Study project for all things cloud. Spin-offs will happen when detailing
This project is maintained by jesperancinha
Azure documentation
Secure the perimeter layer
Azure DDoS Protection, Azure Firewall
Secure the network layer
Segmentation, Deny by default, inbout/outbound restrictions, secure connectivity
Combine services
Network security groups and Azure Firewall, Azure Application Gateway, Web application firewall, Azure Firewall
AuthenticationSingle sign-onApplication managementDevice managementSaaSInternal AppsInternal Cloud ApplicationsSomething the user knowsSomething the user hasSomething the user isAzure AD Premium P1 or P2 licenseIdentity SignalsMFAApprovalManaged DevicesBlocks access from unknown and unexpectted locationsCanNotDelete, ReadOnly
Azure BlueprintsAllowed virtual machine SKUsAllowed locationsMFA should be enabled on accounts with write permissions on your subscriptionCORS should not allow every resource to access your web applicationsSystem updates should be installed on your machinesMonitor unencrypted SQL Database in Security CenterMonitor OS vulnerabilities in Security CenterMonitor missing Endpoint Protection in Security CenterCriminal Justice Information ServiceCloud Security Alliance STAR CertificationEuropean Union Model ClausesHealth Insurance Portability and Accountability ActInternational Organization of Standards/International Electrotechnical Commission 27018Multi-Tier Cloud Security SingaporeService Organization Controls 1, 2, and 3National Institute of Standards and Technology Cybersecurity FrameworkUnited Kingdom Government G-Cloud