Analyze/catalog/frameworks/waf.json

{
  "key": "WAF",
  "order": 3,
  "name": "Azure Well-Architected Framework, Security pillar",
  "shortName": "WAF security",
  "version": "Design review checklist SE:01 to SE:12",
  "publisher": "Microsoft",
  "type": "framework",
  "url": "https://learn.microsoft.com/azure/well-architected/security/checklist",
  "retrieved": "2026-09-20",
  "mapping": "native",
  "note": "Each test checks Azure configuration that the checklist item recommends. The items also cover design and operations, so every item is partly assessed.",
  "controls": {
    "SE:01": {"title":"Establish a security baseline aligned to compliance requirements, industry standards and platform recommendations","url":"https://learn.microsoft.com/azure/well-architected/security/establish-baseline","coverage":"partial","tests":["AZ-GOV-001","AZ-GOV-003","AZ-GOV-009","AZ-GOV-010"]},
    "SE:02": {"title":"Maintain a secure development lifecycle","url":"https://learn.microsoft.com/azure/well-architected/security/secure-development-lifecycle","applicability":"manual"},
    "SE:03": {"title":"Classify and consistently apply sensitivity labels on all workload data and systems","url":"https://learn.microsoft.com/azure/well-architected/security/data-classification","coverage":"partial","tests":["AZ-DEF-024"]},
    "SE:04": {"title":"Create intentional segmentation and perimeters","url":"https://learn.microsoft.com/azure/well-architected/security/segmentation","coverage":"partial","tests":["AZ-AKS-007","AZ-NET-006"]},
    "SE:05": {"title":"Implement strict, conditional and auditable identity and access management","url":"https://learn.microsoft.com/azure/well-architected/security/identity-access","coverage":"partial","tests":["AZ-ACR-001","AZ-AI-001","AZ-AKS-001","AZ-AKS-002","AZ-APP-004","AZ-APP-009","AZ-APP-014","AZ-COS-001","AZ-FUNC-004","AZ-IAM-001","AZ-IAM-002","AZ-IAM-003","AZ-IAM-004","AZ-IAM-009","AZ-IAM-010","AZ-IAM-011","AZ-IAM-015","AZ-IAM-016","AZ-KV-002","AZ-KV-009","AZ-LOGIC-001","AZ-MY-003","AZ-PAAS-002","AZ-PG-004","AZ-SQL-003","AZ-SQL-004","AZ-STG-003","AZ-STG-004","AZ-STG-005","AZ-VM-004"]},
    "SE:06": {"title":"Isolate, filter and control network traffic across ingress and egress flows","url":"https://learn.microsoft.com/azure/well-architected/security/networking","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-003","AZ-AI-002","AZ-AI-003","AZ-AI-005","AZ-AKS-003","AZ-APP-008","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-KV-003","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-007","AZ-NET-008","AZ-NET-012","AZ-NET-015","AZ-NET-018","AZ-NET-019","AZ-NET-020","AZ-NET-023","AZ-PAAS-001","AZ-SQL-005","AZ-STG-006","AZ-STG-007","AZ-VM-011","AZ-VM-012"]},
    "SE:07": {"title":"Encrypt data using modern, industry-standard methods","url":"https://learn.microsoft.com/azure/well-architected/security/encryption","coverage":"partial","tests":["AZ-APIM-002","AZ-APP-001","AZ-APP-002","AZ-CAPP-001","AZ-MY-001","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-006","AZ-SQL-007","AZ-STG-001","AZ-STG-002","AZ-VM-002"]},
    "SE:08": {"title":"Harden all workload components by reducing extraneous surface area","url":"https://learn.microsoft.com/azure/well-architected/security/harden-resources","coverage":"partial","tests":["AZ-APP-003","AZ-APP-005","AZ-APP-007","AZ-DFA-002","AZ-DFA-003","AZ-DFA-004","AZ-NET-022","AZ-VM-003","AZ-VM-005"]},
    "SE:09": {"title":"Protect application secrets","url":"https://learn.microsoft.com/azure/well-architected/security/application-secrets","coverage":"partial","tests":["AZ-ADF-001","AZ-AKS-008","AZ-APIM-003","AZ-APP-006","AZ-AUTO-001","AZ-AUTO-002","AZ-FUNC-002","AZ-IAM-013","AZ-IAM-014","AZ-IAM-022","AZ-KV-001","AZ-KV-005","AZ-KV-006","AZ-KV-010","AZ-KV-011","AZ-LOGIC-003","AZ-LOGIC-004","AZ-LOGIC-005","AZ-LOGIC-006","AZ-SEC-001","AZ-SEC-002","AZ-SEC-003","AZ-SEC-004","AZ-STG-024"]},
    "SE:10": {"title":"Implement a holistic monitoring strategy with modern threat detection","url":"https://learn.microsoft.com/azure/well-architected/security/monitor-threats","coverage":"partial","tests":["AZ-BCK-006","AZ-DEF-001","AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-023","AZ-DFA-001","AZ-LOG-001","AZ-LOG-014","AZ-LOG-015","AZ-LOG-018","AZ-LOG-021","AZ-SQL-001","AZ-VM-006","AZ-VM-008"]},
    "SE:11": {"title":"Establish a comprehensive testing regimen","url":"https://learn.microsoft.com/azure/well-architected/security/test","applicability":"manual"},
    "SE:12": {"title":"Define and test effective incident response procedures","url":"https://learn.microsoft.com/azure/well-architected/security/incident-response","coverage":"partial","tests":["AZ-BCK-001","AZ-BCK-002","AZ-DEF-022","AZ-VM-010"]}
  }
}