Compliance assessment and setting policies

Paul Schoorl 1 Reputation point
2020-07-15T15:00:58.087+00:00

Setting Security Center to Standard Plan allows for view and alteration of ASC policies.
For assessment the framework can be chosen (e.g. ISO)
12425-screen-shot-2020-07-15-at-165408.png

However: looking at the assessment e.g. ISO I notice Windows level CCE policies
Where do these policies come from and how can I alter these?

12470-screen-shot-2020-07-15-at-165331.png

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. JamesTran-MSFT 36,531 Reputation points Microsoft Employee
    2020-07-16T00:48:56.133+00:00

    @PaulSchoorl-2684
    On the Industry and Standards section within Azure Security Center (ASC), those assessments look like they come from ISO 27001:2013. Azure Security Center also uses CCE (Common Configuration Enumeration) to assign unique identifiers for configuration rules. Based off my research and testing, you can manage and edit the security policies. However, you can't view the specific initiatives, or delete the definitions within the industry & regulatory standards. To customize policies to meet your organization's needs, you'd have to create a custom security policy. Additionally, I noticed that the default ASC supported regulatory standards: Azure CIS, PCI DSS 3.2, ISO 27001, and SOC TSP, aren't hyperlinks, so you can't view or delete those specific definitions inside the policy.

    From the screenshot below, you can see that there's only a hyperlink on "Azure CIS 1.1.0 (New)", and not the default regulatory standards.
    12537-standards.jpg

    Within Azure CIS, you can see that I can't delete initiatives, I wasn't able to delete the definitions either.
    12538-standardinitiatives.jpg

    When I go into my custom policy, I'm able to edit or delete initiatives and definitions.
    12450-secpolicyinitiatives.jpg
    12509-customdef.jpg

    Please let me know if you have any other questions.
    Thank you for your time!

    Additional CCE Links:
    Act as part of the operating system
    Shut down the system
    Deny log on locally
    Network access: Let Everyone permissions apply to anonymous users


  2. chakri 1 Reputation point
    2020-08-03T19:53:39.183+00:00

    Hi ,

    I also tried to add Azure CIS 1.1.0(new) and Default policies and not changed and not able to modify because no Edit option on Azure CIS benchmark

    example- if I need to modify as MFA policy to disable also CIS control is still AuditIfnotExist only .

    PLease let me know how can we modify the policy

    0 comments No comments