Forum Discussion
ASC Security Policies & Compliance Wording
- Aug 05, 2020
Hi GlavniArhivator,
thanks for asking these great questions, I'll try to answer them in the respective order using a numbered list.
- Regulatory compliance is part of the ASC Standard tier, whereas Secure Score comes with the ASC free tier. Today, we do not map the compliance assessment results to your Secure Score.
- The Azure Security Benchmark is not exactly the same, as the CIS 1.1.0 benchmark we have integrated in ASC. However, its controls are consistent with other well-known security benchmarks, such as CIS 7.1. You can find more information about the Azure Security Benchmark at https://docs.microsoft.com/en-us/azure/security/benchmarks/overview.
- Benchmarks and Azure Policy are not the same. You can see Azure Policy as the tool for technically implementing auditing of security benchmarks. So, the recommendations you see in your Security Controls in the Resource Security Hygiene part of Azure Security Center are derived from well-known security benchmarks and the technical implementation under the hood is based on Azure Policy. In other words: we are using Azure Policy to create the recommendations you see in Azure Security Center, but these recommendations are based on industry-standard security best-practices.
- No, this is not possible today. The security policy Azure Security Center relies on is scoped to the Management Group or Subscription level.
Best regards,
Tom Janetscheck
Senior Program Manager
CxE | Azure Security Center
Thanks Tom. Where can I find Remediate security configurations security control ? I don't see that anywhere.
Kind regards
Hi GlavniArhivator,
you find it in the Resource Security Hygiene part of Azure Security Center:
Remediate security configurations Security Control in Azure Security Center
Best regards,
Tom
- Tom_JanetscheckAug 07, 2020
Microsoft
Hey GlavniArhivator,
they are grouped as vulnerabilities under the Vulnerabilities in security configuration on your machines should be remediated recommendation, which is part of the above mentioned security control.
Best,
Tom
- GlavniArhivatorAug 07, 2020Copper Contributor
Sorry Tom, I meant the CCE-... recommendations within the regulatory policy controls (like SOC, ISO ...).
Thanks and all the best