Event banner
Microsoft Government CMMC AMA
Event Ended
Tuesday, Apr 12, 2022, 10:30 AM PDTEvent details
We want to hear from our customers and answer their questions around how we can help them achieve CMMC compliance with your Microsoft Azure and Microsoft 365 subscriptions. We will be hosting an "Ask...
Sarah_Gilbert
Updated Apr 12, 2022
ndelena
Copper Contributor
What are the current rules around conducting a penetration test against a company's footprint in GCC High and Azure government? We have a handful of clients that are expecting eventual CMMC Level 3 requirements.
justinO
Apr 12, 2022Microsoft
Hi Nick - Thank you for asking this. We do have a Penetration Testing Rules of Engagement which outlines scope and engagement: https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement?msclkid=bf4ba221ba8711ec80349cf2bb73b179.
Aside from this Microsoft also conducts penetration testing on a regular basis of our services and software.
- ndelenaApr 12, 2022Copper ContributorThanks Justin! Just to clarify, these rules apply to GCC High and Azure Government as well?
- RichardWakemanApr 12, 2022MicrosoftThis is general for all our cloud products and services.