last sync: 2024-Sep-19 17:51:32 UTC

Microsoft Managed Control 1638 - Boundary Protection | Dynamic Isolation / Segregation | Regulatory Compliance - System and Communications Protection

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1638 - Boundary Protection | Dynamic Isolation / Segregation
Id 49b99653-32cd-405d-a135-e7d60a9aae1f
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this System and Communications Protection control
Additional metadata Name/Id: ACF1638 / Microsoft Managed Control 1638
Category: System and Communications Protection
Title: Boundary Protection | Dynamic Isolation / Segregation
Ownership: Customer, Microsoft
Description: The information system provides the capability to dynamically isolate/segregate Servers and network devices from other components of the system.
Requirements: Azure personnel have the capability to isolate or segregate Azure assets by various means, including but not limited to: * Physical network disconnection * Removal from load balancer rotation * VLAN, NSG, and ACL isolation Any of these actions can be performed in real time by the appropriate service team or Security Response Team as required.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC