Compliance, Mapped to Your Cloud
Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

CIS Azure Foundations v4.0.0
The Center for Internet Security (CIS) Benchmarks are consensus-based, prescriptive configuration baselines for hardening cloud environments against the most common attack vectors.
Controls assessed
Azure Files offers soft delete for file shares, allowing you to easily recover your data when it is mistakenly deleted by an application or another storage account user.
Ensure that SMB file shares are configured to use the latest supported SMB protocol version.
Implement SMB channel encryption with AES-256-GCM for SMB file shares to ensure data confidentiality and integrity in transit.
Blobs in Azure storage accounts may contain sensitive or personal data, such as ePHI or financial information.
Enabling blob versioning allows for the automatic retention of previous versions of objects.
Access Keys authenticate application access requests to data contained in Storage Accounts.
Every secure request to an Azure Storage account must be authorized.
Use private endpoints for your Azure Storage accounts to allow clients and services to securely access data located over a network via an encrypted Private Link.
Disallowing public network access for a storage account overrides the public access settings for individual containers in that storage account for Azure Resource Manager Deployment Model storage accounts.
Restricting default network access helps to provide a new layer of security, since storage accounts accept connections from clients on any network.
When this property is enabled, the Azure portal authorizes requests to blobs, files, queues, and tables with Microsoft Entra ID by default.
Enable data encryption in transit.
This recommendation assumes that the `Public network access` parameter is set to `Enabled from selected virtual networks and IP addresses`.
In some cases, Azure Storage sets the minimum TLS version to be version 1.
Cross Tenant Replication in Azure allows data to be replicated across multiple Azure tenants.
The Azure Storage setting 'Allow Blob Anonymous Access' (aka \
Geo-redundant storage (GRS) in Azure replicates data three times within the primary region using locally redundant storage (LRS) and asynchronously copies it to a secondary region hundreds of miles away.
Networking for Azure Databricks can be set up in a few different ways.
Network Security Groups (NSGs) should be implemented to control inbound and outbound traffic to Azure Databricks subnets, ensuring only authorized communication.
Azure Databricks Diagnostic Logging provides insights into system operations, user activities, and security events within a Databricks workspace.
Azure Databricks encrypts data in transit using TLS 1.
Microsoft Entra ID Conditional Access allows an organization to configure `Named locations` and configure whether those locations are trusted or untrusted.
This recommendation ensures that users accessing the Windows Azure Service Management API (i.e. Azure Powershell, Azure CLI, Azure Resource Manager API, etc.) are required to use multifactor authentication (MFA) credentials when accessing resources through the Windows Azure Service Management API.
Microsoft Entra ID has native and extended identity functionality allowing you to invite people from outside your organization to be guest users in your cloud account and sign in with their own work, school, or social identities.
The User Access Administrator role grants the ability to view all resources and manage access assignments at any subscription or management group level within the tenant.
Require administrators or appropriately delegated users to register third-party applications.
Restrict security group creation to administrators only.
The principle of least privilege should be followed and only necessary privileges should be assigned instead of allowing full administrative access.
This recommendation aims to maintain a balance between security and operational efficiency by ensuring that a minimum of 2 and a maximum of 4 users are assigned the Global Administrator role in Microsoft Entra ID.
The diagnostic setting should be configured to log the appropriate activities from the control/management plane.
Storage accounts with the activity log exports can be configured to use Customer Managed Keys (CMK).
Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available.
Ensure that network flow logs are captured and fed into a central log analytics workspace.
Enable AppServiceHTTPLogs diagnostic log category for Azure App Service instances to ensure all http requests are captured and centrally logged.
Ensure that virtual network flow logs are captured and fed into a central log analytics workspace.
Create an activity log alert for the Create Policy Assignment event.
Create an activity log alert for the Delete Policy Assignment event.
Create an Activity Log Alert for the Create or Update Network Security Group event.
Create an activity log alert for the Delete Network Security Group event.
Create an activity log alert for the Create or Update Security Solution event.
Create an activity log alert for the Delete Security Solution event.
Create an activity log alert for the Create or Update SQL Server Firewall Rule event.
Create an activity log alert for the \
Create an activity log alert for the Create or Update Public IP Addresses rule.
Create an activity log alert for the Delete Public IP Address rule.
Network security groups should be periodically evaluated for port misconfigurations.
Network security groups should be periodically evaluated for port misconfigurations.
Network security groups should be periodically evaluated for port misconfigurations.
Network security groups should be periodically evaluated for port misconfigurations.
Network Security Group Flow Logs should be enabled and the retention period set to greater than or equal to 90 days.
Enable Network Watcher for physical regions in Azure subscriptions.
The Defender for Servers plan in Microsoft Defender for Cloud reduces security risk by providing actionable recommendations to improve and remediate machine security posture.
The Endpoint protection component enables Microsoft Defender for Endpoint (formerly 'Advanced Threat Protection' or 'ATP' or 'WDATP' - see additional info) to communicate with Microsoft Defender for Cloud.
Microsoft Defender for Containers helps improve, monitor, and maintain the security of containerized assets—including Kubernetes clusters, nodes, workloads, container registries, and images—across multi-cloud and on-premises environments.
Turning on Microsoft Defender for Storage enables threat detection for Storage, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.
Turning on Microsoft Defender for App Service enables threat detection for App Service, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.
Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.
Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.
Turning on Microsoft Defender for Azure SQL Databases enables threat detection for Managed Instance Azure SQL databases, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.
Turning on Microsoft Defender for SQL servers on machines enables threat detection for SQL servers on machines, providing threat intelligence, anomaly detection, and behavior analytics in Microsoft Defender for Cloud.
Turning on Microsoft Defender for Key Vault enables threat detection for Key Vault, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.
Microsoft Defender for Resource Manager scans incoming administrative requests to change your infrastructure from both CLI and the Azure portal.
Enable security alert emails to subscription owners.
Microsoft Defender for Cloud emails the subscription owners whenever a high-severity alert is triggered for their subscription.
Enables emailing security alerts to the subscription owner or other designated security contact.
Microsoft Defender for DNS scans all network traffic exiting from within a subscription.
Ensure that all Keys in Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.
Ensure that all Keys in Non Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.
Ensure that all Secrets in Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.
Ensure that all Secrets in Non Role Based Access Control (RBAC) Azure Key Vaults have an expiration date set.
Key Vaults contain object keys, secrets, and certificates.
The recommended way to access Key Vaults is to use the Azure Role-Based Access Control (RBAC) permissions model.
Private endpoints will secure network traffic from Azure Key Vault to the resources requesting secrets and keys.
Automated cryptographic key rotation in Key Vault allows users to configure Key Vault to automatically generate a new key version at a specified frequency.
The Azure Bastion service allows secure remote access to Azure Virtual Machines over the Internet without exposing remote access protocol ports and services directly to the Internet.
See where you stand against any framework
Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.
