Analyze/catalog/frameworks/mcsb.json
|
{
"key": "MCSB", "order": 1, "name": "Microsoft cloud security benchmark", "shortName": "MCSB v2", "version": "v2 (preview)", "publisher": "Microsoft", "type": "benchmark", "url": "https://learn.microsoft.com/security/benchmark/azure/overview", "retrieved": "2026-09-20", "mapping": "native", "note": "Each test implements Azure guidance of the MCSB controls it is mapped to. MCSB controls also cover processes and features AzCmply does not test, so every control is partly assessed.", "controls": { "AI-1": {"title":"Ensure use of approved models","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-1","applicability":"manual"}, "AI-2": {"title":"Implement multi-layered content filtering","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-2","coverage":"partial","tests":["AZ-AI-004"]}, "AI-3": {"title":"Adopt safety meta-prompts","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-3","coverage":"partial","tests":["AZ-AI-004"]}, "AI-4": {"title":"Apply least privilege for agent functions","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-4","coverage":"partial","tests":["AZ-AI-003"]}, "AI-5": {"title":"Ensure human-in-the-loop","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-5","applicability":"manual"}, "AI-6": {"title":"Establish monitoring and detection","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-6","coverage":"partial","tests":["AZ-DEF-013"]}, "AI-7": {"title":"Perform continuous AI Red Teaming","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-artificial-intelligence-security#ai-7","applicability":"manual"}, "AM-1": {"title":"Track asset inventory and their risks","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-asset-management#am-1","applicability":"manual"}, "AM-2": {"title":"Use only approved services","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-asset-management#am-2","coverage":"partial","tests":["AZ-APIM-007","AZ-GOV-008"]}, "AM-3": {"title":"Ensure security of asset lifecycle management","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-asset-management#am-3","coverage":"partial","tests":["AZ-GOV-004","AZ-GOV-006","AZ-GOV-007","AZ-LOGIC-007","AZ-LOGIC-008","AZ-LOGIC-010","AZ-STG-025","AZ-STG-026"]}, "AM-4": {"title":"Limit access to asset management","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-asset-management#am-4","applicability":"manual"}, "AM-5": {"title":"Use only approved applications in virtual machine","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-asset-management#am-5","applicability":"manual"}, "BR-1": {"title":"Ensure regular automated backups","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-backup-recovery#br-1","coverage":"partial","tests":["AZ-BCK-004","AZ-BCK-007","AZ-BCK-008","AZ-BCK-009","AZ-STG-014","AZ-STG-015","AZ-STG-016","AZ-STG-017","AZ-STG-022","AZ-VM-010"]}, "BR-2": {"title":"Protect backup and recovery data","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-backup-recovery#br-2","coverage":"partial","tests":["AZ-BCK-001","AZ-BCK-002","AZ-BCK-003","AZ-BCK-005","AZ-GOV-004","AZ-KV-001","AZ-STG-025","AZ-STG-026"]}, "BR-3": {"title":"Monitor backups","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-backup-recovery#br-3","coverage":"partial","tests":["AZ-BCK-006"]}, "BR-4": {"title":"Regularly test backup","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-backup-recovery#br-4","coverage":"partial","tests":["AZ-BCK-010"]}, "DP-1": {"title":"Discover, classify, and label sensitive data","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-1","coverage":"partial","tests":["AZ-DEF-024"]}, "DP-2": {"title":"Monitor anomalies and threats targeting sensitive data","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-2","coverage":"partial","tests":["AZ-ACR-002","AZ-AI-003","AZ-AI-006","AZ-BCK-005","AZ-DEF-004","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-025","AZ-STG-004","AZ-STG-010","AZ-SYN-001","AZ-VM-011","AZ-VM-012"]}, "DP-3": {"title":"Encrypt sensitive data in transit","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-3","coverage":"partial","tests":["AZ-APIM-002","AZ-APIM-005","AZ-APIM-006","AZ-APP-001","AZ-APP-002","AZ-APP-003","AZ-BOT-003","AZ-CAPP-001","AZ-MY-001","AZ-NET-013","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-006","AZ-STG-001","AZ-STG-002","AZ-STG-018","AZ-STG-019"]}, "DP-4": {"title":"Enable data at rest encryption by default","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-4","coverage":"partial","tests":["AZ-ADX-002","AZ-ADX-003","AZ-AUTO-001","AZ-SQL-007","AZ-STG-014","AZ-STG-015","AZ-STG-017","AZ-STG-020","AZ-VM-001","AZ-VM-002"]}, "DP-5": {"title":"Use customer-managed key option in data at rest encryption when required","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-5","coverage":"partial","tests":["AZ-SQL-008","AZ-STG-021"]}, "DP-6": {"title":"Use a secure key management process","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-6","coverage":"partial","tests":["AZ-ADF-001","AZ-AKS-009","AZ-APIM-003","AZ-KV-005","AZ-KV-006","AZ-KV-007","AZ-KV-010","AZ-KV-011","AZ-STG-012","AZ-STG-013"]}, "DP-7": {"title":"Use a secure certificate management process","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-7","coverage":"partial","tests":["AZ-KV-008"]}, "DP-8": {"title":"Ensure security of key and certificate repository","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-data-protection#dp-8","coverage":"partial","tests":["AZ-DEF-010","AZ-KV-001","AZ-KV-002","AZ-KV-003","AZ-KV-004","AZ-KV-009","AZ-LOG-014"]}, "DS-1": {"title":"Conduct threat modeling","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-1","applicability":"manual"}, "DS-2": {"title":"Secure the software supply chain","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-2","applicability":"manual"}, "DS-3": {"title":"Secure the DevOps infrastructure","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-3","applicability":"manual"}, "DS-4": {"title":"Integrate Static Application Security Testing (SAST)","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-4","applicability":"manual"}, "DS-5": {"title":"Integrate Dynamic Application Security Testing (DAST)","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-5","applicability":"manual"}, "DS-6": {"title":"Secure the workload lifecycle","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-6","coverage":"partial","tests":["AZ-ADF-002","AZ-SEC-001","AZ-SEC-002"]}, "DS-7": {"title":"Implement DevOps logging and monitoring","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-devops-security#ds-7","applicability":"manual"}, "ES-1": {"title":"Use Endpoint Detection and Response (EDR)","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-endpoint-security#es-1","coverage":"partial","tests":["AZ-DEF-002","AZ-DEF-014","AZ-VM-006"]}, "ES-2": {"title":"Use modern anti-malware software","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-endpoint-security#es-2","coverage":"partial","tests":["AZ-DEF-014","AZ-DEF-025","AZ-DFA-001","AZ-VM-006"]}, "ES-3": {"title":"Ensure anti-malware software and signatures are updated","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-endpoint-security#es-3","coverage":"partial","tests":["AZ-DFA-001"]}, "IM-1": {"title":"Centralize identity and authentication while ensuring isolation","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-1","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-002","AZ-ACR-004","AZ-ACR-005","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-APIM-001","AZ-APP-004","AZ-BOT-002","AZ-COS-001","AZ-IAM-018","AZ-MY-003","AZ-NET-021","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SQL-003","AZ-SQL-004","AZ-STG-005","AZ-STG-011"]}, "IM-2": {"title":"Protect identity and authentication systems","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-2","applicability":"manual"}, "IM-3": {"title":"Manage application identities securely and automatically","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-3","coverage":"partial","tests":["AZ-ACR-001","AZ-AI-001","AZ-AKS-008","AZ-APP-004","AZ-APP-006","AZ-AUTO-002","AZ-COS-001","AZ-IAM-003","AZ-IAM-013","AZ-IAM-014","AZ-IAM-022","AZ-LOGIC-003","AZ-LOGIC-005","AZ-LOGIC-006","AZ-MY-003","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SQL-004","AZ-STG-005","AZ-STG-023"]}, "IM-4": {"title":"Authenticate server and services","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-4","coverage":"partial","tests":["AZ-APIM-005"]}, "IM-5": {"title":"Use single sign-on (SSO) for application access","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-5","coverage":"partial","tests":["AZ-APP-009"]}, "IM-6": {"title":"Use strong authentication controls","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-6","coverage":"partial","tests":["AZ-IAM-024","AZ-IAM-026","AZ-IAM-027","AZ-NET-021","AZ-STG-023","AZ-VM-004"]}, "IM-7": {"title":"Restrict resource access based on conditions","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-7","coverage":"partial","tests":["AZ-APP-009","AZ-IAM-024","AZ-IAM-029","AZ-IAM-030","AZ-LOGIC-001","AZ-STG-003"]}, "IM-8": {"title":"Restrict the exposure of credentials and secrets","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-identity-management#im-8","coverage":"partial","tests":["AZ-ACR-005","AZ-ADF-001","AZ-APIM-003","AZ-AUTO-001","AZ-AUTO-002","AZ-IAM-013","AZ-IAM-014","AZ-IAM-022","AZ-LOGIC-003","AZ-LOGIC-004","AZ-LOGIC-005","AZ-LOGIC-006","AZ-MSG-001","AZ-SEC-001","AZ-SEC-002","AZ-SEC-003","AZ-SEC-004","AZ-STG-024"]}, "IR-1": {"title":"Preparation - update incident response plan and handling process","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-1","applicability":"manual"}, "IR-2": {"title":"Preparation - setup incident notification","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-2","coverage":"partial","tests":["AZ-DEF-018","AZ-DEF-019","AZ-DEF-020","AZ-DEF-021","AZ-DEF-023","AZ-LOG-013"]}, "IR-3": {"title":"Detection and analysis - create incidents based on high-quality alerts","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-3","coverage":"partial","tests":["AZ-DEF-022"]}, "IR-4": {"title":"Detection and analysis - investigate an incident","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-4","coverage":"partial","tests":["AZ-DEF-022","AZ-LOG-017"]}, "IR-5": {"title":"Detection and analysis - prioritize incidents","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-5","applicability":"manual"}, "IR-6": {"title":"Containment, eradication and recovery - automate the incident handling","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-6","applicability":"manual"}, "IR-7": {"title":"Post-incident activity - conduct lessons learned and retain evidence","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-incident-response#ir-7","applicability":"manual"}, "LT-1": {"title":"Enable threat detection capabilities","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-1","coverage":"partial","tests":["AZ-DEF-001","AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-016"]}, "LT-2": {"title":"Enable threat detection for identity and access management","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-2","coverage":"partial","tests":["AZ-DEF-011"]}, "LT-3": {"title":"Enable logging for security investigation","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-3","coverage":"partial","tests":["AZ-DBX-005","AZ-LOG-001","AZ-LOG-002","AZ-LOG-003","AZ-LOG-004","AZ-LOG-005","AZ-LOG-006","AZ-LOG-007","AZ-LOG-008","AZ-LOG-009","AZ-LOG-010","AZ-LOG-011","AZ-LOG-012","AZ-LOG-014","AZ-LOG-015","AZ-LOG-021","AZ-LOG-025","AZ-MY-002","AZ-PG-002","AZ-PG-003","AZ-SQL-001","AZ-VM-008","AZ-VM-009"]}, "LT-4": {"title":"Enable network logging for security investigation","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-4","coverage":"partial","tests":["AZ-LOG-017","AZ-LOG-018","AZ-LOG-020","AZ-LOG-023","AZ-NET-024","AZ-NET-025"]}, "LT-5": {"title":"Centralize security log management and analysis","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-5","coverage":"partial","tests":["AZ-DEF-023","AZ-LOG-001","AZ-LOG-020","AZ-LOG-023","AZ-VM-008"]}, "LT-6": {"title":"Configure log storage retention","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-6","coverage":"partial","tests":["AZ-LOG-016","AZ-LOG-019","AZ-LOG-022","AZ-LOG-024","AZ-SQL-002"]}, "LT-7": {"title":"Use approved time synchronization sources","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-logging-threat-detection#lt-7","applicability":"manual"}, "NS-1": {"title":"Establish network segmentation boundaries","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-1","coverage":"partial","tests":["AZ-AKS-007","AZ-DBX-001","AZ-DBX-006","AZ-GOV-007","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-006","AZ-NET-007","AZ-NET-008","AZ-NET-011","AZ-NET-023"]}, "NS-2": {"title":"Secure cloud native services with network controls","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-2","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-003","AZ-ADX-001","AZ-AI-002","AZ-AI-005","AZ-AI-006","AZ-AI-007","AZ-AKS-003","AZ-APP-008","AZ-AVD-001","AZ-BOT-001","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-DBX-001","AZ-DBX-002","AZ-DBX-003","AZ-DBX-004","AZ-KV-003","AZ-KV-004","AZ-NET-008","AZ-PAAS-001","AZ-SQL-005","AZ-STG-003","AZ-STG-004","AZ-STG-006","AZ-STG-007","AZ-STG-008","AZ-STG-009","AZ-SYN-001","AZ-VM-011","AZ-VM-012"]}, "NS-3": {"title":"Deploy firewall at the edge of enterprise network","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-3","coverage":"partial","tests":["AZ-NET-001","AZ-NET-002","AZ-NET-007","AZ-NET-009","AZ-NET-019"]}, "NS-4": {"title":"Deploy intrusion detection/intrusion prevention systems (IDS/IPS)","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-4","coverage":"partial","tests":["AZ-NET-020"]}, "NS-5": {"title":"Deploy DDoS protection","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-5","coverage":"partial","tests":["AZ-NET-010"]}, "NS-6": {"title":"Deploy web application firewall","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-6","coverage":"partial","tests":["AZ-NET-004","AZ-NET-012","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018"]}, "NS-7": {"title":"Manage network security centrally and effectively","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-7","applicability":"manual"}, "NS-8": {"title":"Detect and disable insecure services and protocols","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-8","coverage":"partial","tests":["AZ-APIM-006","AZ-APP-002","AZ-APP-003","AZ-APP-005","AZ-NET-003","AZ-NET-005","AZ-NET-013","AZ-NET-014","AZ-PAAS-003","AZ-STG-018"]}, "NS-9": {"title":"Connect on-premises or cloud network privately","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-9","applicability":"manual"}, "NS-10": {"title":"Ensure Domain Name System (DNS) security","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-network-security#ns-10","coverage":"partial","tests":["AZ-NET-022"]}, "PA-1": {"title":"Separate and limit highly privileged/administrative users","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-1","coverage":"partial","tests":["AZ-BCK-003","AZ-IAM-001","AZ-IAM-004","AZ-IAM-009","AZ-IAM-015","AZ-IAM-016","AZ-IAM-017","AZ-IAM-018","AZ-IAM-019"]}, "PA-2": {"title":"Avoid standing access for user accounts and permissions","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-2","coverage":"partial","tests":["AZ-IAM-002","AZ-IAM-011","AZ-IAM-012"]}, "PA-3": {"title":"Manage lifecycle of identities and entitlements","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-3","coverage":"partial","tests":["AZ-IAM-006","AZ-IAM-007","AZ-IAM-020"]}, "PA-4": {"title":"Review and reconcile user access regularly","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-4","coverage":"partial","tests":["AZ-IAM-004","AZ-IAM-005","AZ-IAM-006","AZ-IAM-007","AZ-IAM-020","AZ-IAM-023","AZ-IAM-025"]}, "PA-5": {"title":"Set up emergency access","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-5","coverage":"partial","tests":["AZ-IAM-028"]}, "PA-6": {"title":"Use privileged access solution","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-6","coverage":"partial","tests":["AZ-IAM-011","AZ-IAM-030","AZ-NET-011","AZ-NET-023"]}, "PA-7": {"title":"Follow just enough administration (least privilege) principle","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-7","coverage":"partial","tests":["AZ-AKS-002","AZ-AKS-005","AZ-APIM-004","AZ-COS-003","AZ-GOV-005","AZ-IAM-003","AZ-IAM-008","AZ-IAM-009","AZ-IAM-010","AZ-IAM-015","AZ-IAM-016","AZ-IAM-019","AZ-IAM-021","AZ-IAM-023","AZ-KV-002","AZ-KV-009","AZ-MSG-001"]}, "PA-8": {"title":"Determine access process for cloud provider support","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-privileged-access#pa-8","coverage":"partial","tests":["AZ-IAM-021"]}, "PV-1": {"title":"Define and establish secure configurations","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-1","coverage":"partial","tests":["AZ-GOV-001","AZ-GOV-009"]}, "PV-2": {"title":"Audit and enforce secure configurations","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-2","coverage":"partial","tests":["AZ-ADF-002","AZ-AKS-004","AZ-APIM-001","AZ-APIM-007","AZ-APP-005","AZ-APP-007","AZ-GOV-001","AZ-GOV-002","AZ-GOV-003","AZ-GOV-009","AZ-GOV-010","AZ-STG-010"]}, "PV-3": {"title":"Define and establish secure configurations for compute resources","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-3","coverage":"partial","tests":["AZ-DFA-004","AZ-VM-001","AZ-VM-003","AZ-VM-007"]}, "PV-4": {"title":"Audit and enforce secure configurations for compute resources","criticality":"Must have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-4","coverage":"partial","tests":["AZ-AKS-004","AZ-DEF-016","AZ-DFA-004","AZ-VM-003","AZ-VM-007"]}, "PV-5": {"title":"Perform vulnerability assessments","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-5","coverage":"partial","tests":["AZ-DEF-001","AZ-DEF-015","AZ-DEF-017","AZ-DFA-003","AZ-GOV-010","AZ-SQL-009","AZ-VM-005"]}, "PV-6": {"title":"Rapidly and automatically remediate vulnerabilities","criticality":"Should have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-6","coverage":"partial","tests":["AZ-AKS-006","AZ-DFA-002","AZ-DFA-003","AZ-GOV-008","AZ-VM-005","AZ-VM-009"]}, "PV-7": {"title":"Conduct regular red team operations","criticality":"Nice to have","url":"https://learn.microsoft.com/security/benchmark/azure/mcsb-v2-posture-vulnerability-management#pv-7","applicability":"manual"} } } |