Forum Discussion

AdamKolak-6034's avatar
AdamKolak-6034
Copper Contributor
Nov 27, 2019
Solved

ASC Regulatory Compliance policy definition

Hello,

can anyone give me an advice, where I can get information about technical description what really does Regulatory Compliance policy definition? (I do mean what do they really check in which scope - subscription I suppose etc.).

I was not able to find policy description e.g. for ISO27001 in documentation and FAQ.

Thx anyone for reply where to get right information.

Adam

3 Replies

  • melvynadam's avatar
    melvynadam
    Former Employee

    AdamKolak-6034 they're at the subscription level or higher.

     

    This page describes the dynamic compliance packages (preview) feature, and talks of assigning compliance packages to subscriptions or management groups:

    https://docs.microsoft.com/azure/security-center/update-regulatory-compliance-packages

     

    Hope that helps.

    • AdamKolak-6034's avatar
      AdamKolak-6034
      Copper Contributor

      melvynadam  sorry, but your answer has not reach my goal.

      E.G. look at ISO27001, it is composed from a lot of policies. Where I get information what exactelly does policies connected with this Initiative assigments? ... I know that such ACS default policy assigment is scoped and enabled at the subscription level.

      But my point is where I got Policy definition for particular parts of this defaul ACS policy assigment.

      E.G.

      "A12.2.1. Controls against malware"
      and its one of assessments:
      "Install endpoint protection solution on virtual machines"
      Where I can find such description/mapping what this assessment really technically does? (mostly probably, it checks VMs in particular subscription ... maybee windows, maybee linux ... etc.)
      Hope I cleared what I seek for.
      BR
      Adam

       

Resources