last sync: 2025-Oct-23 17:23:10 UTC

Microsoft Managed Control 1148 - Security Assessments | Independent Assessors | Regulatory Compliance - Security Assessment and Authorization

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1148 - Security Assessments | Independent Assessors
Id 28e62650-c7c2-4786-bdfa-17edc1673902
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Security Assessment and Authorization control
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '1.0.0'
Repository: Azure-Policy 28e62650-c7c2-4786-bdfa-17edc1673902
Additional metadata Name/Id: ACF1148 / Microsoft Managed Control 1148
Category: Security Assessment and Authorization
Title: Security Assessments | Independent Assessors
Ownership: Customer, Microsoft
Description: The organization employs assessors or assessment teams with 3PAO accreditation, specific for FedRAMP certification, to conduct security control assessments.
Requirements: Azure employs an approved Third Party Assessment Organization (3PAO) as an independent assessor to conduct a security control assessment of Azure in accordance with requirements. The results of this assessment and related activities are submitted to Azure’s authorizing officials.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC