EvidenceSheet

Azure Security Benchmark: the evidence behind every control

85 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

Asset Management

AM-1Track asset inventory and their risks hardAM-2Use only approved services hardAM-3Ensure security of asset lifecycle management hardAM-4Limit access to asset management moderateAM-5Use only approved applications in virtual machine moderate

Backup and Recovery

BR-1Ensure regular automated backups hardBR-2Protect backup and recovery data easyBR-3Monitor backups hardBR-4Regularly test backup moderate

Data Protection

DP-1Discover, classify, and label sensitive data moderateDP-2Monitor anomalies and threats targeting sensitive data easyDP-3Encrypt sensitive data in transit moderateDP-4Enable data at rest encryption by default moderateDP-5Use customer-managed key option in data at rest encryption when required moderateDP-6Use a secure key management process hardDP-7Use a secure certificate management process moderateDP-8Ensure security of key and certificate repository moderate

DevOps Security

DS-1Conduct threat modeling moderateDS-2Ensure software supply chain security moderateDS-3Secure DevOps infrastructure easyDS-4Integrate static application security testing into DevOps pipeline moderateDS-5Integrate dynamic application security testing into DevOps pipeline moderateDS-6Enforce security of workload throughout DevOps lifecycle easyDS-7Enable logging and monitoring in DevOps easy

Endpoint Security

ES-1Use Endpoint Detection and Response (EDR) moderateES-2Use modern anti-malware software moderateES-3Ensure anti-malware software and signatures are updated hard

Governance and Strategy

GS-1Align organization roles, responsibilities and accountabilities hardGS-2Define and implement enterprise segmentation/separation of duties strategy hardGS-3Define and implement data protection strategy hardGS-4Define and implement network security strategy hardGS-5Define and implement security posture management strategy hardGS-6Define and implement identity and privileged access strategy moderateGS-7Define and implement logging, threat detection and incident response strategy easyGS-8Define and implement backup and recovery strategy hardGS-9Define and implement endpoint security strategy moderateGS-10Define and implement DevOps security strategy hard

Identity Management

IM-1Use centralized identity and authentication system moderateIM-2Protect identity and authentication systems hardIM-3Manage application identities securely and automatically easyIM-4Authenticate server and services moderateIM-5Use single sign-on (SSO) for application access hardIM-6Use strong authentication controls easyIM-7Restrict resource access based on conditions hardIM-8Restrict the exposure of credential and secrets moderateIM-9Secure user access to existing applications moderate

Incident Response

IR-1Preparation - update incident response plan and handling process hardIR-2Preparation - setup incident notification hardIR-3Detection and analysis - create incidents based on high-quality alerts easyIR-4Detection and analysis - investigate an incident moderateIR-5Detection and analysis - prioritize incidents moderateIR-6Containment, eradication and recovery - automate the incident handling moderateIR-7Post-incident activity - conduct lesson learned and retain evidence hard

Logging and Threat Detection

LT-1Enable threat detection capabilities moderateLT-2Enable threat detection for identity and access management easyLT-3Enable logging for security investigation easyLT-4Enable network logging for security investigation easyLT-5Centralize security log management and analysis easyLT-6Configure log storage retention easyLT-7Use approved time synchronization sources easy

Network Security

NS-1Establish network segmentation boundaries moderateNS-2Secure cloud services with network controls easyNS-3Deploy firewall at the edge of enterprise network easyNS-4Deploy intrusion detection/intrusion prevention systems (IDS/IPS) easyNS-5Deploy DDOS protection moderateNS-6Deploy web application firewall moderateNS-7Simplify network security configuration hardNS-8Detect and disable insecure services and protocols easyNS-9Connect on-premises or cloud network privately easyNS-10Ensure Domain Name System (DNS) security easy

Privileged Access

PA-1Separate and limit highly privileged/administrative users hardPA-2Avoid standing access for user accounts and permissions easyPA-3Manage lifecycle of identities and entitlements easyPA-4Review and reconcile user access regularly hardPA-5Set up emergency access hardPA-6Use privileged access workstations hardPA-7Follow just enough administration (least privilege) principle hardPA-8Determine access process for cloud provider support easy

Posture and Vulnerability Management

PV-1Define and establish secure configurations hardPV-2Audit and enforce secure configurations easyPV-3Define and establish secure configurations for compute resources moderatePV-4Audit and enforce secure configurations for compute resources easyPV-5Perform vulnerability assessments hardPV-6Rapidly and automatically remediate vulnerabilities easyPV-7Conduct regular red team operations hard