Threat protection
Threat protection will be a joint effort of multiple roles and tends to be mostly out-of-scope of the data architect. This is because services here are mostly used platform-wide, spanning more than just the data services. We will look at the relevant parts of Microsoft Defender for Cloud to assess vulnerabilities and perform advanced threat protection, and Microsoft Sentinel to monitor security incidents.
Microsoft Defender for Cloud
Microsoft Defender for Cloud is a broad solution covering all kinds of services on Azure, external clouds, and on-premises. Defender for Cloud encompasses three main pillars:
- Cloud security posture management (CSPM)
- Cloud workload protection platform (CWPP)
- Development security operations (DevSecOps)
First, CSPM refers to the process of continuously monitoring and assessing the security configuration of cloud resources, and identifying and remediating misconfigurations, vulnerabilities, and compliance violations...