Monitoring for compliance
While enforcing policies is important to ensure that the upper management’s decisions are translated into real actions towards optimizing the security state of your company, monitoring these policies for compliance is also indispensable.
Policies that were defined can be easily monitored using tools such as Microsoft Defender for Cloud, which not only monitor Windows VMs and computers, but also those operating with Linux software. The example shown in Figure 10.11 is for Windows machines:
Figure 10.11: Monitoring security policies
This dashboard shows the security recommendation called Vulnerabilities in security configuration on your Windows machines should be remediated (powered by Guest Configuration). This recommendation looks across many security policies to identify if the machine is using the recommended configuration to mitigate a potential threat. For example, one rule that is part of this policy is the Minimum session security...