last sync: 2024-Sep-18 17:50:24 UTC

Microsoft Managed Control 1589 - External Information System Services | Risk Assessments / Organizational Approvals | Regulatory Compliance - System and Services Acquisition

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1589 - External Information System Services | Risk Assessments / Organizational Approvals
Id 86ec7f9b-9478-40ff-8cfd-6a0d510081a8
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this System and Services Acquisition control
Additional metadata Name/Id: ACF1589 / Microsoft Managed Control 1589
Category: System and Services Acquisition
Title: External Information System Services | Risk Assessments / Organizational Approvals - Conduct Risk Assessment
Ownership: Customer, Microsoft
Description: The organization: Conducts an organizational assessment of risk prior to the acquisition or outsourcing of dedicated information security services; and
Requirements: Azure does not consider any information security services to be outsourced as they are defined in the supplemental guidance for the requirement. If any services were to be outsourced after receiving an ATO, Azure Security would complete an assessment of risk and follow change management processes.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance
The following 1 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1589 - External Information System Services | Risk Assessments / Organizational Approvals' (86ec7f9b-9478-40ff-8cfd-6a0d510081a8)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
op.pl.1 Risk analysis op.pl.1 Risk analysis 404 not found n/a n/a 70
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
Spain ENS 175daf90-21e1-4fec-b745-7b4c909aa94c Regulatory Compliance GA BuiltIn
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC