last sync: 2025-Apr-29 17:16:02 UTC

Microsoft Managed Control 1529 - Third-Party Personnel Security | Regulatory Compliance - Personnel Security

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1529 - Third-Party Personnel Security
Id d74fdc92-1cb8-4a34-9978-8556425cd14c
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Personnel Security control
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '1.0.0'
Repository: Azure-Policy d74fdc92-1cb8-4a34-9978-8556425cd14c
Additional metadata Name/Id: ACF1529 / Microsoft Managed Control 1529
Category: Personnel Security
Title: Third-Party Personnel Security - Establish Security Requirements for Third-Party Providers
Ownership: Customer, Microsoft
Description: The organization: Establishes personnel security requirements including security roles and responsibilities for third-party providers;
Requirements: Personnel security requirements, including security roles and responsibilities for third-party providers, are established by requiring them to comply with the Microsoft Information Security Policy. This includes personnel located at Microsoft subsidiaries and locations not owned by Microsoft, such as off-site facilities. Any third-party personnel with access to Azure must pass the same personnel screening process for the requirements established for the risk categorization of their role. In all contracts, Microsoft includes provisions to ensure that third-party providers meet or exceed the personnel security requirements mandated by Microsoft. This includes the ability to successfully pass the Microsoft background check, or equivalent, as well as obtain and maintain additional clearances if the specific project requires it. Third-party providers that have access to the are subject to the same personnel screening requirements as Microsoft personnel working on Azure services for U.S. Government customers, including Federal background investigations. Vendors and subcontractors that require logical access to Federal customer data, or physical access to controlled facilities that house Federal customer data (other than on an occasional or intermittent basis) for the Azure service are required to successfully complete Federal adjudicated background investigations. Should a vendor or subcontractor require physical access to controlled facilities that contain customer data, a cleared/authorized individual is provided as an escort and must accompany the vendor or subcontractor at all times while in the secured location.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Compliance
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1529 - Third-Party Personnel Security' (d74fdc92-1cb8-4a34-9978-8556425cd14c)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
NIS2 LT._Logging_and_Threat_Detection_1 NIS2_LT._Logging_and_Threat_Detection_1 NIS2_LT._Logging_and_Threat_Detection_1 LT. Logging and Threat Detection Risk analysis & information system security policies n/a Responsibility for ensuring the security of network and information system lies, to a great extent, with essential and important entities. A culture of risk management, involving risk assessments and the implementation of cybersecurity risk-management measures appropriate to the risks faced, should be promoted and developed. In order to avoid imposing a disproportionate financial and administrative burden on essential and important entities, the cybersecurity risk-management measures should be proportionate to the risks posed to the network and information system concerned, taking into account the state-of-the-art of such measures, and, where applicable, relevant European and international standards, as well as the cost for their implementation. 24
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
[Preview]: NIS2 32ff9e30-4725-4ca7-ba3a-904a7721ee87 Regulatory Compliance Preview BuiltIn unknown
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC