last sync: 2024-Nov-25 18:54:24 UTC

Microsoft Managed Control 1511 - Personnel Screening | Regulatory Compliance - Personnel Security

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1511 - Personnel Screening
Id a9eae324-d327-4539-9293-b48e122465f8
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Personnel Security control
Additional metadata Name/Id: ACF1511 / Microsoft Managed Control 1511
Category: Personnel Security
Title: Personnel Screening - Access Authorization
Ownership: Customer, Microsoft
Description: The organization: Screens individuals prior to authorizing access to the information system; and
Requirements: The Microsoft Security department conducts background checks and enforces the screening policies for all personnel. Background checks in the form of the Microsoft Cloud Screen are required for new hires or personnel transferring to positions that involve access to customers’ work sites and/or sensitive areas, including access to customer PII. The Microsoft Cloud Screen includes the following: * Employment history check for the previous seven years * Education Check (highest degree obtained) * Social Security Number (SSN) Check * Criminal History Check for the previous seven years * Office of Foreign Assets Control List (OFAC) Check * Bureau of Industry and Security List (BIS) Check * Office of Defense Trade Controls Debarred Persons List Check Vendor staff with access to customer data are required to sign a background screening addendum with Microsoft. Microsoft managers are required to include screening verbiage in their respective SOWs with vendors.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC