Skip to main content

Appendix: MCSB reference

TOdo: Complete

Control DomainDescription
Network Security (NS)Network Security covers controls to secure and protect networks, including securing virtual networks, establishing private connections, preventing and mitigating external attacks, and securing Domain Name System (DNS).
Identity Management (IM)Identity Management covers controls to establish secure identity and access controls using identity and access management systems, including the use of single sign-on, strong authentication, managed identities (and service principals) for applications, conditional access, and account anomalies monitoring.
Privileged Access (PA)Privileged Access covers controls to protect privileged access to your tenant and resources, including a range of controls to protect your administrative model, administrative accounts, and privileged access workstations against deliberate and inadvertent risk.
Data Protection (DP)Data Protection covers control of data protection at rest, in transit, and via authorized access mechanisms, including discovering, classifying, protecting, and monitoring sensitive data assets using access control, encryption, key management, and certificate management.
Asset Management (AM)Asset Management covers controls to ensure security visibility and governance over your resources, including recommendations on permissions for security personnel, security access to asset inventory, and managing approvals for services and resources (inventory, track, and correct).
Logging and Threat Detection (LT)Logging and Threat Detection covers controls for detecting threats on the cloud and enabling, collecting, and storing audit logs for cloud services, including enabling detection, investigation, and remediation processes with controls to generate high-quality alerts with native threat detection in cloud services. It also includes collecting logs with a cloud monitoring service, centralizing security analysis with a Security Event Management (SEM) solution, time synchronization, and log retention.
Incident Response (IR)Incident Response covers controls in the incident response lifecycle, including preparation, detection and analysis, containment, and post-incident activities. This includes using Azure services (such as Microsoft Defender for Cloud and Microsoft Sentinel) and/or other cloud services to automate the incident response process.
Posture and Vulnerability Management (PV)Posture and Vulnerability Management focuses on controls for assessing and improving cloud security posture, including vulnerability scanning, penetration testing, remediation, security configuration tracking, reporting, and correction in cloud resources.
Endpoint Security (ES)Endpoint Security covers controls in endpoint detection and response, including the use of Endpoint Detection and Response (EDR) and anti-malware services for endpoints in cloud environments.
Backup and Recovery (BR)Backup and Recovery covers controls to ensure that data and configuration backups at the different service tiers are performed, validated, and protected.
DevOps Security (DS)DevOps Security covers controls related to security engineering and operations in DevOps processes, including deployment of critical security checks (such as static application security testing and vulnerability management) before deployment to ensure security throughout the DevOps process. It also includes common practices such as threat modeling and software supply chain security.
Governance and Strategy (GS)Governance and Strategy provide guidance for ensuring a coherent security strategy and documented governance approach to guide and sustain security assurance, including establishing roles and responsibilities for different cloud security functions, a unified technical strategy, and supporting policies and standards.