Chapter 9: Describing Security Management and Capabilities of Azure
The previous chapter covered the various security services within Azure for network, compute, and data protection. This included network segmentation, NSGs, DDoS protection, firewalls, remote virtual machine management, and encryption. In this chapter, we will describe how to manage the protection of resources within Azure through Cloud Security Posture Management within Microsoft Defender for Cloud. We will also describe how to use security baselines within Azure to set up best practice protection for your compute, application, and data resources.
In this chapter, we're going to cover the following main topics:
- Describing Cloud Security Posture Management (CSPM)
- Describing the enhanced security features of Microsoft Defender for Cloud
- Describing security baselines for Azure