SlideShare a Scribd company logo
Azure Virtual Datacenter
Building a Secure and Compliant
Azure Infrastructure-as-a-Service
Environment
#ILTACON19
#G1238
Patrick is a founder of Square10 and a proven technology professional with
more than 20 years of industry expertise. He works with law firms to
deliver technology solutions focused on enabling business outcomes,
mitigating risk, optimizing operations and increasing profitability. His areas
of specialty include strategic planning and advisory services, cloud services
delivery and management, identity management and single sign-on,
messaging, technical project management, and complex migrations.
Patrick is regularly invited to present on such topics as technology trends,
cloud computing, identity management, Microsoft technologies, mobile
computing, and disaster recovery.
info@square10.net
www.sqare10.net
PATRICK SKLODOWSKI
Principal
Square10 Solutions LLC
#ILTACON19
#G1238
Azure Virtual Datacenter
Building a Secure and Compliant AZURE
Infrastructure-as-a-Service Environment
VIRTUAL DATA CENTER (VDC)
#ILTACON19
#G1238
ONE FIRM’S JOURNEY
FIRM’S BUSINESS
CHALLENGES
• Acquisition of firm running MPS hosted
virtual desktops
• Head count flexes based on economy
• Client base is 100% financial institutions
• Data localized across offices
• Desktops must be local to servers!
Photo by Olav Ahrens Røtne on Unsplash
Photo by Element5 Digital on Unsplash
TO CLOUD OR NOT TO CLOUD
FISH & RICHARDSON – LAW FIRM CLOUD SURVEY (2019)
Responses covered multitude of SaaS cloud service.
Photo by Elena Taranenko on Unsplash
FIRM’S BUSINESS GOALS
• Quickly integrate new firm (8 weeks)
• Centralize data
• Cost flexes based on staffing
• Move to operating expense (OPEX) model
• Meet requirements of financial institution client base
• Upcoming audit sets compliance precedent
Photo by Chris Knight on Unsplash
PERMISSION OR FORGIVENESS?
FISH & RICHARDSON – LAW FIRM CLOUD SURVEY (2019)
WHO’S RESPONSIBLE?
SHARED RESPONSIBILITY MODEL
Courtesy of Microsoft
Outsourced
TRUST
Maximum
CONTROL
SPECTRUM OF CONTROL AND TRUST
Trusted Execution Environment
SQL Transparent Encryption,
Azure Services in a VNet
Customer
Lockbox
Azure Active Directory, Azure Key Vault
Isolated
VMs
Azure Control Plane, Just in Time Access, Monitoring, Audit and Reporting
Where you land drives service model selection
IaaS
Courtesy of Microsoft
AZURE IMPLEMENTATION - WHAT HAPPENED
AZURE IMPLEMENTATION
- WHAT (REALLY) HAPPENED
• Successful migration!!!
• Order of client audits changed
• 1st Audit
Client CISO says NO CLOUD!
• PANIC!!
• (breathe)
• Respond
Photo by Luka Vovk on Unsplash
FACTS, PHILOSOPHY & GUIDANCE
Securing Privileged Access
Office 365 Security
Rapid Cyberattacks
(Wannacrypt/Petya)
https://aka.ms/MCRA Video Recording Strategies
Office 365
Dynamics 365
+Monito
r
Azure Sentinel – Cloud Native SIEM and SOAR (Preview)
SQL Encryption &
Data Masking
Data Loss
Protection
Data Governance
eDiscovery
MICROSOFT’S COMPLIANCE
• 90+ compliance offerings
• $1B+ investment in security R&D and 3,500 cyber security experts
• 6.5 trillion threat signals analyzed daily
VDC IS A TRUSTED ASSET
Policy Scoping for RBAC – Least Privilege Model
✓ By Governmental Regulatory Authorities
✓ By Corporate Security Authorities (SecOps)
✓ By Management / Admins / IT Pro (NetOps, InfraOps)
✓ By Application Developers (DevOps)
✓ By End Users (GDPR)
Handover: Like racks in
their own DC Sandboxes
can be surfaced through
DevTest Labs.
…Azure as a trusted extension to your on-premises
VDC Perimeter with your workloads
Courtesy of Microsoft
MICROSOFT GUIDANCE
• Cloud Adoption Framework for Azure
• Azure Blueprints
• Service Trust Portal
azure.com/governance
SERVICE TRUST PORTAL
• Compliance Manager
• Industry and region specific documents
Trust Center
servicetrust.microsoft.com
• Trust documents
– Audit reports (FedRAMP, ISO, PCI DSS, SOC)
– Data protection resources (control mappings!)
– Security and compliance blueprints
THIRD PARTY GUIDANCE
• Center for Internet Security
– Azure Benchmark
• Cloud Security Alliance
– Security Trust Assurance and Risk
Registry (STAR)
– Microsoft Self Attestations
TOOLS AND AUTOMATION
MICROSOFT COMPLIANCE MANAGER
• Evolving (use classic portal for Azure)
• Key for Compliance Officers and CISOs
• GDPR complete / ISO Customer controls coming soon
MICROSOFT COMPLIANCE MANAGER
AZURE SECURITY CENTER
• Holistic security and compliance posturing and assessment
• Focus on
– Security policy
– Security score
– Regulatory compliance
AZURE SECURITY SCORE
• Part of Security Center
• Security posturing across Azure
AZURE SECURITY SCORE
REGULATORY COMPLIANCE
• Part of Security Center
• Maps to compliance controls
REGULATORY COMPLIANCE
AZURE POLICY
• Policy and compliance management
• Technical, security and regulatory compliance
• Many features in preview
AZURE POLICY
AZURE ADVISOR
• Best practice recommendations
– High availability
– Security
– Performance
– Cost
AZURE BLUEPRINTS (SERVICE)
• Deploy and update cloud environments in a repeatable manner using templates
• Currently in preview
PRACTICAL TIPS
QUICKSTART
• Access control
• Infrastructure
• Security auditing and logging
• Governance tools
Photo by Jon Tyson on Unsplash
ACCESS CONTROL
• Identity Management / Access Control
– Azure AD Premium 1 / EMS Suite
– Conditional Access
– MFA
– Trusted assets / device management
• Identity Governance
• Privileged Identity Management
Pre-screened Admin
requests access
Leadership grants
temporary privilege
✓ No standing access to the platform and no access to customer Virtual Machines
✓ Grants least privilege required to complete task; access requests are audited and logged
✓ Multi-factor authentication required for all administration
Just-in-Time &
Role-Based
Access
Microsoft Corporate Network
Microsoft Azure
BLOBS
TABLES QUEUES
VMs
MICROSOFT’S ACCESS
Mature platform governanceCourtesy of Microsoft
INFRASTRUCTURE
• Consider with ISO 27001 blueprint?
• Networking
– Connectivity
– Firewall
• Network Security Group
• Virtual Firewall
• Azure Firewall
• Encryption
– BitLocker
– Key Management
• Third party vs Azure Key Vault
Courtesy of Microsoft
Azure
Customer
Azure Monitor
Platform
Application level audit logs
• Customer audits go to the customer via Azure Monitor
• Audit logs for Internal management services (internal only)
Worker roleCloud ServiceVM
Web Apps SQL Azure
Logging and reporting drives confidence and transparency
SECURITY AUDITING AND LOGGING
Courtesy of Microsoft
AZURE SENTINEL
Courtesy of Microsoft
GOVERNANCE TOOLS
HOW DOES THE STORY END?
Photo by James Douglas on Unsplash
HOW DID WE GO FROM
“NO CLOUD” TO PASSING?
• CFO provided
– Business justification
– Offered to explain rationale and work with client
– Focused on controls (Microsoft and internal)
• Written audit response
– Heavy use of Microsoft documentation
– Focused on controls (self attestation) and technologies
• Audit
– Deep dives with auditors
– Open book
Photo by James Douglas on Unsplash
QUESTIONS AND DISCUSSION
CAN WE BE COMPLIANT IN AZURE?
GUIDANCE TOOLS TECHNOLOGY
USE WHAT’S AVAILABLE
RESOURCES
Resources
Azure Architecture Center
• https://docs.microsoft.com/en-us/azure/architecture/
Azure Virtual Datacenter
• https://docs.microsoft.com/en-us/azure/architecture/vdc/
Microsoft Cloud Adoption Framework for Azure
• https://docs.microsoft.com/en-us/azure/architecture/cloud-adoption/
Microsoft Shared responsibility model
• https://docs.microsoft.com/en-us/azure/security/fundamentals/infrastructure
• https://blogs.msdn.microsoft.com/azuresecurity/2016/04/18/what-does-shared-
responsibility-in-the-cloud-mean/
Azure governance
• https://azure.com/governance
Overview of Microsoft Azure compliance
• https://gallery.technet.microsoft.com/Overview-of-Azure-c1be3942
Microsoft Service Trust Portal
• https://servicetrust.microsoft.com
CIS Azure Benchmark
• https://www.cisecurity.org/benchmark/azure/
CIS Hardened Images on Azure
• https://www.cisecurity.org/cis-hardened-images/microsoft/
Cloud Security Alliance
• https://cloudsecurityalliance.org/
Cloud Security Alliance STAR Registry
• https://cloudsecurityalliance.org/star/registry/Microsoft/
Microsoft Compliance Manager
• https://servicetrust.microsoft.com/
• Use Classic Portal for Azure
Azure Security Center
• https://azure.microsoft.com/en-us/services/security-center/
Azure Security Score
• https://docs.microsoft.com/en-us/azure/security-center/security-center-secure-score
Regulatory compliance in Security Center
• https://docs.microsoft.com/en-us/azure/security-center/security-center-compliance-
dashboard/
Azure Policy
• https://azure.microsoft.com/en-us/services/azure-policy/
Azure Advisor
• https://azure.microsoft.com/en-us/services/advisor/
Azure Blueprints Service
• https://docs.microsoft.com/en-us/azure/governance/blueprints/overview
Fish & Richardson Cloud Security Survey
• https://www.linkedin.com/pulse/cloudy-chance-meatballs-beau-mersereau/
55

More Related Content

PPTX
Virtual Data Center VDC - Azure Cloud Reference Architecture CRA
PDF
Microsoft Azure Security Overview
PDF
introduction to Azure Sentinel
PPTX
Trust No-One Architecture For Services And Data
PDF
Azure 101: Shared responsibility in the Azure Cloud
PDF
Govern Your Cloud: The Foundation for Success
PPTX
MCAS High Level Architecture May 2021
PPTX
Supporting Remote Work While Securing, Governing, and Protecting Your Microso...
Virtual Data Center VDC - Azure Cloud Reference Architecture CRA
Microsoft Azure Security Overview
introduction to Azure Sentinel
Trust No-One Architecture For Services And Data
Azure 101: Shared responsibility in the Azure Cloud
Govern Your Cloud: The Foundation for Success
MCAS High Level Architecture May 2021
Supporting Remote Work While Securing, Governing, and Protecting Your Microso...

What's hot (20)

PPTX
Office 365 Security Best Practices
PPTX
Securing Applications in the Cloud
PDF
Securely logging to Microsoft 365
PDF
Microsoft 365 Security Overview
PDF
Azure saturday 2017 - Protecting cloud identities using ems
PPTX
CSS17: Atlanta - Realities of Security in the Cloud
PDF
Azure vm introduction
PPTX
Power of the cloud - Introduction to azure security
PDF
Identity and Data protection with Enterprise Mobility Security in ottica GDPR
PDF
Microsoft Office 365 Security and Compliance
PDF
Azure security architecture
PPTX
Softchoice - Microsoft Office 365 - Discussing legal concerns and informatio...
PPTX
2018 November - AZUGDK - Azure AD
PPTX
Securing your Azure Identity Infrastructure
PDF
SCUGBE_Lowlands_Unite_2017_Protecting cloud identities
PPTX
The Future of CASBs - A Cloud Security Force Awakens
PDF
Cloud Security for Startups - From A to E(xit)
PDF
Css sf azure_8-9-17 - 5_ways to_optimize_your_azure_infrastructure_thayer gla...
PPTX
Shared Security Responsibility for the Azure Cloud
PDF
AWS Frederick Meetup 07192016
Office 365 Security Best Practices
Securing Applications in the Cloud
Securely logging to Microsoft 365
Microsoft 365 Security Overview
Azure saturday 2017 - Protecting cloud identities using ems
CSS17: Atlanta - Realities of Security in the Cloud
Azure vm introduction
Power of the cloud - Introduction to azure security
Identity and Data protection with Enterprise Mobility Security in ottica GDPR
Microsoft Office 365 Security and Compliance
Azure security architecture
Softchoice - Microsoft Office 365 - Discussing legal concerns and informatio...
2018 November - AZUGDK - Azure AD
Securing your Azure Identity Infrastructure
SCUGBE_Lowlands_Unite_2017_Protecting cloud identities
The Future of CASBs - A Cloud Security Force Awakens
Cloud Security for Startups - From A to E(xit)
Css sf azure_8-9-17 - 5_ways to_optimize_your_azure_infrastructure_thayer gla...
Shared Security Responsibility for the Azure Cloud
AWS Frederick Meetup 07192016
Ad

Similar to Building a Secure and Compliant Azure Virtual Data Center (20)

PDF
Tour to Azure Security Center
PPTX
Fundamentals of Microsoft 365 Security , Identity and Compliance
PPTX
Cisco integrated system for microsoft azure stack
PPTX
microsoft-cybersecurity-reference-architectures (1).pptx
PPTX
Improving Application Security With Azure
PPTX
Azure seminar mai 2014 01 hvorfor er azure riktig for din bedrift
PDF
8 Elements of Multi-Cloud Security
PDF
Future of Your Atlassian Platform - Data Center and Cloud Migration
PDF
15th December 2016 - Microsoft Paddington Vuzion Partner Event
PPTX
Kabelo Sekele- Government in Transformation: Cloud Powered Security, Identity...
PDF
366864108 azure-security
PPTX
Continuous Compliance in the Cloud - Best Practices from Sumo Logic, Coalfire...
PDF
TechEvent 2019: More Agile, More AI, More Cloud! Less Work?!; Oliver Dörr - T...
PPTX
Security Architecture Best Practices for SaaS Applications
PDF
Top Learnings from Azure Security (1).pdf
PDF
Microsoft Azure Stack
PPTX
Security architecture best practices for saas applications
PDF
Css sf azure_8-9-17-microsoft_azure_security_overview_babak suzani_msft
PDF
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
PPTX
How to Optimize Your AWS Environment for Improved Cloud Performance
Tour to Azure Security Center
Fundamentals of Microsoft 365 Security , Identity and Compliance
Cisco integrated system for microsoft azure stack
microsoft-cybersecurity-reference-architectures (1).pptx
Improving Application Security With Azure
Azure seminar mai 2014 01 hvorfor er azure riktig for din bedrift
8 Elements of Multi-Cloud Security
Future of Your Atlassian Platform - Data Center and Cloud Migration
15th December 2016 - Microsoft Paddington Vuzion Partner Event
Kabelo Sekele- Government in Transformation: Cloud Powered Security, Identity...
366864108 azure-security
Continuous Compliance in the Cloud - Best Practices from Sumo Logic, Coalfire...
TechEvent 2019: More Agile, More AI, More Cloud! Less Work?!; Oliver Dörr - T...
Security Architecture Best Practices for SaaS Applications
Top Learnings from Azure Security (1).pdf
Microsoft Azure Stack
Security architecture best practices for saas applications
Css sf azure_8-9-17-microsoft_azure_security_overview_babak suzani_msft
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
How to Optimize Your AWS Environment for Improved Cloud Performance
Ad

Recently uploaded (20)

PDF
Machine learning based COVID-19 study performance prediction
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
KodekX | Application Modernization Development
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Cloud computing and distributed systems.
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Encapsulation theory and applications.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Empathic Computing: Creating Shared Understanding
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Approach and Philosophy of On baking technology
Machine learning based COVID-19 study performance prediction
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Chapter 3 Spatial Domain Image Processing.pdf
KodekX | Application Modernization Development
Diabetes mellitus diagnosis method based random forest with bat algorithm
Cloud computing and distributed systems.
Per capita expenditure prediction using model stacking based on satellite ima...
Encapsulation theory and applications.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
NewMind AI Weekly Chronicles - August'25 Week I
Dropbox Q2 2025 Financial Results & Investor Presentation
Understanding_Digital_Forensics_Presentation.pptx
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
The Rise and Fall of 3GPP – Time for a Sabbatical?
Advanced methodologies resolving dimensionality complications for autism neur...
Empathic Computing: Creating Shared Understanding
“AI and Expert System Decision Support & Business Intelligence Systems”
Digital-Transformation-Roadmap-for-Companies.pptx
Approach and Philosophy of On baking technology

Building a Secure and Compliant Azure Virtual Data Center

  • 1. Azure Virtual Datacenter Building a Secure and Compliant Azure Infrastructure-as-a-Service Environment #ILTACON19 #G1238
  • 2. Patrick is a founder of Square10 and a proven technology professional with more than 20 years of industry expertise. He works with law firms to deliver technology solutions focused on enabling business outcomes, mitigating risk, optimizing operations and increasing profitability. His areas of specialty include strategic planning and advisory services, cloud services delivery and management, identity management and single sign-on, messaging, technical project management, and complex migrations. Patrick is regularly invited to present on such topics as technology trends, cloud computing, identity management, Microsoft technologies, mobile computing, and disaster recovery. info@square10.net www.sqare10.net PATRICK SKLODOWSKI Principal Square10 Solutions LLC #ILTACON19 #G1238
  • 3. Azure Virtual Datacenter Building a Secure and Compliant AZURE Infrastructure-as-a-Service Environment VIRTUAL DATA CENTER (VDC) #ILTACON19 #G1238
  • 5. FIRM’S BUSINESS CHALLENGES • Acquisition of firm running MPS hosted virtual desktops • Head count flexes based on economy • Client base is 100% financial institutions • Data localized across offices • Desktops must be local to servers! Photo by Olav Ahrens Røtne on Unsplash
  • 6. Photo by Element5 Digital on Unsplash
  • 7. TO CLOUD OR NOT TO CLOUD FISH & RICHARDSON – LAW FIRM CLOUD SURVEY (2019) Responses covered multitude of SaaS cloud service.
  • 8. Photo by Elena Taranenko on Unsplash
  • 9. FIRM’S BUSINESS GOALS • Quickly integrate new firm (8 weeks) • Centralize data • Cost flexes based on staffing • Move to operating expense (OPEX) model • Meet requirements of financial institution client base • Upcoming audit sets compliance precedent Photo by Chris Knight on Unsplash
  • 10. PERMISSION OR FORGIVENESS? FISH & RICHARDSON – LAW FIRM CLOUD SURVEY (2019)
  • 13. Outsourced TRUST Maximum CONTROL SPECTRUM OF CONTROL AND TRUST Trusted Execution Environment SQL Transparent Encryption, Azure Services in a VNet Customer Lockbox Azure Active Directory, Azure Key Vault Isolated VMs Azure Control Plane, Just in Time Access, Monitoring, Audit and Reporting Where you land drives service model selection IaaS Courtesy of Microsoft
  • 14. AZURE IMPLEMENTATION - WHAT HAPPENED
  • 15. AZURE IMPLEMENTATION - WHAT (REALLY) HAPPENED • Successful migration!!! • Order of client audits changed • 1st Audit Client CISO says NO CLOUD! • PANIC!! • (breathe) • Respond Photo by Luka Vovk on Unsplash
  • 17. Securing Privileged Access Office 365 Security Rapid Cyberattacks (Wannacrypt/Petya) https://aka.ms/MCRA Video Recording Strategies Office 365 Dynamics 365 +Monito r Azure Sentinel – Cloud Native SIEM and SOAR (Preview) SQL Encryption & Data Masking Data Loss Protection Data Governance eDiscovery
  • 18. MICROSOFT’S COMPLIANCE • 90+ compliance offerings • $1B+ investment in security R&D and 3,500 cyber security experts • 6.5 trillion threat signals analyzed daily
  • 19. VDC IS A TRUSTED ASSET Policy Scoping for RBAC – Least Privilege Model ✓ By Governmental Regulatory Authorities ✓ By Corporate Security Authorities (SecOps) ✓ By Management / Admins / IT Pro (NetOps, InfraOps) ✓ By Application Developers (DevOps) ✓ By End Users (GDPR) Handover: Like racks in their own DC Sandboxes can be surfaced through DevTest Labs. …Azure as a trusted extension to your on-premises VDC Perimeter with your workloads Courtesy of Microsoft
  • 20. MICROSOFT GUIDANCE • Cloud Adoption Framework for Azure • Azure Blueprints • Service Trust Portal azure.com/governance
  • 21. SERVICE TRUST PORTAL • Compliance Manager • Industry and region specific documents Trust Center servicetrust.microsoft.com • Trust documents – Audit reports (FedRAMP, ISO, PCI DSS, SOC) – Data protection resources (control mappings!) – Security and compliance blueprints
  • 22. THIRD PARTY GUIDANCE • Center for Internet Security – Azure Benchmark • Cloud Security Alliance – Security Trust Assurance and Risk Registry (STAR) – Microsoft Self Attestations
  • 24. MICROSOFT COMPLIANCE MANAGER • Evolving (use classic portal for Azure) • Key for Compliance Officers and CISOs • GDPR complete / ISO Customer controls coming soon
  • 26. AZURE SECURITY CENTER • Holistic security and compliance posturing and assessment • Focus on – Security policy – Security score – Regulatory compliance
  • 27. AZURE SECURITY SCORE • Part of Security Center • Security posturing across Azure
  • 29. REGULATORY COMPLIANCE • Part of Security Center • Maps to compliance controls
  • 31. AZURE POLICY • Policy and compliance management • Technical, security and regulatory compliance • Many features in preview
  • 33. AZURE ADVISOR • Best practice recommendations – High availability – Security – Performance – Cost
  • 34. AZURE BLUEPRINTS (SERVICE) • Deploy and update cloud environments in a repeatable manner using templates • Currently in preview
  • 36. QUICKSTART • Access control • Infrastructure • Security auditing and logging • Governance tools Photo by Jon Tyson on Unsplash
  • 37. ACCESS CONTROL • Identity Management / Access Control – Azure AD Premium 1 / EMS Suite – Conditional Access – MFA – Trusted assets / device management • Identity Governance • Privileged Identity Management
  • 38. Pre-screened Admin requests access Leadership grants temporary privilege ✓ No standing access to the platform and no access to customer Virtual Machines ✓ Grants least privilege required to complete task; access requests are audited and logged ✓ Multi-factor authentication required for all administration Just-in-Time & Role-Based Access Microsoft Corporate Network Microsoft Azure BLOBS TABLES QUEUES VMs MICROSOFT’S ACCESS Mature platform governanceCourtesy of Microsoft
  • 39. INFRASTRUCTURE • Consider with ISO 27001 blueprint? • Networking – Connectivity – Firewall • Network Security Group • Virtual Firewall • Azure Firewall • Encryption – BitLocker – Key Management • Third party vs Azure Key Vault Courtesy of Microsoft
  • 40. Azure Customer Azure Monitor Platform Application level audit logs • Customer audits go to the customer via Azure Monitor • Audit logs for Internal management services (internal only) Worker roleCloud ServiceVM Web Apps SQL Azure Logging and reporting drives confidence and transparency SECURITY AUDITING AND LOGGING Courtesy of Microsoft
  • 43. HOW DOES THE STORY END?
  • 44. Photo by James Douglas on Unsplash
  • 45. HOW DID WE GO FROM “NO CLOUD” TO PASSING? • CFO provided – Business justification – Offered to explain rationale and work with client – Focused on controls (Microsoft and internal) • Written audit response – Heavy use of Microsoft documentation – Focused on controls (self attestation) and technologies • Audit – Deep dives with auditors – Open book Photo by James Douglas on Unsplash
  • 47. CAN WE BE COMPLIANT IN AZURE?
  • 48. GUIDANCE TOOLS TECHNOLOGY USE WHAT’S AVAILABLE
  • 50. Resources Azure Architecture Center • https://docs.microsoft.com/en-us/azure/architecture/ Azure Virtual Datacenter • https://docs.microsoft.com/en-us/azure/architecture/vdc/ Microsoft Cloud Adoption Framework for Azure • https://docs.microsoft.com/en-us/azure/architecture/cloud-adoption/ Microsoft Shared responsibility model • https://docs.microsoft.com/en-us/azure/security/fundamentals/infrastructure • https://blogs.msdn.microsoft.com/azuresecurity/2016/04/18/what-does-shared- responsibility-in-the-cloud-mean/ Azure governance • https://azure.com/governance Overview of Microsoft Azure compliance • https://gallery.technet.microsoft.com/Overview-of-Azure-c1be3942 Microsoft Service Trust Portal • https://servicetrust.microsoft.com CIS Azure Benchmark • https://www.cisecurity.org/benchmark/azure/ CIS Hardened Images on Azure • https://www.cisecurity.org/cis-hardened-images/microsoft/ Cloud Security Alliance • https://cloudsecurityalliance.org/ Cloud Security Alliance STAR Registry • https://cloudsecurityalliance.org/star/registry/Microsoft/ Microsoft Compliance Manager • https://servicetrust.microsoft.com/ • Use Classic Portal for Azure Azure Security Center • https://azure.microsoft.com/en-us/services/security-center/ Azure Security Score • https://docs.microsoft.com/en-us/azure/security-center/security-center-secure-score Regulatory compliance in Security Center • https://docs.microsoft.com/en-us/azure/security-center/security-center-compliance- dashboard/ Azure Policy • https://azure.microsoft.com/en-us/services/azure-policy/ Azure Advisor • https://azure.microsoft.com/en-us/services/advisor/ Azure Blueprints Service • https://docs.microsoft.com/en-us/azure/governance/blueprints/overview Fish & Richardson Cloud Security Survey • https://www.linkedin.com/pulse/cloudy-chance-meatballs-beau-mersereau/
  • 51. 55