compliance controls are associated with this Policy definition 'Review audit data' (6625638f-3ba1-7404-5983-0ea33d719d34)
                    
                        
                            
                                | Control Domain | Control | Name | MetadataId | Category | Title | Owner | Requirements | Description | Info | Policy# | 
                        
                                        
                        | CIS_Azure_1.1.0 | 2.14 | CIS_Azure_1.1.0_2.14 | CIS Microsoft Azure Foundations Benchmark recommendation 2.14 | 2 Security Center | Ensure ASC Default policy setting "Monitor SQL Auditing" is not "Disabled" | Shared | The customer is responsible for implementing this recommendation. | Enable SQL auditing recommendations. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 3.3 | CIS_Azure_1.1.0_3.3 | CIS Microsoft Azure Foundations Benchmark recommendation 3.3 | 3 Storage Accounts | Ensure Storage logging is enabled for Queue service for read, write, and delete requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Queue service stores messages that may be read by any client who has access to the storage account. A queue can contain an unlimited number of messages, each of which can be up to 64KB in size using version 2011-08-18 or newer. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the queues. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 4.1 | CIS_Azure_1.1.0_4.1 | CIS Microsoft Azure Foundations Benchmark recommendation 4.1 | 4 Database Services | Ensure that 'Auditing' is set to 'On' | Shared | The customer is responsible for implementing this recommendation. | Enable auditing on SQL Servers. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 4.12 | CIS_Azure_1.1.0_4.12 | CIS Microsoft Azure Foundations Benchmark recommendation 4.12 | 4 Database Services | Ensure server parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_checkpoints' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 4.14 | CIS_Azure_1.1.0_4.14 | CIS Microsoft Azure Foundations Benchmark recommendation 4.14 | 4 Database Services | Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_connections' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 4.15 | CIS_Azure_1.1.0_4.15 | CIS Microsoft Azure Foundations Benchmark recommendation 4.15 | 4 Database Services | Ensure server parameter 'log_disconnections' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_disconnections' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 4.16 | CIS_Azure_1.1.0_4.16 | CIS Microsoft Azure Foundations Benchmark recommendation 4.16 | 4 Database Services | Ensure server parameter 'log_duration' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_duration' on 'PostgreSQL Servers'. | link | 4 | 
                    
                        | CIS_Azure_1.1.0 | 4.17 | CIS_Azure_1.1.0_4.17 | CIS Microsoft Azure Foundations Benchmark recommendation 4.17 | 4 Database Services | Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'connection_throttling' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 4.2 | CIS_Azure_1.1.0_4.2 | CIS Microsoft Azure Foundations Benchmark recommendation 4.2 | 4 Database Services | Ensure that 'AuditActionGroups' in 'auditing' policy for a SQL server is set properly | Shared | The customer is responsible for implementing this recommendation. | Configure the 'AuditActionGroups' property to appropriate groups to capture all the critical activities on the SQL Server and all the SQL databases hosted on the SQL server. | link | 5 | 
                    
                        | CIS_Azure_1.1.0 | 5.1.7 | CIS_Azure_1.1.0_5.1.7 | CIS Microsoft Azure Foundations Benchmark recommendation 5.1.7 | 5 Logging and Monitoring | Ensure that logging for Azure KeyVault is 'Enabled' | Shared | The customer is responsible for implementing this recommendation. | Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available. | link | 6 | 
                    
                        | CIS_Azure_1.3.0 | 3.10 | CIS_Azure_1.3.0_3.10 | CIS Microsoft Azure Foundations Benchmark recommendation 3.10 | 3 Storage Accounts | Ensure Storage logging is enabled for Blob service for read, write, and delete requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Blob service provides scalable, cost-efficient objective storage in the cloud. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the blobs. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 3.11 | CIS_Azure_1.3.0_3.11 | CIS Microsoft Azure Foundations Benchmark recommendation 3.11 | 3 Storage Accounts | Ensure Storage logging is enabled for Table service for read, write, and delete requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Table storage is a service that stores structure NoSQL data in the cloud, providing a key/attribute store with a schema less design. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the tables. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 3.3 | CIS_Azure_1.3.0_3.3 | CIS Microsoft Azure Foundations Benchmark recommendation 3.3 | 3 Storage Accounts | Ensure Storage logging is enabled for Queue service for read, write, and delete requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Queue service stores messages that may be read by any client who has access to the storage account. A queue can contain an unlimited number of messages, each of which can be up to 64KB in size using version 2011-08-18 or newer. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the queues. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 4.1.1 | CIS_Azure_1.3.0_4.1.1 | CIS Microsoft Azure Foundations Benchmark recommendation 4.1.1 | 4 Database Services | Ensure that 'Auditing' is set to 'On' | Shared | The customer is responsible for implementing this recommendation. | Enable auditing on SQL Servers. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 4.3.3 | CIS_Azure_1.3.0_4.3.3 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.3 | 4 Database Services | Ensure server parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_checkpoints' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 4.3.4 | CIS_Azure_1.3.0_4.3.4 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.4 | 4 Database Services | Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_connections' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 4.3.5 | CIS_Azure_1.3.0_4.3.5 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.5 | 4 Database Services | Ensure server parameter 'log_disconnections' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_disconnections' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 4.3.6 | CIS_Azure_1.3.0_4.3.6 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.6 | 4 Database Services | Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'connection_throttling' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 5.1.2 | CIS_Azure_1.3.0_5.1.2 | CIS Microsoft Azure Foundations Benchmark recommendation 5.1.2 | 5 Logging and Monitoring | Ensure Diagnostic Setting captures appropriate categories | Shared | The customer is responsible for implementing this recommendation. | The diagnostic setting should be configured to log the appropriate activities from the control/management plane. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 5.1.5 | CIS_Azure_1.3.0_5.1.5 | CIS Microsoft Azure Foundations Benchmark recommendation 5.1.5 | 5 Logging and Monitoring | Ensure that logging for Azure KeyVault is 'Enabled' | Shared | The customer is responsible for implementing this recommendation. | Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available. | link | 5 | 
                    
                        | CIS_Azure_1.3.0 | 5.3 | CIS_Azure_1.3.0_5.3 | CIS Microsoft Azure Foundations Benchmark recommendation 5.3 | 5 Logging and Monitoring | Ensure that Diagnostic Logs are enabled for all services which support it. | Shared | The customer is responsible for implementing this recommendation. | Diagnostic Logs capture activity to the data access plane while the Activity log is a subscription-level log for the control plane. Resource-level diagnostic logs provide insight into operations that were performed within that resource itself, for example, getting a secret from a Key Vault. Currently, 32 Azure resources support Diagnostic Logging (See the references section for a complete list), including Network Security Groups, Load Balancers, Key Vault, AD, Logic Apps and CosmosDB. The content of these logs varies by resource type. For example, Windows event system logs are a category of diagnostics logs 
for VMs, and blob, table, and queue logs are categories of diagnostics logs for storage accounts. 
A number of back-end services were not configured to log and store Diagnostic Logs for certain activities or for a sufficient length. It is crucial that logging systems are correctly configured to log all relevant activities and retain those logs for a sufficient length of time. By default, Diagnostic Logs are not enabled. Given that the mean time to detection in an enterprise is 240 days, a minimum retention period of two years is recommended. 
Note: The CIS Benchmark covers some specific Diagnostic Logs 
separately.
'''
 3.3 - Ensure Storage logging is enabled for Queue service for read, write, and delete requests
 6.4 Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'
''' | link | 20 | 
                    
                        | CIS_Azure_1.4.0 | 3.10 | CIS_Azure_1.4.0_3.10 | CIS Microsoft Azure Foundations Benchmark recommendation 3.10 | 3 Storage Accounts | Ensure Storage logging is Enabled for Blob Service for 'Read', 'Write', and 'Delete' requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Blob service provides scalable, cost-efficient objective storage in the cloud. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the blobs. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 3.11 | CIS_Azure_1.4.0_3.11 | CIS Microsoft Azure Foundations Benchmark recommendation 3.11 | 3 Storage Accounts | Ensure Storage Logging is Enabled for Table Service for 'Read', 'Write', and 'Delete' Requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Table storage is a service that stores structure NoSQL data in the cloud, providing a key/attribute store with a schema less design. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the tables. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 3.3 | CIS_Azure_1.4.0_3.3 | CIS Microsoft Azure Foundations Benchmark recommendation 3.3 | 3 Storage Accounts | Ensure Storage Logging is Enabled for Queue Service for 'Read', 'Write', and 'Delete' requests | Shared | The customer is responsible for implementing this recommendation. | The Storage Queue service stores messages that may be read by any client who has access to the storage account. A queue can contain an unlimited number of messages, each of which can be up to 64KB in size using version 2011-08-18 or newer. Storage Logging happens server-side and allows details for both successful and failed requests to be recorded in the storage account. These logs allow users to see the details of read, write, and delete operations against the queues. Storage Logging log entries contain the following information about individual requests: Timing information such as start time, end-to-end latency, and server latency, authentication details , concurrency information and the sizes of the request and response messages. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 4.1.1 | CIS_Azure_1.4.0_4.1.1 | CIS Microsoft Azure Foundations Benchmark recommendation 4.1.1 | 4 Database Services | Ensure that 'Auditing' is set to 'On' | Shared | The customer is responsible for implementing this recommendation. | Enable auditing on SQL Servers. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 4.3.2 | CIS_Azure_1.4.0_4.3.2 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.2 | 4 Database Services | Ensure Server Parameter 'log_checkpoints' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_checkpoints' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 4.3.3 | CIS_Azure_1.4.0_4.3.3 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.3 | 4 Database Services | Ensure server parameter 'log_connections' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_connections' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 4.3.4 | CIS_Azure_1.4.0_4.3.4 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.4 | 4 Database Services | Ensure server parameter 'log_disconnections' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'log_disconnections' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 4.3.5 | CIS_Azure_1.4.0_4.3.5 | CIS Microsoft Azure Foundations Benchmark recommendation 4.3.5 | 4 Database Services | Ensure server parameter 'connection_throttling' is set to 'ON' for PostgreSQL Database Server | Shared | The customer is responsible for implementing this recommendation. | Enable 'connection_throttling' on 'PostgreSQL Servers'. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 5.1.2 | CIS_Azure_1.4.0_5.1.2 | CIS Microsoft Azure Foundations Benchmark recommendation 5.1.2 | 5 Logging and Monitoring | Ensure Diagnostic Setting captures appropriate categories | Shared | The customer is responsible for implementing this recommendation. | The diagnostic setting should be configured to log the appropriate activities from the control/management plane. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 5.1.5 | CIS_Azure_1.4.0_5.1.5 | CIS Microsoft Azure Foundations Benchmark recommendation 5.1.5 | 5 Logging and Monitoring | Ensure that logging for Azure KeyVault is 'Enabled' | Shared | The customer is responsible for implementing this recommendation. | Enable AuditEvent logging for key vault instances to ensure interactions with key vaults are logged and available. | link | 5 | 
                    
                        | CIS_Azure_1.4.0 | 5.3 | CIS_Azure_1.4.0_5.3 | CIS Microsoft Azure Foundations Benchmark recommendation 5.3 | 5 Logging and Monitoring | Ensure that Diagnostic Logs Are Enabled for All Services that Support it. | Shared | The customer is responsible for implementing this recommendation. | Diagnostic Logs capture activity to the data access plane while the Activity log is a subscription-level log for the control plane. Resource-level diagnostic logs provide insight into operations that were performed within that resource itself, for example, getting a secret from a Key Vault. Currently, 32 Azure resources support Diagnostic Logging (See the references section for a complete list), including Network Security Groups, Load Balancers, Key Vault, AD, Logic Apps and CosmosDB. The content of these logs varies by resource type. For example, Windows event system logs are a category of diagnostics logs 
for VMs, and blob, table, and queue logs are categories of diagnostics logs for storage accounts. 
A number of back-end services were not configured to log and store Diagnostic Logs for certain activities or for a sufficient length. It is crucial that logging systems are correctly configured to log all relevant activities and retain those logs for a sufficient length of time. By default, Diagnostic Logs are not enabled. Given that the mean time to detection in an enterprise is 240 days, a minimum retention period of two years is recommended. 
Note: The CIS Benchmark covers some specific Diagnostic Logs 
separately.
'''
 3.3 - Ensure Storage logging is enabled for Queue service for read, write, and delete requests
 6.4 Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'
''' | link | 20 | 
                    
                        | FedRAMP_High_R4 | AU-12 | FedRAMP_High_R4_AU-12 | FedRAMP High AU-12 | Audit And Accountability | Audit Generation | Shared | n/a | The information system:
 a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Assignment: organization-defined information system components];
 b. Allows [Assignment: organization-defined personnel or roles] to select which auditable events are to be audited by specific components of the information system; and
 c.    Generates audit records for the events defined in AU-2 d. with the content defined in AU-3. 
Supplemental Guidance:  Audit records can be generated from many different information system components. The list of audited events is the set of events for which audits are to be generated. These events are typically a subset of all events for which the information system is capable of generating audit records. Related controls: AC-3, AU-2, AU-3, AU-6, AU-7.
References: None. | link | 34 | 
                    
                        | FedRAMP_High_R4 | AU-6 | FedRAMP_High_R4_AU-6 | FedRAMP High AU-6 | Audit And Accountability | Audit Review, Analysis, And Reporting | Shared | n/a | The organization:
 a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity]; and
 b. Reports findings to [Assignment: organization-defined personnel or roles].
Supplemental Guidance:  Audit review, analysis, and reporting covers information security-related auditing performed by organizations including, for example, auditing that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and nonlocal maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at the information system boundaries, use of mobile code, and use of VoIP. Findings can be reported to organizational entities that include, for example, incident response team, help desk, information security group/department. If organizations are prohibited from reviewing and analyzing audit information or unable to conduct such activities (e.g., in certain national security applications or systems), the review/analysis may be carried out by other organizations granted such authority. Related controls: AC-2, AC-3, AC-6, AC-17, AT-3, AU-7, AU-16, CA-7, CM-5, CM-10, CM-11, IA-3, IA-5, IR-5, IR-6, MA-4, MP-4, PE-3, PE-6, PE-14, PE-16, RA-5, SC-7, SC-18, SC-19, SI-3, SI-4, SI-7.
References: None. | link | 25 | 
                    
                        | FedRAMP_High_R4 | AU-6(1) | FedRAMP_High_R4_AU-6(1) | FedRAMP High AU-6 (1) | Audit And Accountability | Process Integration | Shared | n/a | The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.
Supplemental Guidance:  Organizational processes benefiting from integrated audit review, analysis, and reporting include, for example, incident response, continuous monitoring, contingency planning, and Inspector General audits. Related controls: AU-12, PM-7. | link | 11 | 
                    
                        | FedRAMP_High_R4 | RA-5(8) | FedRAMP_High_R4_RA-5(8) | FedRAMP High RA-5 (8) | Risk Assessment | Review Historic Audit Logs | Shared | n/a | The organization reviews historic audit logs to determine if a vulnerability identified in the information system has been previously exploited.
Supplemental Guidance:  Related control: AU-6. | link | 15 | 
                    
                        | FedRAMP_Moderate_R4 | AU-12 | FedRAMP_Moderate_R4_AU-12 | FedRAMP Moderate AU-12 | Audit And Accountability | Audit Generation | Shared | n/a | The information system:
 a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Assignment: organization-defined information system components];
 b. Allows [Assignment: organization-defined personnel or roles] to select which auditable events are to be audited by specific components of the information system; and
 c.    Generates audit records for the events defined in AU-2 d. with the content defined in AU-3. 
Supplemental Guidance:  Audit records can be generated from many different information system components. The list of audited events is the set of events for which audits are to be generated. These events are typically a subset of all events for which the information system is capable of generating audit records. Related controls: AC-3, AU-2, AU-3, AU-6, AU-7.
References: None. | link | 34 | 
                    
                        | FedRAMP_Moderate_R4 | AU-6 | FedRAMP_Moderate_R4_AU-6 | FedRAMP Moderate AU-6 | Audit And Accountability | Audit Review, Analysis, And Reporting | Shared | n/a | The organization:
 a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity]; and
 b. Reports findings to [Assignment: organization-defined personnel or roles].
Supplemental Guidance:  Audit review, analysis, and reporting covers information security-related auditing performed by organizations including, for example, auditing that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and nonlocal maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at the information system boundaries, use of mobile code, and use of VoIP. Findings can be reported to organizational entities that include, for example, incident response team, help desk, information security group/department. If organizations are prohibited from reviewing and analyzing audit information or unable to conduct such activities (e.g., in certain national security applications or systems), the review/analysis may be carried out by other organizations granted such authority. Related controls: AC-2, AC-3, AC-6, AC-17, AT-3, AU-7, AU-16, CA-7, CM-5, CM-10, CM-11, IA-3, IA-5, IR-5, IR-6, MA-4, MP-4, PE-3, PE-6, PE-14, PE-16, RA-5, SC-7, SC-18, SC-19, SI-3, SI-4, SI-7.
References: None. | link | 25 | 
                    
                        | FedRAMP_Moderate_R4 | AU-6(1) | FedRAMP_Moderate_R4_AU-6(1) | FedRAMP Moderate AU-6 (1) | Audit And Accountability | Process Integration | Shared | n/a | The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.
Supplemental Guidance:  Organizational processes benefiting from integrated audit review, analysis, and reporting include, for example, incident response, continuous monitoring, contingency planning, and Inspector General audits. Related controls: AU-12, PM-7. | link | 11 | 
                    
                        | FedRAMP_Moderate_R4 | RA-5(8) | FedRAMP_Moderate_R4_RA-5(8) | FedRAMP Moderate RA-5 (8) | Risk Assessment | Review Historic Audit Logs | Shared | n/a | The organization reviews historic audit logs to determine if a vulnerability identified in the information system has been previously exploited.
Supplemental Guidance:  Related control: AU-6. | link | 15 | 
                    
                        | hipaa | 0202.09j1Organizational.3-09.j | hipaa-0202.09j1Organizational.3-09.j | 0202.09j1Organizational.3-09.j | 02 Endpoint Protection | 0202.09j1Organizational.3-09.j 09.04 Protection Against Malicious and Mobile Code | Shared | n/a | Audit logs of the scans are maintained. |  | 15 | 
                    
                        | hipaa | 0216.09j2Organizational.9-09.j | hipaa-0216.09j2Organizational.9-09.j | 0216.09j2Organizational.9-09.j | 02 Endpoint Protection | 0216.09j2Organizational.9-09.j 09.04 Protection Against Malicious and Mobile Code | Shared | n/a | For systems considered not commonly affected by malicious software, the organization performs periodic assessments to identify and evaluate evolving malware threats to confirm whether such systems continue to not require anti-virus software. |  | 13 | 
                    
                        | hipaa | 0217.09j2Organizational.10-09.j | hipaa-0217.09j2Organizational.10-09.j | 0217.09j2Organizational.10-09.j | 02 Endpoint Protection | 0217.09j2Organizational.10-09.j 09.04 Protection Against Malicious and Mobile Code | Shared | n/a | The organization configures malicious code and spam protection mechanisms to (i) perform periodic scans of the information system according to organization guidelines; (ii) perform real-time scans of files from external sources at endpoints and network entry/exit points as the files are downloaded, opened, or executed in accordance with organizational security policy; and, (iii) block malicious code, quarantine malicious code, or send an alert to the administrator in response to malicious code detection. |  | 25 | 
                    
                        | hipaa | 0663.10h1System.7-10.h | hipaa-0663.10h1System.7-10.h | 0663.10h1System.7-10.h | 06 Configuration Management | 0663.10h1System.7-10.h 10.04 Security of System Files | Shared | n/a | The operating system has in place supporting technical controls such as antivirus, file integrity monitoring, host-based (personal) firewalls or port filtering tools, and logging as part of its baseline. |  | 16 | 
                    
                        | hipaa | 0714.10m2Organizational.7-10.m | hipaa-0714.10m2Organizational.7-10.m | 0714.10m2Organizational.7-10.m | 07 Vulnerability Management | 0714.10m2Organizational.7-10.m 10.06 Technical Vulnerability Management | Shared | n/a | The technical vulnerability management program is evaluated on a quarterly basis. |  | 19 | 
                    
                        | hipaa | 0790.10m3Organizational.22-10.m | hipaa-0790.10m3Organizational.22-10.m | 0790.10m3Organizational.22-10.m | 07 Vulnerability Management | 0790.10m3Organizational.22-10.m 10.06 Technical Vulnerability Management | Shared | n/a | The organization reviews historic audit logs to determine if high vulnerability scan findings identified in the information system have been previously exploited. |  | 17 | 
                    
                        | hipaa | 1207.09aa2System.4-09.aa | hipaa-1207.09aa2System.4-09.aa | 1207.09aa2System.4-09.aa | 12 Audit Logging & Monitoring | 1207.09aa2System.4-09.aa 09.10 Monitoring | Shared | n/a | Audit records are retained for 90 days and older audit records are archived for one year. |  | 13 | 
                    
                        | hipaa | 1210.09aa3System.3-09.aa | hipaa-1210.09aa3System.3-09.aa | 1210.09aa3System.3-09.aa | 12 Audit Logging & Monitoring | 1210.09aa3System.3-09.aa 09.10 Monitoring | Shared | n/a | All disclosures of covered information within or outside of the organization are logged including type of disclosure, date/time of the event, recipient, and sender. |  | 11 | 
                    
                        | hipaa | 12101.09ab1Organizational.3-09.ab | hipaa-12101.09ab1Organizational.3-09.ab | 12101.09ab1Organizational.3-09.ab | 12 Audit Logging & Monitoring | 12101.09ab1Organizational.3-09.ab 09.10 Monitoring | Shared | n/a | The organization specifies how often audit logs are reviewed, how the reviews are documented, and the specific roles and responsibilities of the personnel conducting the reviews, including the professional certifications or other qualifications required. |  | 18 | 
                    
                        | hipaa | 12103.09ab1Organizational.5-09.ab | hipaa-12103.09ab1Organizational.5-09.ab | 12103.09ab1Organizational.5-09.ab | 12 Audit Logging & Monitoring | 12103.09ab1Organizational.5-09.ab 09.10 Monitoring | Shared | n/a | Information collected from multiple sources is aggregated for review. |  | 11 | 
                    
                        | hipaa | 1216.09ab3System.12-09.ab | hipaa-1216.09ab3System.12-09.ab | 1216.09ab3System.12-09.ab | 12 Audit Logging & Monitoring | 1216.09ab3System.12-09.ab 09.10 Monitoring | Shared | n/a | Automated systems are used to review monitoring activities of security systems (e.g., IPS/IDS) and system records on a daily basis, and identify and document anomalies. |  | 20 | 
                    
                        | hipaa | 1230.09c2Organizational.1-09.c | hipaa-1230.09c2Organizational.1-09.c | 1230.09c2Organizational.1-09.c | 12 Audit Logging & Monitoring | 1230.09c2Organizational.1-09.c 09.01 Documented Operating Procedures | Shared | n/a | No single person is able to access, modify, or use information systems without authorization or detection. |  | 13 | 
                    
                        | hipaa | 1270.09ad1System.12-09.ad | hipaa-1270.09ad1System.12-09.ad | 1270.09ad1System.12-09.ad | 12 Audit Logging & Monitoring | 1270.09ad1System.12-09.ad 09.10 Monitoring | Shared | n/a | The organization ensures proper logging is enabled in order to audit administrator activities; and reviews system administrator and operator logs on a regular basis. |  | 18 | 
                    
                        | hipaa | 1512.11a2Organizational.8-11.a | hipaa-1512.11a2Organizational.8-11.a | 1512.11a2Organizational.8-11.a | 15 Incident Management | 1512.11a2Organizational.8-11.a 11.01 Reporting Information Security Incidents and Weaknesses | Shared | n/a | Intrusion detection/information protection system (IDS/IPS) alerts are utilized for reporting information security events. |  | 17 | 
                    
                        | hipaa | 1519.11c2Organizational.2-11.c | hipaa-1519.11c2Organizational.2-11.c | 1519.11c2Organizational.2-11.c | 15 Incident Management | 1519.11c2Organizational.2-11.c 11.02 Management of Information Security Incidents and Improvements | Shared | n/a | For unauthorized disclosures of covered information, a log is maintained and annually submitted to the appropriate parties (e.g., a state, regional or national regulatory agency). |  | 14 | 
                    
                        | ISO27001-2013 | A.12.4.1 | ISO27001-2013_A.12.4.1 | ISO 27001:2013 A.12.4.1 | Operations Security | Event Logging | Shared | n/a | Event logs recording user activities, exceptions, faults and information security events shall be produced, kept and regularly reviewed. | link | 51 | 
                    
                        | ISO27001-2013 | A.12.4.3 | ISO27001-2013_A.12.4.3 | ISO 27001:2013 A.12.4.3 | Operations Security | Administrator and operator logs | Shared | n/a | System administrator and system operator activities shall be logged and the logs protected and regularly reviewed. | link | 27 | 
                    
                        | ISO27001-2013 | A.16.1.2 | ISO27001-2013_A.16.1.2 | ISO 27001:2013 A.16.1.2 | Information Security Incident Management | Reporting information security events | Shared | n/a | Information security events shall be reported through appropriate management channels as quickly as possible. | link | 14 | 
                    
                        | ISO27001-2013 | A.16.1.4 | ISO27001-2013_A.16.1.4 | ISO 27001:2013 A.16.1.4 | Information Security Incident Management | Assessment of and decision on information security events | Shared | n/a | Information security events shall be assessed and it shall be decided if they are to be classified as information security incidents. | link | 23 | 
                    
                        |  | mp.eq.3 Protection of portable devices | mp.eq.3 Protection of portable devices | 404 not found |  |  |  | n/a | n/a |  | 71 | 
                    
                        | NIST_SP_800-171_R2_3 | .3.1 | NIST_SP_800-171_R2_3.3.1 | NIST SP 800-171 R2 3.3.1 | Audit and Accountability | Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity | Shared | Microsoft and the customer share responsibilities for implementing this requirement. | An event is any observable occurrence in a system, which includes unlawful or unauthorized system activity. Organizations identify event types for which a logging functionality is needed as those events which are significant and relevant to the security of systems and the environments in which those systems operate to meet specific and ongoing auditing needs. Event types can include password changes, failed logons or failed accesses related to systems, administrative privilege usage, or third-party credential usage. In determining event types that require logging, organizations consider the monitoring and auditing appropriate for each of the CUI security requirements. Monitoring and auditing requirements can be balanced with other system needs. For example, organizations may determine that systems must have the capability to log every file access both successful and unsuccessful, but not activate that capability except for specific circumstances due to the potential burden on system performance.  Audit records can be generated at various levels of abstraction, including at the packet level as information traverses the network. Selecting the appropriate level of abstraction is a critical aspect of an audit logging capability and can facilitate the identification of root causes to problems. Organizations consider in the definition of event types, the logging necessary to cover related events such as the steps in distributed, transaction-based processes (e.g., processes that are distributed across multiple organizations) and actions that occur in service-oriented or cloud-based architectures.  Audit record content that may be necessary to satisfy this requirement includes time stamps, source and destination addresses, user or process identifiers, event descriptions, success or fail indications, filenames involved, and access control or flow control rules invoked. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the system after the event occurred).  Detailed information that organizations may consider in audit records includes full text recording of privileged commands or the individual identities of group account users. Organizations consider limiting the additional audit log information to only that information explicitly needed for specific audit requirements. This facilitates the use of audit trails and audit logs by not including information that could potentially be misleading or could make it more difficult to locate information of interest. Audit logs are reviewed and analyzed as often as needed to provide important information to organizations to facilitate risk-based decision making.  [SP 800-92] provides guidance on security log management. | link | 48 | 
                    
                        | NIST_SP_800-171_R2_3 | .3.6 | NIST_SP_800-171_R2_3.3.6 | NIST SP 800-171 R2 3.3.6 | Audit and Accountability | Provide audit record reduction and report generation to support on-demand analysis and reporting. | Shared | Microsoft and the customer share responsibilities for implementing this requirement. | Audit record reduction is a process that manipulates collected audit information and organizes such information in a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not always emanate from the same system or organizational entities conducting auditing activities. Audit record reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the system can help generate customizable reports. Time ordering of audit records can be a significant issue if the granularity of the time stamp in the record is insufficient. | link | 7 | 
                    
                        | NIST_SP_800-53_R4 | AU-12 | NIST_SP_800-53_R4_AU-12 | NIST SP 800-53 Rev. 4 AU-12 | Audit And Accountability | Audit Generation | Shared | n/a | The information system:
 a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Assignment: organization-defined information system components];
 b. Allows [Assignment: organization-defined personnel or roles] to select which auditable events are to be audited by specific components of the information system; and
 c.    Generates audit records for the events defined in AU-2 d. with the content defined in AU-3. 
Supplemental Guidance:  Audit records can be generated from many different information system components. The list of audited events is the set of events for which audits are to be generated. These events are typically a subset of all events for which the information system is capable of generating audit records. Related controls: AC-3, AU-2, AU-3, AU-6, AU-7.
References: None. | link | 34 | 
                    
                        | NIST_SP_800-53_R4 | AU-6 | NIST_SP_800-53_R4_AU-6 | NIST SP 800-53 Rev. 4 AU-6 | Audit And Accountability | Audit Review, Analysis, And Reporting | Shared | n/a | The organization:
 a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity]; and
 b. Reports findings to [Assignment: organization-defined personnel or roles].
Supplemental Guidance:  Audit review, analysis, and reporting covers information security-related auditing performed by organizations including, for example, auditing that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and nonlocal maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at the information system boundaries, use of mobile code, and use of VoIP. Findings can be reported to organizational entities that include, for example, incident response team, help desk, information security group/department. If organizations are prohibited from reviewing and analyzing audit information or unable to conduct such activities (e.g., in certain national security applications or systems), the review/analysis may be carried out by other organizations granted such authority. Related controls: AC-2, AC-3, AC-6, AC-17, AT-3, AU-7, AU-16, CA-7, CM-5, CM-10, CM-11, IA-3, IA-5, IR-5, IR-6, MA-4, MP-4, PE-3, PE-6, PE-14, PE-16, RA-5, SC-7, SC-18, SC-19, SI-3, SI-4, SI-7.
References: None. | link | 25 | 
                    
                        | NIST_SP_800-53_R4 | AU-6(1) | NIST_SP_800-53_R4_AU-6(1) | NIST SP 800-53 Rev. 4 AU-6 (1) | Audit And Accountability | Process Integration | Shared | n/a | The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.
Supplemental Guidance:  Organizational processes benefiting from integrated audit review, analysis, and reporting include, for example, incident response, continuous monitoring, contingency planning, and Inspector General audits. Related controls: AU-12, PM-7. | link | 11 | 
                    
                        | NIST_SP_800-53_R4 | RA-5(8) | NIST_SP_800-53_R4_RA-5(8) | NIST SP 800-53 Rev. 4 RA-5 (8) | Risk Assessment | Review Historic Audit Logs | Shared | n/a | The organization reviews historic audit logs to determine if a vulnerability identified in the information system has been previously exploited.
Supplemental Guidance:  Related control: AU-6. | link | 15 | 
                    
                        | NIST_SP_800-53_R5 | AU-12 | NIST_SP_800-53_R5_AU-12 | NIST SP 800-53 Rev. 5 AU-12 | Audit and Accountability | Audit Record Generation | Shared | n/a | a. Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [Assignment: organization-defined system components];
 b. Allow [Assignment: organization-defined personnel or roles] to select the event types that are to be logged by specific components of the system; and
 c. Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3). | link | 34 | 
                    
                        | NIST_SP_800-53_R5 | AU-6 | NIST_SP_800-53_R5_AU-6 | NIST SP 800-53 Rev. 5 AU-6 | Audit and Accountability | Audit Record Review, Analysis, and Reporting | Shared | n/a | a. Review and analyze system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity;
 b. Report findings to [Assignment: organization-defined personnel or roles]; and
 c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information. | link | 25 | 
                    
                        | NIST_SP_800-53_R5 | AU-6(1) | NIST_SP_800-53_R5_AU-6(1) | NIST SP 800-53 Rev. 5 AU-6 (1) | Audit and Accountability | Automated Process Integration | Shared | n/a | Integrate audit record review, analysis, and reporting processes using [Assignment: organization-defined automated mechanisms]. | link | 11 | 
                    
                        | NIST_SP_800-53_R5 | RA-5(8) | NIST_SP_800-53_R5_RA-5(8) | NIST SP 800-53 Rev. 5 RA-5 (8) | Risk Assessment | Review Historic Audit Logs | Shared | n/a | Review historic audit logs to determine if a vulnerability identified in a [Assignment: organization-defined system] has been previously exploited within an [Assignment: organization-defined time period]. | link | 15 | 
                    
                        |  | op.exp.7 Incident management | op.exp.7 Incident management | 404 not found |  |  |  | n/a | n/a |  | 103 | 
                    
                        |  | op.exp.8 Recording of the activity | op.exp.8 Recording of the activity | 404 not found |  |  |  | n/a | n/a |  | 65 | 
                    
                        |  | op.exp.9 Incident management record | op.exp.9 Incident management record | 404 not found |  |  |  | n/a | n/a |  | 30 | 
                    
                        |  | org.2 Security regulations | org.2 Security regulations | 404 not found |  |  |  | n/a | n/a |  | 100 | 
                    
                        | PCI_DSS_v4.0 | 10.2.1 | PCI_DSS_v4.0_10.2.1 | PCI DSS v4.0 10.2.1 | Requirement 10: Log and Monitor All Access to System Components and Cardholder Data | Audit logs are implemented to support the detection of anomalies and suspicious activity, and the forensic analysis of events | Shared | n/a | Audit logs are enabled and active for all system components and cardholder data. | link | 4 | 
                    
                        | PCI_DSS_v4.0 | 10.4.1 | PCI_DSS_v4.0_10.4.1 | PCI DSS v4.0 10.4.1 | Requirement 10: Log and Monitor All Access to System Components and Cardholder Data | Audit logs are reviewed to identify anomalies or suspicious activity | Shared | n/a | The following audit logs are reviewed at least once daily:
• All security events.
• Logs of all system components that store, process, or transmit CHD and/or SAD.
• Logs of all critical system components.
• Logs of all servers and system components that perform security functions (for example, network security controls, intrusion-detection systems/intrusion-prevention systems (IDS/IPS), authentication servers). | link | 11 | 
                    
                        | PCI_DSS_v4.0 | 10.4.1.1 | PCI_DSS_v4.0_10.4.1.1 | PCI DSS v4.0 10.4.1.1 | Requirement 10: Log and Monitor All Access to System Components and Cardholder Data | Audit logs are reviewed to identify anomalies or suspicious activity | Shared | n/a | Automated mechanisms are used to perform audit log reviews. | link | 11 | 
                    
                        | PCI_DSS_v4.0 | 10.4.2 | PCI_DSS_v4.0_10.4.2 | PCI DSS v4.0 10.4.2 | Requirement 10: Log and Monitor All Access to System Components and Cardholder Data | Audit logs are reviewed to identify anomalies or suspicious activity | Shared | n/a | Logs of all other system components (those not specified in Requirement 10.4.1) are reviewed periodically. | link | 11 | 
                    
                        | PCI_DSS_v4.0 | 10.4.2.1 | PCI_DSS_v4.0_10.4.2.1 | PCI DSS v4.0 10.4.2.1 | Requirement 10: Log and Monitor All Access to System Components and Cardholder Data | Audit logs are reviewed to identify anomalies or suspicious activity | Shared | n/a | The frequency of periodic log reviews for all other system components (not defined in Requirement 10.4.1) is defined in the entity’s targeted risk analysis, which is performed according to all elements specified in Requirement12.3.1 | link | 11 | 
                    
                        | PCI_DSS_v4.0 | 10.4.3 | PCI_DSS_v4.0_10.4.3 | PCI DSS v4.0 10.4.3 | Requirement 10: Log and Monitor All Access to System Components and Cardholder Data | Audit logs are reviewed to identify anomalies or suspicious activity | Shared | n/a | Exceptions and anomalies identified during the review process are addressed. | link | 11 | 
                    
                        | SWIFT_CSCF_v2022 | 6.1 | SWIFT_CSCF_v2022_6.1 | SWIFT CSCF v2022 6.1 | 6. Detect Anomalous Activity to Systems or Transaction Records | Ensure that local SWIFT infrastructure is protected against malware and act upon results. | Shared | n/a | Anti-malware software from a reputable vendor is installed, kept up-to-date on all systems, and results are considered for appropriate resolving actions. | link | 29 | 
                    
                        | SWIFT_CSCF_v2022 | 6.4 | SWIFT_CSCF_v2022_6.4 | SWIFT CSCF v2022 6.4 | 6. Detect Anomalous Activity to Systems or Transaction Records | Record security events and detect anomalous actions and operations within the local SWIFT environment. | Shared | n/a | Capabilities to detect anomalous activity are implemented, and a process or tool is in place to keep and review logs. | link | 47 |