{"id":19389,"date":"2020-04-30T06:00:13","date_gmt":"2020-04-30T13:00:13","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=19389"},"modified":"2020-06-01T15:41:42","modified_gmt":"2020-06-01T22:41:42","slug":"cmmc-with-microsoft-azure-audit-accountability-management-2-of-10","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-audit-accountability-management-2-of-10\/","title":{"rendered":"CMMC with Microsoft Azure: Audit &#038; Accountability Management (2 of 10)"},"content":{"rendered":"<p><em>This is the second in a ten-part blog series where we\u2019ll demonstrate principles of the Cybersecurity Maturity Model Certification (CMMC) aligned with Microsoft Azure. Subsequent blogs in the series will delve into asset &amp; configuration management, identification &amp; authentication, incident response, maintenance &amp; media protection, recovery &amp; risk management, security assessment &amp; risk management, system &amp; communications protection and system &amp; information integrity. In this second blog of the series we will explore how to leverage Microsoft Azure for audit &amp; accountability management. <\/em><\/p>\n<p>Please note that the information cutoff date for this post is October 2020 and that as of the date of this writing, CMMC developments and guidance are in progress. Additionally, as of the date of this writing, the CMMC Accreditation Body (CMMC AB) has not identified nor certified any third-party assessors, nor issued prescriptive guidance on the formal assessment process and criteria. As a result, the information herein, including our CMMC related offerings, may be enhanced to align with future guidance from the DoD and CMMC AB. Microsoft is closely tracking developments related to the CMMC.<\/p>\n<p><strong>Stay tuned for the published and upcoming CMMC blogs in the series:<\/strong><\/p>\n<ol>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-access-control-1-of-10\">Access Control Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-audit-accountability-management-2-of-10\">Audit &amp; Accountability Maturity<\/a> &#8211; this blog<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-asset-configuration-management-3-of-10\/\">Asset &amp; Configuration Management Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-identification-authentication-maturity-4-of-10\/\">Identification &amp; Authentication Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-incident-response-maturity-5-of-10\/\">Incident Response Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-maintenance-media-protection-6-of-10\/\">Maintenance &amp; Media Protection Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-recovery-risk-management-7-of-10\/\">Recovery &amp; Risk Management Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-security-assessment-situational-awareness-8-of-10\/\">Security Assessment &amp; Situational Awareness Maturity<\/a> &#8211; live<\/li>\n<li><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/cmmc-with-microsoft-azure-system-communications-protection-9-of-10\/\">System &amp; Communications Protection Maturity<\/a> &#8211; live<\/li>\n<li>System &amp; Information Integrity Maturity (5\/28)<\/li>\n<\/ol>\n<p><strong>What is Cybersecurity Maturity Model Certification (CMMC)?<\/strong><\/p>\n<p><img decoding=\"async\" class=\"size-full wp-image-19453 alignright\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series1-WhatIsCMMC-1.png\" alt=\"Image CMMC Series1 WhatIsCMMC\" width=\"450\" height=\"291\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series1-WhatIsCMMC-1.png 450w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series1-WhatIsCMMC-1-300x194.png 300w\" sizes=\"(max-width: 450px) 100vw, 450px\" \/><\/p>\n<p>The Defense Industrial Base (DIB) is charged with implementing <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/offering-dfars?view=o365-worldwide\">Defense Federal Acquisition Regulation Supplement (DFARS)<\/a> 252.204-7012. DFARS requires organizations supporting the Department of Defense (DoD) to implement <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/offering-nist-sp-800-171?view=o365-worldwide\">NIST SP 800-171<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/offering-fedramp?view=o365-worldwide\">FedRAMP<\/a> Moderate Impact level controls. DoD has mandated CMMC with periodic assessments in order to strengthen cybersecurity across the DIB. CMMC builds upon DFARS 7012 by verifying an organization\u2019s readiness to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) such as International Traffic in Arms Regulation (ITAR) and Export Administration Regulations (EAR) export-controlled data.<\/p>\n<p>CMMC extends beyond the parent organization into sub-contractors, partners, and suppliers. The framework is intended to enforce critical thinking approaches for comprehensive security. The CMMC framework specifies 5 levels of maturity measurement from Maturity Level 1 (Basic Cyber Hygiene) to Maturity Level 5 (Proactive &amp; Advanced Cyber Practice). The Certification levels will be determined through audits from independent, third-party assessment organizations (C3PAO).<\/p>\n<p><strong>What preparation is required for CMMC alignment to audit &amp; accountability management?<\/strong><\/p>\n<p><img decoding=\"async\" class=\"size-full wp-image-19435 alignleft\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-PrepRequirements-Alignment-1.png\" alt=\"Image CMMC Series2 PrepRequirements Alignment\" width=\"240\" height=\"249\" \/><\/p>\n<p>It\u2019s important to understand that compliance is a shared responsibility between the customer and the Cloud Services Provider (CSP). The graphic on the left demonstrates the CSP responsibility in respective cloud models (On-Prem, IaaS, PaaS, SaaS) with dark blue aligning with customer responsibility and light blue aligning with CSP responsibility. For example, CMMC requirements such as Physical Protection (PE) for limiting physical access (C028) is managed by the CSP. Establishment of respective policies and procedures are the customer\u2019s responsibility. It\u2019s important to note that this blog series is aligned with setting the foundation of controls for CMMC Maturity Levels 1 &amp; 2. Once C3PAOs are identified by the CMMC Accreditation Body, customers are advised to work with their respective C3PAO for guidance on comprehensive alignment of controls, audit and certification.<\/p>\n<p><img decoding=\"async\" class=\"size-full wp-image-19440 alignright\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-AdminControlsTable-1.png\" alt=\"Image CMMC Series2 AdminControlsTable\" width=\"441\" height=\"221\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-AdminControlsTable-1.png 441w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-AdminControlsTable-1-300x150.png 300w\" sizes=\"(max-width: 441px) 100vw, 441px\" \/><\/p>\n<p>The administrative controls for the CMMC Audit &amp; Accountability Maturity Capability (AU-MC) are listed here. These controls fall within the customer\u2019s responsibility. This starts with establishing a policy that includes audit &amp; accountability (ML2) and progresses to a documented approach across all applicable organizational units (ML5). These controls should be formally created, documented in the System Security Plan (SSP) and implemented within the organization.<\/p>\n<p><strong>Microsoft Azure Security Controls Aligned to CMMC: Audit &amp; Accountability Management<\/strong><\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19455\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-BigTable-1.png\" alt=\"Image CMMC Series2 BigTable\" width=\"680\" height=\"1036\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-BigTable-1.png 680w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-BigTable-1-197x300.png 197w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-BigTable-1-672x1024.png 672w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/><\/p>\n<p><strong>\u00a0<\/strong><strong>Azure Security Controls Aligned to CMMC: Audit &amp; Accountability Management<\/strong><\/p>\n<p>Microsoft Azure Government has developed an 11-step process to facilitate audit &amp; accountability management with the security principles within CMMC, NIST SP 800-53 R4 and NIST SP 800-171 standards. Note this process is a starting point, as CMMC requires alignment of people, processes, policy, and technology so refer to organizational requirements and respective standards for implementation. Azure has several offerings to facilitate audit &amp; accountability management including <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/active-directory\/\">Azure Active Directory<\/a>, <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/governance\/policy\/overview\">Azure Policy<\/a>, <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/monitor\/\">Azure Monitor<\/a>, <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-sentinel\/\">Azure Sentinel<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/learn\/quick-create-workspace\">Log Analytics Workspace<\/a>.<\/p>\n<ul>\n<li><strong>Azure Active Directory<\/strong> is an identity and access management-as-a-service (IDaaS) solution that combines single-on capabilities to any cloud and on-premises application with advanced protection.<\/li>\n<li><strong>Azure Policy <\/strong>helps you manage and prevent IT issues with policy definitions that enforce rules and effects for your resources.<\/li>\n<li><strong>Azure Monitor<\/strong> helps collect, analyze, and act on telemetry data from your Azure and on-premises environments. Azure Monitor helps you maximize performance and availability of your applications and proactively identify problems in seconds.<\/li>\n<li><strong>Azure Sentinel<\/strong> is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution.<\/li>\n<li><strong>Log Analytics Workspace<\/strong> is a unique environment for Azure Monitor log data. Each workspace has its own data repository and configuration. Data sources and solutions are configured to store their data in a workspace.<\/li>\n<\/ul>\n<p><strong>11 Steps to CMMC for Audit &amp; Accountability Management with Microsoft Azure<\/strong><\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-19402\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-11Steps.png\" alt=\"Image CMMC Series2 11Steps\" width=\"636\" height=\"368\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-11Steps.png 1144w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-11Steps-300x174.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-11Steps-1024x593.png 1024w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-11Steps-768x444.png 768w\" sizes=\"(max-width: 636px) 100vw, 636px\" \/><\/p>\n<p><strong>1) Log User Actions<\/strong><\/p>\n<p>Azure Active Directory (Azure AD) records all user activity in the Azure portal. The audit logs report consolidates the following reports:<\/p>\n<ul>\n<li>Audit report<\/li>\n<li>Password reset activity<\/li>\n<li>Password reset registration activity<\/li>\n<li>Self-service groups activity<\/li>\n<li>Office365 Group Name Changes<\/li>\n<li>Account provisioning activity<\/li>\n<li>Password rollover status<\/li>\n<li>Account provisioning errors<\/li>\n<\/ul>\n<p>You can use advanced filtering in the audit report to access a specific category of audit data, by specifying it in the Category filter. For example, to view all activities related to users, select the UserManagement category. Categories include:<\/p>\n<ul>\n<li>All<\/li>\n<li>AdministrativeUnit<\/li>\n<li>ApplicationManagement<\/li>\n<li>Authentication<\/li>\n<li>Authorization<\/li>\n<li>Contact<\/li>\n<li>Device<\/li>\n<li>DeviceConfiguration<\/li>\n<li>DirectoryManagement<\/li>\n<li>EntitlementManagement<\/li>\n<li>GroupManagement<\/li>\n<li>Other<\/li>\n<li>Policy<\/li>\n<li>ResourceManagement<\/li>\n<li>RoleManagement<\/li>\n<li>UserManagement<\/li>\n<\/ul>\n<p>Review user activity in Azure AD via the steps below: For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/reports-monitoring\/howto-find-activity-reports\">Find activity reports in the Azure portal<\/a>.<\/p>\n<ol>\n<li>Navigate to the <a href=\"https:\/\/portal.azure.com\/\">Azure portal<\/a>.<\/li>\n<li>Select your directory from the top-right corner, then select the <strong>Azure Active Directory<\/strong> blade from the left navigation pane.<\/li>\n<li>Select <strong>Audit logs<\/strong> from the <strong>Activity<\/strong> section of the Azure Active Directory blade.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19444\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ContosoCloud-1.png\" alt=\"Image CMMC Series2 ContosoCloud\" width=\"310\" height=\"388\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ContosoCloud-1.png 310w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ContosoCloud-1-240x300.png 240w\" sizes=\"(max-width: 310px) 100vw, 310px\" \/><\/li>\n<\/ol>\n<p><strong>2) Enable Resource Logging<\/strong><\/p>\n<p>Enable Diagnostic Settings on Azure resources for access to audit, security, and diagnostic logs. Activity logs, which are automatically available, include event source, date, user, timestamp, source addresses, destination addresses, and other useful elements. Enable resource logging with Azure Monitor via the steps below. Additional metric and log data can be collected using extensions to configure diagnostics on your VMs from the guest operating system. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/platform\/diagnostic-settings#create-diagnostic-settings-in-azure-portal\">Create a diagnostic setting<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-machines\/windows\/monitor\">How to monitor virtual machines in Azure<\/a>.<\/p>\n<ol>\n<li>Where you configure diagnostic settings in the Azure portal depends on the resource.\n<ul style=\"list-style-type: disc;\">\n<li>For a single resource, click Diagnostic settings under Monitor in the resource&#8217;s menu.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19446\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-EnableResourceLogging1-1.png\" alt=\"Image CMMC Series2 EnableResourceLogging1\" width=\"220\" height=\"140\" \/><\/li>\n<li>For one or more resources, click Diagnostic settings under Settings in the Azure Monitor menu and then click on the resource.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19447\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-EnableResourceLogging2-1.png\" alt=\"Image CMMC Series2 EnableResourceLogging2\" width=\"220\" height=\"87\" \/><\/li>\n<li>For the Activity log, click Activity log in the Azure Monitor menu and then Diagnostic settings.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19428\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-EnableResourceLogging3-1.png\" alt=\"Image CMMC Series2 EnableResourceLogging3\" width=\"600\" height=\"160\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-EnableResourceLogging3-1.png 600w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-EnableResourceLogging3-1-300x80.png 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/li>\n<\/ul>\n<\/li>\n<li>If no settings exist on the resource you have selected, you are prompted to create a setting. Click <strong>Add diagnostic setting<\/strong>.<\/li>\n<li>Give your setting a name if it doesn\u2019t already have one.<\/li>\n<li>Check the box for each destination to send the logs. Options include Log Analytics workspace, Storage account, Event hub namespace, Event hub name and\/or Event hub policy name. Select<strong> Configure<\/strong>.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19445\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-DiagnosticSettings-1.png\" alt=\"Image CMMC Series2 DiagnosticSettings\" width=\"341\" height=\"347\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-DiagnosticSettings-1.png 341w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-DiagnosticSettings-1-295x300.png 295w\" sizes=\"(max-width: 341px) 100vw, 341px\" \/><\/li>\n<li>Check the box for each of the categories of data to send to the specified destinations. The list of categories will vary for each Azure service.<\/li>\n<li>Click <strong>Save<\/strong>.<\/li>\n<\/ol>\n<p><strong>3) Synchronize Time Stamps<\/strong><\/p>\n<p>Time sync is important for security and event correlation. Sometimes it is used for distributed transactions implementation. Time accuracy between multiple computer systems is achieved through synchronization. Synchronization can be affected by multiple things, including reboots and network traffic between the time source and the computer fetching the time.<\/p>\n<p>Accuracy for a computer clock is gauged on how close the computer clock is to the Coordinated Universal Time (UTC) time standard. UTC is defined by a multinational sample of precise atomic clocks that can only be off by one second in 300 years. But, reading UTC directly requires specialized hardware. Instead, time servers are synced to UTC and are accessed from other computers to provide scalability and robustness. Every computer has time synchronization service running that knows what time servers to use and periodically checks if computer clock needs to be corrected and adjusts time if needed.<\/p>\n<p>Azure hosts are synchronized to internal Microsoft time servers that take their time from Microsoft-owned Stratum 1 devices, with GPS antennas. Virtual machines in Azure can either depend on their host to pass the accurate time (host time) on to the VM or the VM can directly get time from a time server, or a combination of both. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-machines\/windows\/time-sync\">Time sync in Azure<\/a>.<\/p>\n<p><strong>4) Centralize Logging<\/strong><\/p>\n<p>Ingest logs via Azure Monitor to aggregate security data generated by endpoint devices, network resources, and other security systems. Within Azure Monitor, use Log Analytics Workspace(s) to query and perform analytics, and use Azure Storage Accounts for long-term\/archival storage. Alternatively, you may enable and on-board data to Azure Sentinel or a third-party SIEM. Enable Azure Sentinel for centralized logging via the steps below.<\/p>\n<ol>\n<li>Sign into the <a href=\"https:\/\/portal.azure.com\/\">Azure Portal<\/a>. Select the subscription in which Azure Sentinel will be created.<\/li>\n<li>Search for and select <em>Azure Sentinel.<\/em><\/li>\n<li>Select <strong>Add<\/strong>.<\/li>\n<li>Select the workspace you want to use or create a new one. You can run Azure Sentinel on more than one workspace, but the data is isolated to a single workspace.\n<img decoding=\"async\" class=\"alignnone wp-image-19406\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-CentralizedLogging.png\" alt=\"Image CMMC Series2 CentralizedLogging\" width=\"405\" height=\"113\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-CentralizedLogging.png 720w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-CentralizedLogging-300x84.png 300w\" sizes=\"(max-width: 405px) 100vw, 405px\" \/><\/li>\n<li>Select <strong>Add Azure Sentinel<\/strong>.<\/li>\n<li>Click <strong>Data collection<\/strong>.<\/li>\n<li>Select your respective data sources. Not there are tiles for each data source you can connect. For example, click Azure Active Directory. If you connect this data source, you stream all the logs from Azure AD into Azure Sentinel. You can select what type of logs you want to get &#8211; sign-in logs and\/or audit logs.<\/li>\n<li>Select desired workbooks to get pre-built security insight dashboards for your data sources.<\/li>\n<\/ol>\n<p>After your data sources are connected, your data starts streaming into Azure Sentinel and is ready for you to start working with. You can view the logs in the built-in dashboards and start building queries in Log Analytics to investigate the data. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/quickstart-onboard\">Quickstart: On-board Azure Sentinel<\/a>.<\/p>\n<p><strong>5) Stream Logging Events<\/strong><\/p>\n<p>Azure Sentinel creates the connection to services and apps by connecting to the service and forwarding the events and logs to Azure Sentinel. For machines and virtual machines, you can install the Azure Sentinel agent that collects the logs and forwards them to Azure Sentinel. For Firewalls and proxies, Azure Sentinel utilizes a Linux Syslog server. The agent is installed on it and from which the agent collects the log files and forwards them to Azure Sentinel.<\/p>\n<ol>\n<li>Sign into the <a href=\"https:\/\/portal.azure.com\/\">Azure Portal<\/a>.<\/li>\n<li>Search for and select <em>Azure Sentinel.<\/em><\/li>\n<li>Select the desired <strong>Azure Sentinel Workspace<\/strong>.<\/li>\n<li>Click <strong>Data collection<\/strong> under the <strong>Configuration<\/strong> section.<\/li>\n<li>There is a tile for each data source you can connect.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19456\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-SteamLoggingEvents-1.png\" alt=\"Image CMMC Series2 SteamLoggingEvents\" width=\"654\" height=\"349\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-SteamLoggingEvents-1.png 654w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-SteamLoggingEvents-1-300x160.png 300w\" sizes=\"(max-width: 654px) 100vw, 654px\" \/><\/li>\n<\/ol>\n<p>For example, click Azure Active Directory. If you connect this data source, you stream all the logs from Azure AD into Azure Sentinel. You can specify what type of logs you\u2019d like to stream- sign-in logs and\/or audit logs.<\/p>\n<p>At the bottom, Azure Sentinel provides recommendations for which workbooks you should install for each connector so you can immediately get interesting insights across your data.<\/p>\n<p>Follow the installation instructions or refer to the relevant connection guide for more information. For information about data connectors, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-data-sources\">Connect data sources<\/a>.<\/p>\n<p><strong>6) Alert on Logging Failures<\/strong><\/p>\n<p>Alerting on logging failures is configured in Azure Monitor. Log search alert rules work only on the logic you build into the query. The alert system doesn&#8217;t have any other context of the state of the system, your intent, or the root cause implied by the query. As such, log alerts are referred to as state-less. The conditions are evaluated as &#8220;TRUE&#8221; or &#8220;FALSE&#8221; each time they are run. An alert will fire each time the evaluation of the alert condition is &#8220;TRUE&#8221;, regardless of it is fired previously. Setting alerting for logging agents related to <em>Health Service<\/em> and <em>Service Connectors<\/em> issues monitors for logging failures.<\/p>\n<p>Filter the Operations Manager agent (Windows) or Log Analytics Agent (Linux) event log by Event sources &#8211; <em>Health Service Modules<\/em>, <em>HealthService<\/em>, and <em>Service Connector<\/em>. Filter by <strong>Event Level<\/strong> <em>Warning<\/em> and <em>Error<\/em> to confirm if it has written events from the following table. If they are, review the resolution steps included for each possible event. Below are common log event failures to monitor and alert on. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/platform\/alerts-unified-log\">Log alerts in Azure Monitor<\/a>.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-19457\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-AlertLoggingFailiures-1.png\" alt=\"Image CMMC Series2 AlertLoggingFailiures\" width=\"650\" height=\"191\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-AlertLoggingFailiures-1.png 650w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-AlertLoggingFailiures-1-300x88.png 300w\" sizes=\"(max-width: 650px) 100vw, 650px\" \/><\/p>\n<p><strong>7) Set Logging Admin Controls<\/strong><\/p>\n<p>Azure Monitor stores log data in a Log Analytics workspace. A workspace is a container that includes data and configuration information. To manage access to log data, you perform various administrative tasks related to your workspace. You can view the access control mode configured on a workspace from the Azure portal. You can view the current workspace access control mode on the Overview page for the workspace in the Log Analytics workspace menu. Configure Log Analytics Workspace access via the steps below. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/platform\/manage-access\">Manage access to log data and workspaces in Azure Monitor<\/a>.<\/p>\n<ol>\n<li>Sign into the <a href=\"https:\/\/portal.azure.com\/\">Azure Portal<\/a>.<\/li>\n<li>In the Azure portal, select <strong>Log Analytics workspaces<\/strong> &gt; <em>your workspace<\/em>.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19458\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-LoggingAdminControls1-2.png\" alt=\"Image CMMC Series2 LoggingAdminControls1\" width=\"621\" height=\"183\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-LoggingAdminControls1-2.png 621w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-LoggingAdminControls1-2-300x88.png 300w\" sizes=\"(max-width: 621px) 100vw, 621px\" \/><\/li>\n<li>Select <strong>Properties<\/strong>. Changing the setting will be disabled if you don&#8217;t have permissions to configure the workspace.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19459\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-LoggingAdminControls2-2.png\" alt=\"Image CMMC Series2 LoggingAdminControls2\" width=\"621\" height=\"221\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-LoggingAdminControls2-2.png 621w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-LoggingAdminControls2-2-300x107.png 300w\" sizes=\"(max-width: 621px) 100vw, 621px\" \/><\/li>\n<\/ol>\n<p><strong>\u00a0<\/strong><strong>8) Protect Audit Logging<\/strong><\/p>\n<p>There are several approaches to protecting audit logging. The processes referenced below provide a starting point and foundation for protecting audit logging:<\/p>\n<ol>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/platform\/manage-access\">Manage Access to Log Data<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/benchmarks\/security-control-logging-monitoring\">Configure Audit Log Retention<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-network\/tutorial-filter-network-traffic\">Segregate Access to Audit Logging Systems with Network Security Groups<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/platform\/diagnostic-settings#create-diagnostic-settings-in-azure-portal\">Stream Logging Events to Multiple Sources for Redundancy<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/encryption-overview\">Encrypt Logs<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/backup\/backup-create-rs-vault\">Backup Logs with Recovery Services Vault<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/platform\/data-security\">Configure Read Only Storage Keys for Logging<\/a><\/li>\n<\/ol>\n<p><strong>9) Review Logs<\/strong><\/p>\n<p>There are several methods to reviewing logs in Azure including log queries in Azure Monitor and Workbooks in Azure Sentinel. You can leverage Azure Monitor for writing log queries. Queries can start with either a table name or the search command. You should start with a table name since it defines a clear scope for the query and improves both query performance and relevance of the results. Azure Monitor queries are based in the Kusto Query Language (KQL) per the example below. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-monitor\/log-query\/get-started-queries\">Get started with log queries in Azure Monitor<\/a>.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-19398\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs1.png\" alt=\"Image CMMC Series2 ReviewLogs1\" width=\"253\" height=\"97\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs1.png 454w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs1-300x115.png 300w\" sizes=\"(max-width: 253px) 100vw, 253px\" \/><\/p>\n<p>You can visualize and monitor log data using the Azure Sentinel adoption of Azure Monitor Workbooks, which provides versatility in creating custom dashboards. Azure Sentinel allows you to create custom workbooks across your data, and also comes with built-in workbook templates to allow you to quickly gain insights across your data as soon as you connect a data source. You can create custom workbooks or follow the steps below to start with a built-in workbook. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-monitor-your-data\">Tutorial: Visualize and monitor your data<\/a>.<\/p>\n<ol>\n<li>Sign into the <a href=\"https:\/\/portal.azure.com\/\">Azure Portal<\/a>.<\/li>\n<li>Search for and select <em>Azure Sentinel.<\/em><\/li>\n<li>Go to <strong>Workbooks<\/strong> and then select <strong>Templates<\/strong> to see the full list of Azure Sentinel built-in workbooks. To see which are relevant to the data types you have connected, the <strong>Required data types<\/strong> field in each workbook will list the data type next to a green check mark if you already stream relevant data to Azure Sentinel.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19460\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs2-2.png\" alt=\"Image CMMC Series2 ReviewLogs2\" width=\"651\" height=\"282\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs2-2.png 651w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs2-2-300x130.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/li>\n<li>Click <strong>View workbook<\/strong> to see the template populated with your data.<\/li>\n<li>To edit the workbook, select <strong>Save<\/strong>, and then select the location where you want to save the json file for the template.<\/li>\n<li>Select <strong>View workbook<\/strong>. Then, click the <strong>Edit<\/strong> button at the top. You can now edit the workbook and customize it according to your needs.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19438\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs3-1.png\" alt=\"Image CMMC Series2 ReviewLogs3\" width=\"651\" height=\"357\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs3-1.png 651w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-ReviewLogs3-1-300x165.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/li>\n<li>After you make your changes, you can save the workbook.<\/li>\n<li>You can also clone the workbook: Select <strong>Edit<\/strong> and then <strong>Save as<\/strong>, making sure to save it with another name, under the same subscription and resource group. These workbooks are displayed under the <strong>My workbooks<\/strong> tab.<\/li>\n<\/ol>\n<p><strong>10) Investigate Abnormal Activity<\/strong><\/p>\n<p>After you connected your data sources to Azure Sentinel, you want to be notified when something suspicious happens. To enable you to do this, Azure Sentinel provides you with out-of-the-box built-in templates. These templates were designed by Microsoft&#8217;s team of security experts and analysts based on known threats, common attack vectors, and suspicious activity escalation chains. After enabling these templates, they will automatically search for any activity that looks suspicious across your environment. Many of the templates can be customized to search for, or filter out, activities, according to your needs. The alerts generated by these templates will create incidents that you can assign and investigate in your environment. Create an Azure Sentinel Detection rule via the steps below. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-detect-threats-built-in\">Tutorial: Detect threats out-of-the-box<\/a>.<\/p>\n<ol>\n<li>Sign into the <a href=\"https:\/\/portal.azure.com\/\">Azure Portal<\/a>.<\/li>\n<li>Search for and select <em>Azure Sentinel.<\/em><\/li>\n<li>In order to use a built-in template, click on <strong>Create rule<\/strong> to create a new active rule based on that template. Each entry has a list of required data sources that are automatically checked and this can result in <strong>Create rule<\/strong> being disabled.\n<img decoding=\"async\" class=\"alignnone size-full wp-image-19462\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-investigateAbnormalActivity-2.png\" alt=\"Image CMMC Series2 investigateAbnormalActivity\" width=\"351\" height=\"450\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-investigateAbnormalActivity-2.png 351w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-investigateAbnormalActivity-2-234x300.png 234w\" sizes=\"(max-width: 351px) 100vw, 351px\" \/><\/li>\n<li>This opens the rule creation wizard, based on the selected template. All the details are auto filled, and for <strong>Scheduled rules<\/strong> or <strong>Microsoft security rules<\/strong>, you can customize the logic to better suit your organization, or create additional rules based on the built-in template. After following the steps in the rule creation wizard and finished creating a rule based on the template, the new rule appears in the <strong>Active rules tab<\/strong>.<\/li>\n<\/ol>\n<p><strong>11) Optimize &amp; Report<\/strong><\/p>\n<p>There are numerous Azure solutions to facilitate log reporting, reduction and optimization. These capabilities range from threat reporting in Azure Sentinel, to log reporting in Azure Monitor, to usage reporting in Azure Advisor. Azure Active Directory provides the capability to report on user sign-in, usage, and insights. Create a User Sign-in report via the steps below. The Azure AD Sign-ins report provides user sign-in patterns, quantity of sign-ins and status of sign-ins. For more information, see <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/reports-monitoring\/concept-sign-ins#sign-ins-report\">Sign-in activity reports in the Azure Active Directory portal<\/a>.<\/p>\n<ol>\n<li>On the Azure portal menu, select <strong>Azure Active Directory<\/strong>, or search for and select <strong>Azure Active Directory<\/strong> from any page.<\/li>\n<li>Under <strong>Monitoring<\/strong>, select <strong>Sign-ins<\/strong> to open the <strong>Sign-ins report<\/strong>.\n<img decoding=\"async\" class=\"alignnone wp-image-19396\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport1.png\" alt=\"Image CMMC Series2 OptimizeReport1\" width=\"215\" height=\"277\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport1.png 495w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport1-233x300.png 233w\" sizes=\"(max-width: 215px) 100vw, 215px\" \/><\/li>\n<li>View and customize <strong>Sign-in reporting<\/strong>.\n<img decoding=\"async\" class=\"alignnone wp-image-19397\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport2.png\" alt=\"Image CMMC Series2 OptimizeReport2\" width=\"626\" height=\"298\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport2.png 1168w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport2-300x143.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport2-1024x487.png 1024w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/04\/CMMC-Series2-OptimizeReport2-768x366.png 768w\" sizes=\"(max-width: 626px) 100vw, 626px\" \/><\/li>\n<\/ol>\n<p><strong>Learn more about CMMC with Microsoft <\/strong><\/p>\n<p>Here are some of the best resource to learn more about CMMC in the cloud with Microsoft:<\/p>\n<ul>\n<li><a href=\"https:\/\/aka.ms\/CMMCResponse\">Accelerating CMMC compliance with Microsoft cloud (in depth review)<\/a><\/li>\n<li><a href=\"https:\/\/www.youtube.com\/watch?v=sey4aWuqtvk\">CMMC-AB Standards with Regan Edens &#8211; National Conversation<\/a><\/li>\n<li><a href=\"https:\/\/www.acq.osd.mil\/cmmc\/\">The Office of the Under Secretary of Defense for Acquisition and Sustainment CMMC Website<\/a><\/li>\n<li><a href=\"https:\/\/www.cmmcab.org\/\">The CMMC Accreditation Body Website<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/offering-dfars?view=o365-worldwide\">Defense Federal Acquisition Regulation Supplement (DFARS)<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/offering-nist-sp-800-171?view=o365-worldwide\">NIST SP 800-171 Compliance<\/a><\/li>\n<\/ul>\n<p>Bookmark the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Security blog<\/a> to keep up with our expert coverage on security matters and follow us at <a href=\"https:\/\/twitter.com\/@MSFTSecurity\">@MSFTSecurity<\/a> or visit our <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\">website<\/a> for the latest news and updates on cybersecurity.<\/p>\n<p>Are you a federal government agency that needs help with cybersecurity? Reach out to <a href=\"https:\/\/www.linkedin.com\/in\/tjbanasik\/\">TJ Banasik<\/a> or <a href=\"http:\/\/www.linkedin.com\/in\/marmci\">Mark McIntyre<\/a> for additional details on the content above, or if you have any other questions about Microsoft\u2019s cybersecurity investments for the federal government.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is the second in a ten-part blog series where we\u2019ll demonstrate principles of the Cybersecurity Maturity Model Certification (CMMC) aligned with Microsoft Azure. Subsequent blogs in the series will delve into asset &amp; configuration management, identification &amp; authentication, incident response, maintenance &amp; media protection, recovery &amp; risk management, security assessment &amp; risk management, system [&hellip;]<\/p>\n","protected":false},"author":16830,"featured_media":19415,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14],"tags":[3057,66,75,95,3055,3054],"class_list":["post-19389","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-learning","tag-accountability-management","tag-audit","tag-azure","tag-azure-government","tag-cmmc","tag-cybersecurity-maturity-model-certification"],"acf":[],"blog_post_summary":"<p>This is the second in a ten-part blog series where we\u2019ll demonstrate principles of the Cybersecurity Maturity Model Certification (CMMC) aligned with Microsoft Azure. Subsequent blogs in the series will delve into asset &amp; configuration management, identification &amp; authentication, incident response, maintenance &amp; media protection, recovery &amp; risk management, security assessment &amp; risk management, system [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/19389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/16830"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=19389"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/19389\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/19415"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=19389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=19389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=19389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}