Compliance Flashcards

1
Q

Compliance programme: CJIS

A

Criminal Justice Information Services - those accessing CJ Db need to adhere to their security policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Compliance programme: CSA

A

Cloud Security Alliance - 3rd party assessment of cloud providers security posture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Compliance programme: GDPR

A

Euro privacy law offering goods in Europe or deals with data regarding EU residents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Compliance programme: HIPAA***

A

Health Insurance and Accountability Act - US federal law regulating patient Protected Health info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compliance programme: MTCS Singapore

A

Singapore common standard addressing customer concerns re confidential in the cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Compliance programme: NIST

A

National Institute of Standards and Technology

Note: National, therefore US only.

Voluntary framework consisting of guidelines, best practices, and standards to manage cyber security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Compliance programme: UK Government G Cloud

A

Cloud computing certification for services used by UK Governement entities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Compliance programme:

FIPS 140-2

A

US and Canadian govt standard specifying security requirements for cryptographics modules that protect sensitive info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Azure Trust Center

A

Public web portal with easy access to privacy, security and compliance info
Can see info on GDPR and others.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Azure Policy

A

Service to create, assign and manage polcies

Policies - rules. Service compares business rules to resources. E.g. limit size of VMs that can be created.

Rules are described in JSON are known as Policy definitions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Creating Azure Policy (3 steps)

A

Definition - what is the policy (rule)

Scope - what resources/level does it apply to (can be at different levels from RG to resource. Policy will be inherited.

Evaluation results - see which resources are out of policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Management Groups

A

Containers for managing subsriptions (accounts)

Good for applying policies to several subscriptions.

Any Azure AD user can create one. Can have upto 10,000 in an organisation.

New subscriptions automatically added to Root group.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Azure Blueprints

A

Group related resources, deploy repeatedly and maintain compliance. Think of plans and structure.

  • Create a draft
  • Publish version
  • Assign to the environment

To help you with auditing, traceability, and compliance of your deployments.

Just as a blueprint allows an engineer or an architect to sketch a project’s design parameters, Azure Blueprints enables cloud architects and central information technology groups to define a repeatable set of Azure resources that implements and adheres to an organization’s standards, patterns, and requirements.

Blueprints are a declarative way to orchestrate the deployment of various resource templates

When they are updated, you must manually update the assignment for it to take effect.

Assigned versions remain in place when blueprint deleted.

Blueprints must be unassigned before deletion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Compliance Manager

A

Enables you to assign, track, and record compliance and assessment-related activities, which can help your organization achieve your compliance goals.

Provides a Compliance Score to help you track your progress. See which products are in scope, and what controls they have vs whatever policy e.g. GDPR. Tests and controls are done for both Microsoft and our side.

Provides a secure repository in which to upload and manage evidence regarding compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Iniatitives

A

An Azure initiative is a collection of Azure policy definitions that are grouped together towards a specific goal or purpose in mind.

Can be assigned to multiple scopes

Can only group policies within the same subscription

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Azure Resource Manager (ARM templates)

A

JSON file describing architecture of project. Deployed with a parameter file to an environment. E.g. size of VM could be a parameter. Can then easily scale up when creating in prod (change parameter).

Allows teams to deploy quickly with agility.

Foundation of infrastructure as code.

Version controlled.

Can restrict how many resources of each type can be provisioned per Region.

17
Q

Azure Government

A

Only available in the US

Creates silo between gov and non gov data.

18
Q

Audit reports

A

Found in Service Trust Portal

Tell Azure users how compliant Azure is regarding various standards e.g. GDPR, NIST, ISO etc.

Written by indepdent assessors.

19
Q

ISO standards

A

International standards based non regulatory agency based in Switzerland.