Tech Hub

@ Solution Architecture Works

Secure Azure services and workloads with Microsoft Defender for Cloud regulatory compliance controls

Regulatory compliance standards in Defender for Cloud

Estimated reading: 4 minutes 106 views

Microsoft Defender for Cloud simplifies the regulatory compliance process by helping you identify issues that prevent you from meeting a particular compliance standard or obtaining a compliance certification.

Industry standards, regulatory standards, and benchmarks are represented in Defender for Cloud as security standards, and appear in the regulatory compliance dashboard.

Compliance controls


Each security standard is composed of several compliance controls, which are logical groups of associated security recommendations.

Defender for Cloud continuously evaluates the relevant environment against all compliance controls that can be automatically assessed. Based on these evaluations, it indicates whether resources are compliant or non-compliant with the controls.

Note


If standards include compliance controls that cannot be automatically assessed, Defender for Cloud is unable to determine whether a resource is compliant with the control. In this case, the control appears in gray.

Viewing compliance standards


The regulatory compliance dashboard offers an interactive overview of the compliance status.

In the dashboard, you can:

  • Get a summary of the controls from the standards that have been validated.
  • Get a summary of the standards with the lowest success rate for resources.
  • Review the standards applied to the selected scope.
  • Review the compliance control assessments for each applied standard.
  • Obtain a summary report for a specific standard.
  • Manage compliance policies to see the standards assigned to a specific scope.
  • Run a query to create a custom compliance report.
  • Create a “compliance over time workbook” to track compliance status over time.
  • Download audit reports.
  • Review compliance offerings for Microsoft and third‑party audits.

Details of compliance standards

For each compliance standard, you can view:

  • The scope of the standard.
  • Each standard broken down into control groups and sub‑controls.

When you apply a standard to a scope, you can see a summary of the compliance assessment for the resources in that scope, for each control in the standard.

The assessment status reflects compliance with the standard. There are three states:

  • A green circle indicates that the resources in the scope are compliant with the control.
  • A red circle indicates that the resources are not compliant with the control.
  • Controls that are not available cannot be automatically assessed; therefore, Defender for Cloud cannot determine whether the resources are compliant.

You can drill into the controls to obtain information about the resources that passed or failed the assessments, as well as remediation steps.

Default compliance standards

By default, when you enable Defender for Cloud, the following standards are enabled:

  • For Azure: Microsoft Cloud Security Benchmark (MCSB).
  • For AWS: Microsoft Cloud Security Benchmark (MCSB) and the AWS Foundational Security Best Practices standard.
  • For GCP: Microsoft Cloud Security Benchmark (MCSB) and GCP Default.

Available compliance standards

The following standards are available in Defender for Cloud:

Standards for Azure subscriptionsStandards for AWS accountsStandards for GCP projects
Australian Government ISM Protected StandardAWS Foundational Security Best PracticesBrazilian General Data Protection Law (LGPD)
Canada Federal PBMMAWS Well‑Architected FrameworkCalifornia Consumer Privacy Act (CCPA)
CIS Azure FoundationsBrazilian General Data Protection Law (LGPD)CIS Controls
CMMCCalifornia Consumer Privacy Act (CCPA)CIS GCP Foundations
FedRAMP “H” & “M”CIS AWS FoundationsCIS Google Cloud Platform Foundation Benchmark
HIPAA/HITRUSTCRI ProfileCIS Google Kubernetes Engine (GKE) Benchmark
ISO/IEC 27001Cloud Security Alliance Cloud Controls Matrix (CCM)CRI Profile
New Zealand ISM RestrictedCloud Security Alliance Cloud Controls Matrix (CCM)
NIST SP 800‑171ISO/IEC 27001Cybersecurity Maturity Model Certification (CMMC)
NIST SP 800‑53ISO/IEC 27002FFIEC Cybersecurity Assessment Tool (CAT)
PCI DSSNIST Cybersecurity Framework (CSF)
RMIT MalaysiaNIST SP 800‑172ISO/IEC 27001
SOC 2PCI DSSISO/IEC 27002
SWIFT CSP CSCFISO/IEC 27017
UK OFFICIAL and UK NHSNIST Cybersecurity Framework (CSF)
Digital Operations Resilience Act (DORA)NIST SP 800‑53
European Union AI Act (EU AI Act)NIST SP 800‑171
Korea Public Cloud Information System (k‑ISMS‑P)NIST SP 800‑172
CIS Azure Foundation Benchmark v3.0PCI DSS
Sarbanes‑Oxley Act (SOX)
SOC 2

Next unit: Microsoft Cloud Security Benchmark in Defender for Cloud

Share this Doc

Regulatory compliance standards in Defender for Cloud

Or copy link

CONTENTS