Back to Frameworks

Azure Security Benchmark

International
vAzure Security Benchmark v3.0
12 domains
85 controls

Microsoft Azure cloud security best practices and controls

Verified

Azure Security Benchmark is a compliance framework from International with 12 domains and 85 controls that map to 147 other frameworks. The largest domains are Governance and Strategy (10 controls), Network Security (10 controls), Identity Management (9 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit github.com

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

Asset Management

5 controls
Controls in the Asset Management domain of Azure Security Benchmark5 controls
CodeTitle
AM-2Use only approved services
AM-3Ensure security of asset lifecycle management
ASBv3-AM-1Track asset inventory and their risks
ASBv3-AM-4Limit access to asset management
ASBv3-AM-5Use only approved applications in virtual machine

Backup and Recovery

4 controls
Controls in the Backup and Recovery domain of Azure Security Benchmark4 controls
CodeTitle
ASBv3-BR-3Monitor backups
ASBv3-BR-4Regularly test backup
BR-1Ensure regular automated backups
BR-2Protect backup and recovery data

Data Protection

8 controls
Controls in the Data Protection domain of Azure Security Benchmark8 controls
CodeTitle
ASBv3-DP-1Discover, classify, and label sensitive data
ASBv3-DP-5Use customer-managed key option in data at rest encryption when required
ASBv3-DP-6Use a secure key management process
ASBv3-DP-7Use a secure certificate management process
ASBv3-DP-8Ensure security of key and certificate repository
DP-2Monitor anomalies and threats targeting sensitive data
DP-3Encrypt sensitive data in transit
DP-4Enable data at rest encryption by default

DevOps Security

7 controls
Controls in the DevOps Security domain of Azure Security Benchmark7 controls
CodeTitle
ASBv3-DS-1Conduct threat modeling
ASBv3-DS-3Secure DevOps infrastructure
ASBv3-DS-4Integrate static application security testing into DevOps pipeline
ASBv3-DS-5Integrate dynamic application security testing into DevOps pipeline
ASBv3-DS-7Enable logging and monitoring in DevOps
DS-2Ensure software supply chain security
DS-6Enforce security of workload throughout DevOps lifecycle

Endpoint Security

3 controls
Controls in the Endpoint Security domain of Azure Security Benchmark3 controls
CodeTitle
ASBv3-ES-3Ensure anti-malware software and signatures are updated
ES-1Use Endpoint Detection and Response (EDR)
ES-2Use modern anti-malware software

Governance and Strategy

10 controls
Controls in the Governance and Strategy domain of Azure Security Benchmark10 controls
CodeTitle
ASBv3-GS-10Define and implement DevOps security strategy
ASBv3-GS-2Define and implement enterprise segmentation/separation of duties strategy
ASBv3-GS-3Define and implement data protection strategy
ASBv3-GS-4Define and implement network security strategy
ASBv3-GS-5Define and implement security posture management strategy
ASBv3-GS-6Define and implement identity and privileged access strategy
ASBv3-GS-7Define and implement logging, threat detection and incident response strategy
ASBv3-GS-8Define and implement backup and recovery strategy
ASBv3-GS-9Define and implement endpoint security strategy
GS-1Align organization roles, responsibilities and accountabilities

Identity Management

9 controls
Controls in the Identity Management domain of Azure Security Benchmark9 controls
CodeTitle
ASBv3-IM-2Protect identity and authentication systems
ASBv3-IM-5Use single sign-on (SSO) for application access
ASBv3-IM-8Restrict the exposure of credential and secrets
ASBv3-IM-9Secure user access to existing applications
IM-1Use centralized identity and authentication system
IM-3Manage application identities securely and automatically
IM-4Authenticate server and services
IM-6Use strong authentication controls
IM-7Restrict resource access based on conditions

Incident Response

7 controls
Controls in the Incident Response domain of Azure Security Benchmark7 controls
CodeTitle
ASBv3-IR-1Preparation - update incident response plan and handling process
ASBv3-IR-2Preparation - setup incident notification
ASBv3-IR-3Detection and analysis - create incidents based on high-quality alerts
ASBv3-IR-4Detection and analysis - investigate an incident
ASBv3-IR-5Detection and analysis - prioritize incidents
ASBv3-IR-6Containment, eradication and recovery - automate the incident handling
ASBv3-IR-7Post-incident activity - conduct lesson learned and retain evidence

Logging and Threat Detection

7 controls
Controls in the Logging and Threat Detection domain of Azure Security Benchmark7 controls
CodeTitle
ASBv3-LT-1Enable threat detection capabilities
ASBv3-LT-2Enable threat detection for identity and access management
ASBv3-LT-6Configure log storage retention
ASBv3-LT-7Use approved time synchronization sources
LT-3Enable logging for security investigation
LT-4Enable network logging for security investigation
LT-5Centralize security log management and analysis

Network Security

10 controls
Controls in the Network Security domain of Azure Security Benchmark10 controls
CodeTitle
ASBv3-NS-10Ensure Domain Name System (DNS) security
ASBv3-NS-4Deploy intrusion detection/intrusion prevention systems (IDS/IPS)
ASBv3-NS-6Deploy web application firewall
ASBv3-NS-7Simplify network security configuration
ASBv3-NS-8Detect and disable insecure services and protocols
ASBv3-NS-9Connect on-premises or cloud network privately
NS-1Establish network segmentation boundaries
NS-2Secure cloud services with network controls
NS-3Deploy firewall at the edge of enterprise network
NS-5Deploy DDOS protection

Posture and Vulnerability Management

7 controls
Controls in the Posture and Vulnerability Management domain of Azure Security Benchmark7 controls
CodeTitle
ASBv3-PV-1Define and establish secure configurations
ASBv3-PV-3Define and establish secure configurations for compute resources
ASBv3-PV-4Audit and enforce secure configurations for compute resources
ASBv3-PV-6Rapidly and automatically remediate vulnerabilities
ASBv3-PV-7Conduct regular red team operations
PV-2Audit and enforce secure configurations
PV-5Perform vulnerability assessments

Privileged Access

8 controls
Controls in the Privileged Access domain of Azure Security Benchmark8 controls
CodeTitle
ASBv3-PA-4Review and reconcile user access regularly
ASBv3-PA-5Set up emergency access
ASBv3-PA-6Use privileged access workstations
ASBv3-PA-7Follow just enough administration (least privilege) principle
ASBv3-PA-8Determine access process for cloud provider support
PA-1Separate and limit highly privileged/administrative users
PA-2Avoid standing access for user accounts and permissions
PA-3Manage lifecycle of identities and entitlements

Your Compliance Coverage

If you comply with Azure Security Benchmark, you already cover:

Maps to 147 other frameworks

85 total controls
FedRAMP High
85 source controls mapped|185 target controls covered
100%
FedRAMP Moderate
85 source controls mapped|186 target controls covered
100%
NIST SP 800-53 Revision 5.1 HIGH
85 source controls mapped|140 target controls covered
100%
NIST Cybersecurity Framework 2.0
85 source controls mapped|66 target controls covered
100%
ISO 27002:2022
85 source controls mapped|60 target controls covered
100%
NIST SP 800-53 Rev 5
85 source controls mapped|121 target controls covered
100%
NIST SP 800-53 Rev 5 MODERATE
84 source controls mapped|137 target controls covered
99%
ISO 27001:2022
84 source controls mapped|60 target controls covered
99%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
84 source controls mapped|126 target controls covered
99%
C5 (Germany)
80 source controls mapped|90 target controls covered
94%
CIS Controls v8
77 source controls mapped|114 target controls covered
91%
NIST SP 800-53 Rev 5 LOW
77 source controls mapped|85 target controls covered
91%
NIST SP 800-161 Rev 1
76 source controls mapped|71 target controls covered
89%
SOC 2
75 source controls mapped|26 target controls covered
88%
NIST SP 800-171 Rev 3
74 source controls mapped|68 target controls covered
87%
AWS Well-Architected Security Pillar
71 source controls mapped|61 target controls covered
84%
CMMC 2.0
70 source controls mapped|70 target controls covered
82%
PCI DSS 4.0
68 source controls mapped|141 target controls covered
80%
HIPAA Security Rule
65 source controls mapped|44 target controls covered
76%
NIST SP 800-66 Rev 2
65 source controls mapped|42 target controls covered
76%
ISO 27701:2019
57 source controls mapped|30 target controls covered
67%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
57 source controls mapped|37 target controls covered
67%
NIST SP 800-172
51 source controls mapped|27 target controls covered
60%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
46 source controls mapped|21 target controls covered
54%
ASD Strategies to Mitigate Cyber Security Incidents
43 source controls mapped|31 target controls covered
51%
ACSC Essential Eight
39 source controls mapped|24 target controls covered
46%
Australia Consumer Data Right - Banking (CDR)
37 source controls mapped|11 target controls covered
44%
UK Cyber Essentials
35 source controls mapped|33 target controls covered
41%
APRA CPS 234
25 source controls mapped|15 target controls covered
29%
NIST SP 800-218
24 source controls mapped|35 target controls covered
28%
APEC Cross-Border Privacy Rules (CBPR) System
21 source controls mapped|10 target controls covered
25%
Australia My Health Records Act 2012
17 source controls mapped|7 target controls covered
20%
APRA CPS 230 Operational Risk Management
12 source controls mapped|10 target controls covered
14%
ISO 22301:2019
9 source controls mapped|11 target controls covered
11%
APPI
8 source controls mapped|5 target controls covered
9%
Authorised Economic Operator (AEO) Programmes - Global Standards
4 source controls mapped|5 target controls covered
5%
ISO/IEC 42001:2023
3 source controls mapped|3 target controls covered
4%
NIST SP 800-53A Rev. 5
2 source controls mapped|1 target controls covered
2%
NIST SP 800-181
1 source controls mapped|3 target controls covered
1%
Virginia CDPA
1 source controls mapped|2 target controls covered
1%
Vietnam PDPD
1 source controls mapped|1 target controls covered
1%
Uruguay DPL
1 source controls mapped|3 target controls covered
1%
UNICEF Policy Guidance on AI for Children (2021)
1 source controls mapped|1 target controls covered
1%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|2 target controls covered
1%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
1 source controls mapped|1 target controls covered
1%
South Africa Promotion of Access to Information Act (PAIA)
1 source controls mapped|1 target controls covered
1%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
1%
Turkey KVKK
1 source controls mapped|2 target controls covered
1%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|4 target controls covered
1%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
1%
Texas Data Privacy Act
1 source controls mapped|2 target controls covered
1%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|4 target controls covered
1%
Taiwan PDPA
1 source controls mapped|2 target controls covered
1%
Student Privacy Pledge 2020
1 source controls mapped|1 target controls covered
1%
SASB Standards
1 source controls mapped|3 target controls covered
1%
Qatar DPL
1 source controls mapped|2 target controls covered
1%
Privacy Act 2020
1 source controls mapped|3 target controls covered
1%
POPIA
1 source controls mapped|2 target controls covered
1%
Peru DPL
1 source controls mapped|2 target controls covered
1%
Personal Data Act (personopplysningsloven)
1 source controls mapped|3 target controls covered
1%
PDPA Thailand
1 source controls mapped|3 target controls covered
1%
PDPA Singapore
1 source controls mapped|3 target controls covered
1%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|1 target controls covered
1%
Oregon Consumer Privacy Act
1 source controls mapped|4 target controls covered
1%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
1%
OECD AI Principles
1 source controls mapped|1 target controls covered
1%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|2 target controls covered
1%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
1%
NIST SP 800-122
1 source controls mapped|4 target controls covered
1%
NIST Privacy Framework
1 source controls mapped|5 target controls covered
1%
NIST AI 600-1: Generative AI Profile
1 source controls mapped|1 target controls covered
1%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|3 target controls covered
1%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|2 target controls covered
1%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|5 target controls covered
1%
Nebraska Data Privacy Act
1 source controls mapped|5 target controls covered
1%
New Jersey Data Privacy Act
1 source controls mapped|3 target controls covered
1%
New Hampshire Data Privacy Act
1 source controls mapped|4 target controls covered
1%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
1%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|1 target controls covered
1%
Montana Consumer Data Privacy Act
1 source controls mapped|3 target controls covered
1%
Minnesota Consumer Data Privacy Act
1 source controls mapped|3 target controls covered
1%
Mexico LFPDPPP
1 source controls mapped|3 target controls covered
1%
Mauritius DPA
1 source controls mapped|2 target controls covered
1%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|3 target controls covered
1%
MARS-E
1 source controls mapped|1 target controls covered
1%
Malaysia PDPA 2010
1 source controls mapped|4 target controls covered
1%
Liechtenstein DPA
1 source controls mapped|3 target controls covered
1%
LGPD
1 source controls mapped|2 target controls covered
1%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|2 target controls covered
1%
South Korea PIPA
1 source controls mapped|1 target controls covered
1%
Kids Online Safety Act (KOSA)
1 source controls mapped|2 target controls covered
1%
Kenya Data Protection Act
1 source controls mapped|2 target controls covered
1%
Kentucky Consumer Data Protection Act
1 source controls mapped|2 target controls covered
1%
Japan AI Guidelines
1 source controls mapped|1 target controls covered
1%
Jamaica Data Protection Act 2020
1 source controls mapped|3 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
1%
Israel Protection of Privacy Law (5741-1981)
1 source controls mapped|3 target controls covered
1%
Iowa Consumer Data Protection Act
1 source controls mapped|2 target controls covered
1%
Indonesia PDP Law
1 source controls mapped|2 target controls covered
1%
Indiana Consumer Data Protection Act
1 source controls mapped|2 target controls covered
1%
IEEE 7000
1 source controls mapped|1 target controls covered
1%
1%
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
1 source controls mapped|2 target controls covered
1%
HITECH Act
1 source controls mapped|2 target controls covered
1%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
1%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|3 target controls covered
1%
Family Educational Rights and Privacy Act (FERPA)
1 source controls mapped|4 target controls covered
1%
FedRAMP Rev 5
1 source controls mapped|1 target controls covered
1%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|3 target controls covered
1%
Barbados Data Protection Act 2019
1 source controls mapped|3 target controls covered
1%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|8 target controls covered
1%
Bahrain PDPL
1 source controls mapped|4 target controls covered
1%
Australian Privacy Principles (APPs)
1 source controls mapped|3 target controls covered
1%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|3 target controls covered
1%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
1%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|3 target controls covered
1%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
1%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|1 target controls covered
1%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|1 target controls covered
1%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
1%
Section 508 - ICT Accessibility (Revised)
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27400:2022
1 source controls mapped|2 target controls covered
1%
1%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
1%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
1 source controls mapped|3 target controls covered
1%
WHO Global Strategy on Digital Health 2020-2025
1 source controls mapped|3 target controls covered
1%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
1 source controls mapped|1 target controls covered
1%
UK Age Appropriate Design Code (Children's Code)
1 source controls mapped|5 target controls covered
1%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
1%
UK Data Protection Act 2018
1 source controls mapped|3 target controls covered
1%
GDPR
1 source controls mapped|6 target controls covered
1%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
1%
Saudi Arabia PDPL
1 source controls mapped|4 target controls covered
1%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
1 source controls mapped|1 target controls covered
1%
Uganda Data Protection and Privacy Act (2019)
1 source controls mapped|2 target controls covered
1%
South Korea ISMS-P
1 source controls mapped|3 target controls covered
1%
UK Open Banking Standard
1 source controls mapped|2 target controls covered
1%
ISO 8000 - Data Quality
1 source controls mapped|1 target controls covered
1%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
1 source controls mapped|1 target controls covered
1%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
1 source controls mapped|1 target controls covered
1%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
1%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|3 target controls covered
1%
SSAE 18 - Attestation Standards (SOC Reporting)
1 source controls mapped|2 target controls covered
1%

What is Azure Security Benchmark and who does it apply to?

Azure Security Benchmark is a compliance framework from International with 12 domains and 85 controls. Microsoft Azure cloud security best practices and controls It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Azure Security Benchmark actually require?

Azure Security Benchmark has 85 controls organised across 12 domains. The largest domains are Governance and Strategy (10 controls), Network Security (10 controls), Identity Management (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Azure Security Benchmark do I already cover?

Azure Security Benchmark maps to 147 other compliance frameworks. The top mapping partners are FedRAMP High (100% coverage), FedRAMP Moderate (100% coverage), NIST SP 800-53 Revision 5.1 HIGH (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Azure Security Benchmark?

Start your Azure Security Benchmark compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Azure Security Benchmark requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 85 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required