Azure Security Benchmark
Microsoft Azure cloud security best practices and controls
Azure Security Benchmark is a compliance framework from International with 12 domains and 85 controls that map to 147 other frameworks. The largest domains are Governance and Strategy (10 controls), Network Security (10 controls), Identity Management (9 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit github.comFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
Asset Management
| Code | Title |
|---|---|
| AM-2 | Use only approved services |
| AM-3 | Ensure security of asset lifecycle management |
| ASBv3-AM-1 | Track asset inventory and their risks |
| ASBv3-AM-4 | Limit access to asset management |
| ASBv3-AM-5 | Use only approved applications in virtual machine |
Backup and Recovery
| Code | Title |
|---|---|
| ASBv3-BR-3 | Monitor backups |
| ASBv3-BR-4 | Regularly test backup |
| BR-1 | Ensure regular automated backups |
| BR-2 | Protect backup and recovery data |
Data Protection
| Code | Title |
|---|---|
| ASBv3-DP-1 | Discover, classify, and label sensitive data |
| ASBv3-DP-5 | Use customer-managed key option in data at rest encryption when required |
| ASBv3-DP-6 | Use a secure key management process |
| ASBv3-DP-7 | Use a secure certificate management process |
| ASBv3-DP-8 | Ensure security of key and certificate repository |
| DP-2 | Monitor anomalies and threats targeting sensitive data |
| DP-3 | Encrypt sensitive data in transit |
| DP-4 | Enable data at rest encryption by default |
DevOps Security
| Code | Title |
|---|---|
| ASBv3-DS-1 | Conduct threat modeling |
| ASBv3-DS-3 | Secure DevOps infrastructure |
| ASBv3-DS-4 | Integrate static application security testing into DevOps pipeline |
| ASBv3-DS-5 | Integrate dynamic application security testing into DevOps pipeline |
| ASBv3-DS-7 | Enable logging and monitoring in DevOps |
| DS-2 | Ensure software supply chain security |
| DS-6 | Enforce security of workload throughout DevOps lifecycle |
Endpoint Security
| Code | Title |
|---|---|
| ASBv3-ES-3 | Ensure anti-malware software and signatures are updated |
| ES-1 | Use Endpoint Detection and Response (EDR) |
| ES-2 | Use modern anti-malware software |
Governance and Strategy
| Code | Title |
|---|---|
| ASBv3-GS-10 | Define and implement DevOps security strategy |
| ASBv3-GS-2 | Define and implement enterprise segmentation/separation of duties strategy |
| ASBv3-GS-3 | Define and implement data protection strategy |
| ASBv3-GS-4 | Define and implement network security strategy |
| ASBv3-GS-5 | Define and implement security posture management strategy |
| ASBv3-GS-6 | Define and implement identity and privileged access strategy |
| ASBv3-GS-7 | Define and implement logging, threat detection and incident response strategy |
| ASBv3-GS-8 | Define and implement backup and recovery strategy |
| ASBv3-GS-9 | Define and implement endpoint security strategy |
| GS-1 | Align organization roles, responsibilities and accountabilities |
Identity Management
| Code | Title |
|---|---|
| ASBv3-IM-2 | Protect identity and authentication systems |
| ASBv3-IM-5 | Use single sign-on (SSO) for application access |
| ASBv3-IM-8 | Restrict the exposure of credential and secrets |
| ASBv3-IM-9 | Secure user access to existing applications |
| IM-1 | Use centralized identity and authentication system |
| IM-3 | Manage application identities securely and automatically |
| IM-4 | Authenticate server and services |
| IM-6 | Use strong authentication controls |
| IM-7 | Restrict resource access based on conditions |
Incident Response
| Code | Title |
|---|---|
| ASBv3-IR-1 | Preparation - update incident response plan and handling process |
| ASBv3-IR-2 | Preparation - setup incident notification |
| ASBv3-IR-3 | Detection and analysis - create incidents based on high-quality alerts |
| ASBv3-IR-4 | Detection and analysis - investigate an incident |
| ASBv3-IR-5 | Detection and analysis - prioritize incidents |
| ASBv3-IR-6 | Containment, eradication and recovery - automate the incident handling |
| ASBv3-IR-7 | Post-incident activity - conduct lesson learned and retain evidence |
Logging and Threat Detection
| Code | Title |
|---|---|
| ASBv3-LT-1 | Enable threat detection capabilities |
| ASBv3-LT-2 | Enable threat detection for identity and access management |
| ASBv3-LT-6 | Configure log storage retention |
| ASBv3-LT-7 | Use approved time synchronization sources |
| LT-3 | Enable logging for security investigation |
| LT-4 | Enable network logging for security investigation |
| LT-5 | Centralize security log management and analysis |
Network Security
| Code | Title |
|---|---|
| ASBv3-NS-10 | Ensure Domain Name System (DNS) security |
| ASBv3-NS-4 | Deploy intrusion detection/intrusion prevention systems (IDS/IPS) |
| ASBv3-NS-6 | Deploy web application firewall |
| ASBv3-NS-7 | Simplify network security configuration |
| ASBv3-NS-8 | Detect and disable insecure services and protocols |
| ASBv3-NS-9 | Connect on-premises or cloud network privately |
| NS-1 | Establish network segmentation boundaries |
| NS-2 | Secure cloud services with network controls |
| NS-3 | Deploy firewall at the edge of enterprise network |
| NS-5 | Deploy DDOS protection |
Posture and Vulnerability Management
| Code | Title |
|---|---|
| ASBv3-PV-1 | Define and establish secure configurations |
| ASBv3-PV-3 | Define and establish secure configurations for compute resources |
| ASBv3-PV-4 | Audit and enforce secure configurations for compute resources |
| ASBv3-PV-6 | Rapidly and automatically remediate vulnerabilities |
| ASBv3-PV-7 | Conduct regular red team operations |
| PV-2 | Audit and enforce secure configurations |
| PV-5 | Perform vulnerability assessments |
Privileged Access
| Code | Title |
|---|---|
| ASBv3-PA-4 | Review and reconcile user access regularly |
| ASBv3-PA-5 | Set up emergency access |
| ASBv3-PA-6 | Use privileged access workstations |
| ASBv3-PA-7 | Follow just enough administration (least privilege) principle |
| ASBv3-PA-8 | Determine access process for cloud provider support |
| PA-1 | Separate and limit highly privileged/administrative users |
| PA-2 | Avoid standing access for user accounts and permissions |
| PA-3 | Manage lifecycle of identities and entitlements |
Your Compliance Coverage
If you comply with Azure Security Benchmark, you already cover:
FedRAMP High
100%
85 controls mapped
Compare →FedRAMP Moderate
100%
85 controls mapped
Compare →NIST SP 800-53 Revision 5.1 HIGH
100%
85 controls mapped
Compare →+ 144 more: NIST Cybersecurity Framework 2.0 (100%), ISO 27002:2022 (100%)
See all 147 mapped frameworks ↓Maps to 147 other frameworks
What is Azure Security Benchmark and who does it apply to?
Azure Security Benchmark is a compliance framework from International with 12 domains and 85 controls. Microsoft Azure cloud security best practices and controls It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Azure Security Benchmark actually require?
Azure Security Benchmark has 85 controls organised across 12 domains. The largest domains are Governance and Strategy (10 controls), Network Security (10 controls), Identity Management (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Azure Security Benchmark do I already cover?
Azure Security Benchmark maps to 147 other compliance frameworks. The top mapping partners are FedRAMP High (100% coverage), FedRAMP Moderate (100% coverage), NIST SP 800-53 Revision 5.1 HIGH (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Azure Security Benchmark?
Start your Azure Security Benchmark compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Azure Security Benchmark requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 85 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required