Azure Security Benchmark: the evidence behind every control
85 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
Asset Management
AM-1Track asset inventory and their risks hardAM-2Use only approved services hardAM-3Ensure security of asset lifecycle management hardAM-4Limit access to asset management moderateAM-5Use only approved applications in virtual machine moderateBackup and Recovery
BR-1Ensure regular automated backups hardBR-2Protect backup and recovery data easyBR-3Monitor backups hardBR-4Regularly test backup moderateData Protection
DP-1Discover, classify, and label sensitive data moderateDP-2Monitor anomalies and threats targeting sensitive data easyDP-3Encrypt sensitive data in transit moderateDP-4Enable data at rest encryption by default moderateDP-5Use customer-managed key option in data at rest encryption when required moderateDP-6Use a secure key management process hardDP-7Use a secure certificate management process moderateDP-8Ensure security of key and certificate repository moderateDevOps Security
DS-1Conduct threat modeling moderateDS-2Ensure software supply chain security moderateDS-3Secure DevOps infrastructure easyDS-4Integrate static application security testing into DevOps pipeline moderateDS-5Integrate dynamic application security testing into DevOps pipeline moderateDS-6Enforce security of workload throughout DevOps lifecycle easyDS-7Enable logging and monitoring in DevOps easyEndpoint Security
ES-1Use Endpoint Detection and Response (EDR) moderateES-2Use modern anti-malware software moderateES-3Ensure anti-malware software and signatures are updated hardGovernance and Strategy
GS-1Align organization roles, responsibilities and accountabilities hardGS-2Define and implement enterprise segmentation/separation of duties strategy hardGS-3Define and implement data protection strategy hardGS-4Define and implement network security strategy hardGS-5Define and implement security posture management strategy hardGS-6Define and implement identity and privileged access strategy moderateGS-7Define and implement logging, threat detection and incident response strategy easyGS-8Define and implement backup and recovery strategy hardGS-9Define and implement endpoint security strategy moderateGS-10Define and implement DevOps security strategy hardIdentity Management
IM-1Use centralized identity and authentication system moderateIM-2Protect identity and authentication systems hardIM-3Manage application identities securely and automatically easyIM-4Authenticate server and services moderateIM-5Use single sign-on (SSO) for application access hardIM-6Use strong authentication controls easyIM-7Restrict resource access based on conditions hardIM-8Restrict the exposure of credential and secrets moderateIM-9Secure user access to existing applications moderateIncident Response
IR-1Preparation - update incident response plan and handling process hardIR-2Preparation - setup incident notification hardIR-3Detection and analysis - create incidents based on high-quality alerts easyIR-4Detection and analysis - investigate an incident moderateIR-5Detection and analysis - prioritize incidents moderateIR-6Containment, eradication and recovery - automate the incident handling moderateIR-7Post-incident activity - conduct lesson learned and retain evidence hardLogging and Threat Detection
LT-1Enable threat detection capabilities moderateLT-2Enable threat detection for identity and access management easyLT-3Enable logging for security investigation easyLT-4Enable network logging for security investigation easyLT-5Centralize security log management and analysis easyLT-6Configure log storage retention easyLT-7Use approved time synchronization sources easyNetwork Security
NS-1Establish network segmentation boundaries moderateNS-2Secure cloud services with network controls easyNS-3Deploy firewall at the edge of enterprise network easyNS-4Deploy intrusion detection/intrusion prevention systems (IDS/IPS) easyNS-5Deploy DDOS protection moderateNS-6Deploy web application firewall moderateNS-7Simplify network security configuration hardNS-8Detect and disable insecure services and protocols easyNS-9Connect on-premises or cloud network privately easyNS-10Ensure Domain Name System (DNS) security easyPrivileged Access
PA-1Separate and limit highly privileged/administrative users hardPA-2Avoid standing access for user accounts and permissions easyPA-3Manage lifecycle of identities and entitlements easyPA-4Review and reconcile user access regularly hardPA-5Set up emergency access hardPA-6Use privileged access workstations hardPA-7Follow just enough administration (least privilege) principle hardPA-8Determine access process for cloud provider support easyPosture and Vulnerability Management
PV-1Define and establish secure configurations hardPV-2Audit and enforce secure configurations easyPV-3Define and establish secure configurations for compute resources moderatePV-4Audit and enforce secure configurations for compute resources easyPV-5Perform vulnerability assessments hardPV-6Rapidly and automatically remediate vulnerabilities easyPV-7Conduct regular red team operations hard