last sync: 2025-Apr-29 17:16:02 UTC

Microsoft Managed Control 1161 - Continuous Monitoring | Regulatory Compliance - Security Assessment and Authorization

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1161 - Continuous Monitoring
Id e2f8f6c6-dde4-436b-a79d-bc50e129eb3a
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Security Assessment and Authorization control
Cloud environments AzureCloud = true
AzureUSGovernment = true
AzureChinaCloud = unknown
Available in AzUSGov The Policy is available in AzureUSGovernment cloud. Version: '1.0.0'
Repository: Azure-Policy e2f8f6c6-dde4-436b-a79d-bc50e129eb3a
Additional metadata Name/Id: ACF1161 / Microsoft Managed Control 1161
Category: Security Assessment and Authorization
Title: Continuous Monitoring - Metrics Monitored
Ownership: Customer, Microsoft
Description: The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes: Establishment of Rate of closure/remediation of POA&Ms and high vulnerabilities to be monitored;
Requirements: As part of the configuration management process, a Security Impact Analysis (SIA) and Business Impact Analysis (BIA) are performed on Azure for all changes. Deficiencies to the system are documented in the SSP and SAR that are included in the Security Authorization Package. As part of continuous monitoring, Azure documents such as the SSP, SAR and POA&M are updated to reflect any newly identified or remediated security issues. Additionally, Azure tracks through closure all vulnerabilities identified using the vulnerability scanning processes described in RA-05.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Compliance
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1161 - Continuous Monitoring' (e2f8f6c6-dde4-436b-a79d-bc50e129eb3a)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
NIS2 BR._Backup_and_Recovery_3 NIS2_BR._Backup_and_Recovery_3 NIS2_BR._Backup_and_Recovery_3 BR. Backup and Recovery Business continuity and crisis management n/a Directive (EU) 2016/1148 of the European Parliament and the Council (4) aimed to build cybersecurity capabilities across the Union, mitigate threats to network and information systems used to provide essential services in key sectors and ensure the continuity of such services when facing incidents, thus contributing to the Union’s security and to the effective functioning of its economy and society. 25
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type polSet in AzUSGov
[Preview]: NIS2 32ff9e30-4725-4ca7-ba3a-904a7721ee87 Regulatory Compliance Preview BuiltIn unknown
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC