Azure 数据资源管理器的 Azure Policy 法规合规性控制措施Azure Policy Regulatory Compliance controls for Azure Data Explorer

Azure Policy 中的法规符合性为与不同符合性标准相关的“符合域”和“安全控件”提供 Microsoft 创建和管理的计划定义,称为“内置” 。Regulatory Compliance in Azure Policy provides Microsoft created and managed initiative definitions, known as built-ins, for the compliance domains and security controls related to different compliance standards. 本页面列出了 Azure 数据资源管理器的合规性域和安全控制措施 。This page lists the compliance domains and security controls for Azure Data Explorer. 可以分别为“安全控件”分配内置项,以帮助 Azure 资源符合特定的标准。You can assign the built-ins for a security control individually to help make your Azure resources compliant with the specific standard.

每个内置策略定义链接(指向 Azure 门户中的策略定义)的标题。The title of each built-in policy definition links to the policy definition in the Azure portal. 使用“策略版本”列中的链接查看 Azure Policy GitHub 存储库上的源。Use the link in the Policy Version column to view the source on the Azure Policy GitHub repo.

重要

下面的每个控件都与一个或多个 Azure Policy 定义关联。Each control below is associated with one or more Azure Policy definitions. 这些策略有助于评估控制的合规性;但是,控制与一个或多个策略之间通常不是一对一或完全匹配。These policies may help you assess compliance with the control; however, there often is not a one-to-one or complete match between a control and one or more policies. 因此,Azure Policy 中的符合性仅引用策略本身;这不确保你完全符合控件的所有要求。As such, Compliant in Azure Policy refers only to the policies themselves; this doesn't ensure you're fully compliant with all requirements of a control. 此外,符合性标准包含目前未由任何 Azure Policy 定义处理的控件。In addition, the compliance standard includes controls that aren't addressed by any Azure Policy definitions at this time. 因此,Azure Policy 中的符合性只是整体符合性状态的部分视图。Therefore, compliance in Azure Policy is only a partial view of your overall compliance status. 这些符合性标准的控制措施和 Azure Policy 法规符合性定义之间的关联可能会随着时间的推移而发生变化。The associations between controls and Azure Policy Regulatory Compliance definitions for these compliance standards may change over time.

CMMC 级别 3CMMC Level 3

Domain 控制 IDControl ID 控制标题Control title 策略Policy
(Azure 门户)(Azure portal)
策略版本Policy version
(GitHub)(GitHub)
系统和通信保护System and Communications Protection SC.3.177SC.3.177 采用经 FIPS 验证的加密系统来保护 CUI 的机密性。Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. Azure 数据资源管理器静态加密应使用客户管理的密钥Azure Data Explorer encryption at rest should use a customer-managed key 1.0.01.0.0
系统和通信保护System and Communications Protection SC.3.177SC.3.177 采用经 FIPS 验证的加密系统来保护 CUI 的机密性。Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. 应为 Azure 数据资源管理器启用磁盘加密Disk encryption should be enabled on Azure Data Explorer 2.0.02.0.0
系统和通信保护System and Communications Protection SC.3.177SC.3.177 采用经 FIPS 验证的加密系统来保护 CUI 的机密性。Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. 应为 Azure 数据资源管理器启用双重加密Double encryption should be enabled on Azure Data Explorer 2.0.02.0.0
系统和通信保护System and Communications Protection SC.3.191SC.3.191 保护静态 CUI 的机密性。Protect the confidentiality of CUI at rest. 应为 Azure 数据资源管理器启用磁盘加密Disk encryption should be enabled on Azure Data Explorer 2.0.02.0.0
系统和通信保护System and Communications Protection SC.3.191SC.3.191 保护静态 CUI 的机密性。Protect the confidentiality of CUI at rest. 应为 Azure 数据资源管理器启用双重加密Double encryption should be enabled on Azure Data Explorer 2.0.02.0.0

后续步骤Next steps