Designing a Regulatory Compliance Strategy
The previous chapter discussed how to design an identity security strategy for cloud-native, hybrid, and multi-cloud identity and access management infrastructures. This chapter will discuss how to design security and governance strategies based on regulatory compliance requirements within your company. This includes how to utilize Microsoft Defender for Cloud and Azure Policy to evaluate and govern your company resources.
In this chapter, we are going to cover the following main topics:
- Interpreting compliance requirements and translating them into specific technical capabilities (new or existing)
- Evaluating infrastructure compliance by using Microsoft Defender for Cloud
- Interpreting compliance scores and recommending actions to resolve issues or improve security
- Designing the implementation of Azure Policy
- Designing for data residency requirements
- Translating privacy requirements into requirements for security...