Source | Azure Portal | ||||||||||||||||||||||
Display name | Microsoft Managed Control 1367 - Incident Handling | Insider Threats - Specific Capabilities | ||||||||||||||||||||||
Id | 435b2547-6374-4f87-b42d-6e8dbe6ae62a | ||||||||||||||||||||||
Version | 1.0.0 Details on versioning |
||||||||||||||||||||||
Versioning |
Versions supported for Versioning: 0 Built-in Versioning [Preview] |
||||||||||||||||||||||
Category | Regulatory Compliance Microsoft Learn |
||||||||||||||||||||||
Description | Microsoft implements this Incident Response control | ||||||||||||||||||||||
Additional metadata |
Name/Id: ACF1367 / Microsoft Managed Control 1367 Category: Incident Response Title: Incident Handling | Insider Threats - Specific Capabilities Ownership: Customer, Microsoft Description: The organization implements incident handling capability for insider threats. Requirements: The Incident Management SOP describes the incident handling process for all incidents, including incidents generated by insider threats. Azure Security may engage the Microsoft personnel investigations team to provide support and guidance on forensic investigations when the scope of investigation includes personnel working at Microsoft. Once an incident is identified as suspected insider threat, the Security Incident Manager notifies the Office of Legal Compliance (OLC). Additionally, Azure Security may engage the Microsoft Corporate Security team to provide support and guidance on forensic investigations when the scope of investigation includes personnel working at Microsoft to include CorpNet information. |
||||||||||||||||||||||
Mode | Indexed | ||||||||||||||||||||||
Type | Static | ||||||||||||||||||||||
Preview | False | ||||||||||||||||||||||
Deprecated | False | ||||||||||||||||||||||
Effect | Fixed audit |
||||||||||||||||||||||
RBAC role(s) | none | ||||||||||||||||||||||
Rule aliases | none | ||||||||||||||||||||||
Rule resource types | IF (2) Microsoft.Resources/subscriptions Microsoft.Resources/subscriptions/resourceGroups |
||||||||||||||||||||||
Compliance |
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1367 - Incident Handling | Insider Threats - Specific Capabilities' (435b2547-6374-4f87-b42d-6e8dbe6ae62a)
| ||||||||||||||||||||||
Initiatives usage |
|
||||||||||||||||||||||
History | none | ||||||||||||||||||||||
JSON compare | n/a | ||||||||||||||||||||||
JSON |
|