SOLVED

ASC Regulatory Compliance policy definition

%3CLINGO-SUB%20id%3D%22lingo-sub-1035515%22%20slang%3D%22en-US%22%3EASC%20Regulatory%20Compliance%20policy%20definition%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1035515%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3Ecan%20anyone%20give%20me%20an%20advice%2C%20where%20I%20can%20get%20information%20about%20technical%20description%20what%20really%20does%20Regulatory%20Compliance%20policy%20definition%3F%20(I%20do%20mean%20what%20do%20they%20really%20check%20in%20which%20scope%20-%20subscription%20I%20suppose%20etc.).%3C%2FP%3E%3CP%3EI%20was%20not%20able%20to%20find%20policy%20description%20e.g.%20for%20ISO27001%20in%20documentation%20and%20FAQ.%3C%2FP%3E%3CP%3EThx%20anyone%20for%20reply%20where%20to%20get%20right%20information.%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1035515%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EASC%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1035626%22%20slang%3D%22en-US%22%3ERe%3A%20ASC%20Regulatory%20Compliance%20policy%20definition%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1035626%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F427984%22%20target%3D%22_blank%22%3E%40AdamKolak-6034%3C%2FA%3E%20they're%20at%20the%20subscription%20level%20or%20higher.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20page%20describes%20the%20dynamic%20compliance%20packages%20(preview)%20feature%2C%20and%20talks%20of%20assigning%20compliance%20packages%20to%20subscriptions%20or%20management%20groups%3A%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fsecurity-center%2Fupdate-regulatory-compliance-packages%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fsecurity-center%2Fupdate-regulatory-compliance-packages%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20that%20helps.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1035652%22%20slang%3D%22en-US%22%3ERe%3A%20ASC%20Regulatory%20Compliance%20policy%20definition%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1035652%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F434547%22%20target%3D%22_blank%22%3E%40melvynadam%3C%2FA%3E%26nbsp%3B%20sorry%2C%20but%20your%20answer%20has%20not%20reach%20my%20goal.%3C%2FP%3E%3CP%3EE.G.%20look%20at%20ISO27001%2C%20it%20is%20composed%20from%20a%20lot%20of%20policies.%20Where%20I%20get%20information%20what%20exactelly%20does%20policies%20connected%20with%20this%20Initiative%20assigments%3F%20...%20I%20know%20that%20such%20ACS%20default%20policy%20assigment%20is%20scoped%20and%20enabled%20at%20the%20subscription%20level.%3C%2FP%3E%3CP%3EBut%20my%20point%20is%20where%20I%20got%20Policy%20definition%20for%20particular%20parts%20of%20this%20defaul%20ACS%20policy%20assigment.%3C%2FP%3E%3CP%3EE.G.%3C%2FP%3E%3CDIV%20class%3D%22fxc-accordion-header-text%22%3E%3CDIV%20class%3D%22ext-compliance-rule-container%20ext-compliance-rule-container-automationId%22%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3E%22A12.2.1.%20Controls%20against%20malware%22%3C%2FDIV%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3Eand%20its%20one%20of%20assessments%3A%3C%2FDIV%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3E%22I%3CSPAN%20class%3D%22ext-compliance-ruleControl-gridItem-displayName-notClickable%22%3Enstall%20endpoint%20protection%20solution%20on%20virtual%20machines%22%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3E%3CSPAN%20class%3D%22ext-compliance-ruleControl-gridItem-displayName-notClickable%22%3EWhere%20I%20can%20find%20such%20description%2Fmapping%20what%20this%20assessment%20really%20technically%20does%3F%20(mostly%20probably%2C%20it%20checks%20VMs%20in%20particular%20subscription%20...%20maybee%20windows%2C%20maybee%20linux%20...%20etc.)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3E%3CSPAN%20class%3D%22ext-compliance-ruleControl-gridItem-displayName-notClickable%22%3EHope%20I%20cleared%20what%20I%20seek%20for.%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3E%3CSPAN%20class%3D%22ext-compliance-ruleControl-gridItem-displayName-notClickable%22%3EBR%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ext-compliance-rule-title-ruleId%22%3E%3CSPAN%20class%3D%22ext-compliance-ruleControl-gridItem-displayName-notClickable%22%3EAdam%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CH3%20id%3D%22toc-hId-1055844947%22%20id%3D%22toc-hId-1055844947%22%20id%3D%22toc-hId-1055844947%22%3E%26nbsp%3B%3C%2FH3%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1045476%22%20slang%3D%22en-US%22%3ERe%3A%20ASC%20Regulatory%20Compliance%20policy%20definition%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1045476%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F427984%22%20target%3D%22_blank%22%3E%40AdamKolak-6034%3C%2FA%3E%20-%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI'm%20not%20entirely%20understanding%20what%20you're%20looking%20for%2C%20but%20I%20can%20give%20you%20a%20few%20pointers%20for%20more%20information.%3C%2FP%3E%0A%3CP%3ETake%20a%20look%20here%20for%20mapping%20information%20of%20compliance%20requirements%20to%20assessments%2F%20Azure%20policies%20that%20help%20address%20those%20requirements%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fgovernance%2Fblueprints%2Fsamples%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fgovernance%2Fblueprints%2Fsamples%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3ESpecifically%20for%20ISO%2027001%20control%20mapping%20for%20example%2C%20see%20this%20section%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fgovernance%2Fblueprints%2Fsamples%2Fiso27001%2Fcontrol-mapping%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fgovernance%2Fblueprints%2Fsamples%2Fiso27001%2Fcontrol-mapping%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20learn%20more%20about%20what%20the%20assessments%20in%20Security%20Center%20are%20doing%2C%20you%20can%20take%20a%20look%20at%20the%20documenation%20on%20Security%20Center%20recommendations%3A%20%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-recommendations%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-recommendations%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThere%20are%20reference%20pages%20in%20that%20section%20for%20each%20of%20the%20ASC%20recommendation%20types.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlso%2C%20specifically%20for%20the%20recommendation%20you%20were%20interested%20in%20below%20on%20installing%20endpoint%20protection%2C%20please%20take%20a%20look%20at%20the%20following%20article%3A%20%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-endpoint-protection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-endpoint-protection%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20that%20helps!%3C%2FP%3E%0A%3CP%3EThanks%3C%2FP%3E%0A%3CP%3E--Ronit.%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditorclipboard_image_0%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello,

can anyone give me an advice, where I can get information about technical description what really does Regulatory Compliance policy definition? (I do mean what do they really check in which scope - subscription I suppose etc.).

I was not able to find policy description e.g. for ISO27001 in documentation and FAQ.

Thx anyone for reply where to get right information.

Adam

3 Replies

@AdamKolak-6034 they're at the subscription level or higher.

 

This page describes the dynamic compliance packages (preview) feature, and talks of assigning compliance packages to subscriptions or management groups:

https://docs.microsoft.com/azure/security-center/update-regulatory-compliance-packages

 

Hope that helps.

@melvynadam  sorry, but your answer has not reach my goal.

E.G. look at ISO27001, it is composed from a lot of policies. Where I get information what exactelly does policies connected with this Initiative assigments? ... I know that such ACS default policy assigment is scoped and enabled at the subscription level.

But my point is where I got Policy definition for particular parts of this defaul ACS policy assigment.

E.G.

"A12.2.1. Controls against malware"
and its one of assessments:
"Install endpoint protection solution on virtual machines"
Where I can find such description/mapping what this assessment really technically does? (mostly probably, it checks VMs in particular subscription ... maybee windows, maybee linux ... etc.)
Hope I cleared what I seek for.
BR
Adam

 

best response confirmed by AdamKolak-6034 (Occasional Contributor)
Solution

Hi @AdamKolak-6034

I'm not entirely understanding what you're looking for, but I can give you a few pointers for more information.

Take a look here for mapping information of compliance requirements to assessments/ Azure policies that help address those requirements: https://docs.microsoft.com/azure/governance/blueprints/samples/

Specifically for ISO 27001 control mapping for example, see this section: https://docs.microsoft.com/azure/governance/blueprints/samples/iso27001/control-mapping

 

To learn more about what the assessments in Security Center are doing, you can take a look at the documenation on Security Center recommendations:  https://docs.microsoft.com/en-us/azure/security-center/security-center-recommendations

There are reference pages in that section for each of the ASC recommendation types.

 

Also, specifically for the recommendation you were interested in below on installing endpoint protection, please take a look at the following article:  https://docs.microsoft.com/en-us/azure/security-center/security-center-endpoint-protection

 

Hope that helps!

Thanks

--Ronit.