Summary
In this chapter, we have covered validating controls within your environment. This includes looking at both internal auditing as well as external auditing. We then reviewed what SOC is and the different types, before reviewing the importance of vendor assessments as part of your vendor onboarding process. Next, we reviewed the Microsoft Service Trust portal, which is a place to view all of Microsoft's audits and assessments. We then finished the section with an overview of the regulatory compliance center within Azure Security Center.
In the next section, we covered vulnerability scanning, which included a detailed review of what scanning and assessments are and how Security Center can help with running assessments. We then reviewed penetration testing and remediation, which involved reviewing the different types of penetration tests, the process to execute, the importance of remediation, and an overview of the rules of engagement that Microsoft has published. In the...