International

Azure Security Benchmark

85 controls. 147 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

85 controls 147 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
AM-2Use only approved services23
AM-3Ensure security of asset lifecycle management32
ASBv3-AM-1Track asset inventory and their risks30
ASBv3-AM-4Limit access to asset management25
ASBv3-AM-5Use only approved applications in virtual machine24
ASBv3-BR-3Monitor backups20
ASBv3-BR-4Regularly test backup24
ASBv3-DP-1Discover, classify, and label sensitive data26
ASBv3-DP-5Use customer-managed key option in data at rest encryption when required22
ASBv3-DP-6Use a secure key management process22
ASBv3-DP-7Use a secure certificate management process15
ASBv3-DP-8Ensure security of key and certificate repository18
ASBv3-DS-1Conduct threat modeling25
ASBv3-DS-3Secure DevOps infrastructure21
ASBv3-DS-4Integrate static application security testing into DevOps pipeline19
ASBv3-DS-5Integrate dynamic application security testing into DevOps pipeline18
ASBv3-DS-7Enable logging and monitoring in DevOps19
ASBv3-ES-3Ensure anti-malware software and signatures are updated25
ASBv3-GS-10Define and implement DevOps security strategy21
ASBv3-GS-2Define and implement enterprise segmentation/separation of duties strategy25
ASBv3-GS-3Define and implement data protection strategy26
ASBv3-GS-4Define and implement network security strategy25
ASBv3-GS-5Define and implement security posture management strategy27
ASBv3-GS-6Define and implement identity and privileged access strategy27
ASBv3-GS-7Define and implement logging, threat detection and incident response strategy26
ASBv3-GS-8Define and implement backup and recovery strategy23
ASBv3-GS-9Define and implement endpoint security strategy22
ASBv3-IM-2Protect identity and authentication systems25
ASBv3-IM-5Use single sign-on (SSO) for application access14
ASBv3-IM-8Restrict the exposure of credential and secrets26
ASBv3-IM-9Secure user access to existing applications12
ASBv3-IR-1Preparation - update incident response plan and handling process33
ASBv3-IR-2Preparation - setup incident notification28
ASBv3-IR-3Detection and analysis - create incidents based on high-quality alerts26
ASBv3-IR-4Detection and analysis - investigate an incident26
ASBv3-IR-5Detection and analysis - prioritize incidents24
ASBv3-IR-6Containment, eradication and recovery - automate the incident handling22
ASBv3-IR-7Post-incident activity - conduct lesson learned and retain evidence28
ASBv3-LT-1Enable threat detection capabilities27
ASBv3-LT-2Enable threat detection for identity and access management24
ASBv3-LT-6Configure log storage retention25
ASBv3-LT-7Use approved time synchronization sources16
ASBv3-NS-10Ensure Domain Name System (DNS) security11
ASBv3-NS-4Deploy intrusion detection/intrusion prevention systems (IDS/IPS)21
ASBv3-NS-6Deploy web application firewall18
ASBv3-NS-7Simplify network security configuration17
ASBv3-NS-8Detect and disable insecure services and protocols27
ASBv3-NS-9Connect on-premises or cloud network privately21
ASBv3-PA-4Review and reconcile user access regularly27
ASBv3-PA-5Set up emergency access16
ASBv3-PA-6Use privileged access workstations24
ASBv3-PA-7Follow just enough administration (least privilege) principle32
ASBv3-PA-8Determine access process for cloud provider support24
ASBv3-PV-1Define and establish secure configurations29
ASBv3-PV-3Define and establish secure configurations for compute resources25
ASBv3-PV-4Audit and enforce secure configurations for compute resources27
ASBv3-PV-6Rapidly and automatically remediate vulnerabilities30
ASBv3-PV-7Conduct regular red team operations27
BR-1Ensure regular automated backups25
BR-2Protect backup and recovery data26
DP-2Monitor anomalies and threats targeting sensitive data24
DP-3Encrypt sensitive data in transit26
DP-4Enable data at rest encryption by default26
DS-2Ensure software supply chain security133
DS-6Enforce security of workload throughout DevOps lifecycle21
ES-1Use Endpoint Detection and Response (EDR)26
ES-2Use modern anti-malware software27
GS-1Align organization roles, responsibilities and accountabilities31
IM-1Use centralized identity and authentication system28
IM-3Manage application identities securely and automatically24
IM-4Authenticate server and services18
IM-6Use strong authentication controls29
IM-7Restrict resource access based on conditions26
LT-3Enable logging for security investigation29
LT-4Enable network logging for security investigation23
LT-5Centralize security log management and analysis27
NS-1Establish network segmentation boundaries27
NS-2Secure cloud services with network controls25
NS-3Deploy firewall at the edge of enterprise network24
NS-5Deploy DDOS protection13
PA-1Separate and limit highly privileged/administrative users28
PA-2Avoid standing access for user accounts and permissions24
PA-3Manage lifecycle of identities and entitlements26
PV-2Audit and enforce secure configurations30
PV-5Perform vulnerability assessments34

Tell me when Azure Security Benchmark files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • OT asset inventory
  • Zone and conduit diagram
  • Patch register
  • Remote access policy
  • Infrastructure/virtualization security policy
  • Network segmentation + defense architecture
  • Annual review
  • RACI for infosec roles
  • RACI matrix
  • role descriptions

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Azure Security Benchmark, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition