Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A global company uses Azure and needs to ensure that all data stored in Azure meets the requirements of GDPR (General Data Protection Regulation) for their European customers and HIPAA (Health Insurance Portability and Accountability Act) for their US healthcare data. Which Azure feature provides a centralized view of compliance offerings and helps assess compliance against these regulations?
- AAzure Policy
- BAzure Compliance Manager
- CAzure Security Center (Microsoft Defender for Cloud)
- DAzure Advisor
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Compliance Manager
Microsoft Purview Compliance Manager (often referred to as Azure Compliance Manager in a broader context) helps organizations manage their compliance posture, providing a dashboard to track progress, assign tasks, and assess compliance against various regulations like GDPR and HIPAA.
Why the other options are wrong
- A. Azure Policy enforces standards and assesses compliance of resources with defined rules, but doesn't provide a centralized dashboard for managing diverse regulatory frameworks like GDPR or HIPAA across an organization's compliance efforts.
- C. Azure Security Center (now Microsoft Defender for Cloud) focuses on security posture management and threat protection, not on centralized regulatory compliance assessment and management.
- D. Azure Advisor provides recommendations for operational excellence, security, reliability, performance, and cost, not for managing regulatory compliance assessments.
Microsoft Purview Compliance Manager
A feature within Microsoft Purview that helps organizations manage their compliance posture, track progress, and assess adherence to various regulatory standards.
- Centralizes compliance assessment.
- Provides actionable insights for regulatory standards.
- Supports regulations like GDPR, HIPAA, ISO 27001.
Memory trick: Compliance Manager Checks All the Boxes.