected scope. In this way, you can track newly published regulatory initiatives as compliance standards in your dashboard.
29
28
30
-
* Including more policies
31
-
* Automatically updating with new coverage as it's added
29
+
When you've onboarded a standard or benchmark, the standard appears in your regulatory compliance dashboard with all associated compliance data mapped as assessments. You can also download summary reports for any of the standards that have been onboarded.
32
30
33
-
Update to the new dynamic package as described below.
31
+
Microsoft also tracks the regulatory standards themselves and automatically improves its coverage in some of the packages over time. When Microsoft releases new content for the initiative (new policies that map to more controls in the standard), the additional content appears automatically in your dashboard.
34
32
35
-
## Adding a dynamic compliance package
33
+
> [!TIP]
34
+
> One standard which improves over time as Microsoft releases new content is **Azure CIS 1.1.0 (new)** (more formally, the [CIS Microsoft Azure Foundations Benchmark version 1.1.0](https://www.cisecurity.org/benchmark/azure/)). You'll need to add this to your dashboard alongside "Azure CIS 1.1.0", the representation of Azure CIS that is configured by default in every Security Center environment. That package relies on a static set of rules. The newer package includes more policies and will automatically update over time. Update to the new dynamic package as described below.
36
35
37
-
The following steps explain how to add the dynamic package for monitoring your compliance with the Azure CIS benchmark v1.1.0.
38
36
39
-
### Update to the Azure CIS 1.1.0 (new) dynamic compliance package
37
+
## Available packages
38
+
39
+
You can add standards such as NIST SP 800-53 R4, SWIFT CSP CSCF-v2020, UK Official and UK NHS, Canada Federal PBMM, and Azure CIS 1.1.0 (new) (which is a more complete representation of Azure CIS 1.1.0).
40
+
41
+
In addition, you can add Azure Security Benchmark, the Microsoft-authored Azure-specific guidelines for security and compliance best practices based on common compliance frameworks. Additional standards will be supported in the dashboard as they become available.
42
+
43
+
44
+
## Adding a regulatory standard to your dashboard
45
+
46
+
The following steps explain how to add a package to monitor your compliance with one of the supported regulatory standards.
40
47
41
48
1. From Security Center's sidebar, select **Regulatory compliance** to open the regulatory compliance dashboard. Here you can see the compliance standards currently assigned to the currently selected subscriptions.
42
49
@@ -47,9 +54,9 @@ The following steps explain how to add the dynamic package for monitoring your c
47
54
> [!TIP]
48
55
> We recommend selecting the highest scope for which the standard is applicable so that compliance data is aggregated and tracked for all nested resources.
49
56
50
-
1.In the Industry & regulatory standards section, you'll see that Azure CIS 1.1.0 can be updated for new content. Click**Update now**.
57
+
1.To update Azure CIS 1.1.0 with new content, select**Update now** alongside it in the Industry & regulatory standards section.
51
58
52
-
1. Optionally, click **Add more standards** to open the **Add regulatory compliance standards** page. There, you can search manually for **Azure CIS 1.1.0 (New)** and dynamic packages for other compliance standards such as:
59
+
1. Optionally, click **Add more standards** to open the **Add regulatory compliance standards** page. There, you can search manually for packages for any of the available standards. These include:
@@ -64,8 +71,8 @@ The following steps explain how to add the dynamic package for monitoring your c
64
71
65
72
66
73
1. From Security Center's sidebar, select **Regulatory compliance** again to go back to the regulatory compliance dashboard.
67
-
***Azure CIS 1.1.0 (New)** now appears in your list of Industry & regulatory standards.
68
-
*The original *static* view of your Azure CIS 1.1.0 compliance will also remain alongside it. It may be automatically removed in the future.
74
+
*Your new standard appears in your list of Industry & regulatory standards.
75
+
*If you've added **Azure CIS 1.1.0 (New)**, the original *static* view of your Azure CIS 1.1.0 compliance will also remain alongside it. It may be automatically removed in the future.
69
76
70
77
> [!NOTE]
71
78
> It may take a few hours for a newly added standard to appear in the compliance dashboard.
0 commit comments