{"id":20448,"date":"2021-05-06T06:00:14","date_gmt":"2021-05-06T13:00:14","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=20448"},"modified":"2021-05-18T09:35:05","modified_gmt":"2021-05-18T16:35:05","slug":"meeting-cmmc-level-3-on-azure","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/meeting-cmmc-level-3-on-azure\/","title":{"rendered":"Meeting CMMC Level 3 on Azure"},"content":{"rendered":"<p><b><i><span data-contrast=\"none\">Disclaimer<\/span><\/i><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">: <\/span><em>The CMMC Level 3 policy initiative and blueprint provides customers with a resource to support CMMC initiatives in Azure, however\u00a0compliant\u00a0in Azure Policy refers only to the policy definitions themselves. In addition, the compliance standard includes controls that are not addressed by any Azure Policy definitions at this time. Therefore, compliance in\u00a0Azure\u00a0Policy is only a partial view of your overall compliance status. Microsoft does not guarantee\u00a0nor\u00a0imply compliance with the regulatory framework, as all accreditation requirements and decisions are governed by the\u00a0<a href=\"https:\/\/www.cmmcab.org\/c3pao-lp\">CMMC Accreditation Body<\/a>. The associations between compliance domains, controls, and Azure Policy definitions for this compliance standard may change over time.\u00a0<\/em><\/p>\n<p>The Azure team just released a new CMMC Level 3 initiative for Azure Policy and a corresponding blueprint sample. These preview releases are available in Azure and Azure Government. In this blog post we break down the releases and how customers can use these tools to accelerate CMMC compliance in Azure.<\/p>\n<p><strong>Why\u00a0CMMC\u00a0Level\u00a03?\u00a0<\/strong><\/p>\n<p>Cybersecurity Maturity Model Certification (CMMC) is a new standard introduced by the US Department of Defense (DoD), which is intended to measure and certify Defense Industrial Base (DIB) contractors\u2019 ability to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in accordance with Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012 regulations.<\/p>\n<p>The previous iteration of the DFARS mandate specified contractors adhere to NIST\u00a0SP\u00a0800-171 which consists of 110 controls derived from the NIST\u00a0SP\u00a0800-53 framework.\u00a0CMMC Level 3 includes all 110 controls from NIST\u00a0SP\u00a0800-171, plus an additional 20 controls which are primarily focused on centralized security operations and modern cyber incident response. Additionally, each CMMC level must be certified through an audit conducted by a\u00a0certified\u00a0third-party\u00a0assessor\u00a0organization (C3PAO), as opposed to NIST\u00a0SP\u00a0800-171 which only required self-attestation.\u00a0While CMMC levels 4 and 5 expand further into cyber practices,\u00a0federal\u00a0contracts requiring those levels\u00a0are not expected to roll out\u00a0for some time.\u00a0Thus,\u00a0the\u00a0CMMC Level 3 framework provides an ideal starting point for\u00a0organizations\u00a0that wish to continue working with the DoD, in addition\u00a0to improving\u00a0their\u00a0overall security posture.<\/p>\n<p><b><span data-contrast=\"auto\">Regulatory\u00a0<\/span><\/b><b><span data-contrast=\"auto\">compliance\u00a0<\/span><\/b><b><span data-contrast=\"auto\">in Azure<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p style=\"text-align: left;\"><span data-contrast=\"auto\">Achieving<\/span><span data-contrast=\"auto\">\u00a0regulatory compliance\u00a0<\/span><span data-contrast=\"auto\">extends beyond<\/span><span data-contrast=\"auto\">\u00a0deploying a\u00a0<\/span><span data-contrast=\"auto\">specific tool<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">and\u00a0<\/span><span data-contrast=\"auto\">building a compliant environment<\/span><span data-contrast=\"auto\">\u00a0in Azure<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-contrast=\"auto\">M<\/span><span data-contrast=\"auto\">any of the controls within a framework extend to corporate-wide policies and processes, as well as to partner organizations and suppliers. This makes implementing regulatory initiatives a lengthy and complex process. However, Microsoft has\u00a0built\u00a0<\/span><a href=\"https:\/\/docs.microsoft.com\/en-us\/compliance\/regulatory\/offering-home\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"auto\">the\u00a0<\/span><span data-contrast=\"auto\">broadest set of compliance offerings\u00a0<\/span><span data-contrast=\"none\">in the industry<\/span><\/a><span data-contrast=\"auto\">, with tools and services designed to help organizations significantly reduce complexity and accelerate implementation.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">While this post will focus on a specific subset of Azure compliance offerings, it\u2019s important to reiterate that\u00a0<\/span><span data-contrast=\"auto\">a comprehensive approach<\/span><span data-contrast=\"auto\">\u00a0will be required for most organizations to achieve full compliance with CMMC, or any other regulatory framework.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Azure Policy<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Azure Policy helps customers enforce organizational standards and compliance across <\/span><span data-contrast=\"auto\">their\u00a0<\/span><span data-contrast=\"auto\">Azure\u00a0<\/span><span data-contrast=\"auto\">subscriptions and resources.\u00a0<\/span><span data-contrast=\"auto\">I<\/span><span data-contrast=\"auto\">n the Azure\u00a0<\/span><span data-contrast=\"auto\">p<\/span><span data-contrast=\"auto\">ortal<\/span><span data-contrast=\"auto\">, Azure Policy<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">provides a snapshot of\u00a0<\/span><span data-contrast=\"auto\">overall\u00a0<\/span><span data-contrast=\"auto\">resource compliance\u00a0<\/span><span data-contrast=\"auto\">against assigned policies<\/span><span data-contrast=\"auto\">,\u00a0<\/span><span data-contrast=\"auto\">detailed<\/span><span data-contrast=\"auto\">\u00a0resource-level\u00a0<\/span><span data-contrast=\"auto\">assessment results<\/span><span data-contrast=\"auto\">,\u00a0<\/span><span data-contrast=\"auto\">and<\/span><span data-contrast=\"auto\">\u00a0the ability to remediat<\/span><span data-contrast=\"auto\">e<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">non-compliant resources<\/span><span data-contrast=\"auto\">\u00a0at scale<\/span><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-1.png\"><img decoding=\"async\" class=\"alignnone wp-image-20449\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-1.png\" alt=\"Image CMMC 1\" width=\"700\" height=\"188\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-1.png 624w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-1-300x81.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p><em>Azure Policy overview page<\/em><\/p>\n<p>Within the scope of an assignment, Azure Policy evaluates resources by comparing resource properties to JSON formatted compliance conditions and rules known as policy definitions. Customers may choose to assign built-in definitions or create their own. Multiple definitions can be grouped together to form an initiative. Initiatives help customers manage policy at scale and can be used to facilitate a specific purpose or goal such as regulatory compliance. Azure provides built-in initiatives specific to regulatory compliance, and our latest release in this category is the <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/governance\/policy\/samples\/cmmc-l3\">CMMC Level 3 initiative<\/a>.<\/p>\n<p><b><span data-contrast=\"auto\">CMMC Level 3\u00a0<\/span><\/b><b><span data-contrast=\"auto\">policy initiative<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Customers can deploy the CMMC Level 3 initiative\u00a0<\/span><span data-contrast=\"auto\">using\u00a0<\/span><span data-contrast=\"auto\">the\u00a0<\/span><span data-contrast=\"auto\">Azure\u00a0<\/span><span data-contrast=\"auto\">or Azure Government\u00a0<\/span><span data-contrast=\"auto\">portal<\/span><span data-contrast=\"auto\">:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<ol>\n<li data-leveltext=\"%1.\" data-font=\"Segoe UI,Times New Roman\" data-listid=\"3\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Browse\u00a0<\/span><span data-contrast=\"auto\">to Policy<\/span><span data-contrast=\"auto\">, then\u00a0<\/span><span data-contrast=\"auto\">Definitions<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Segoe UI,Times New Roman\" data-listid=\"3\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Definition type<\/span><span data-contrast=\"auto\">:<\/span><span data-contrast=\"auto\">\u00a0<\/span><i><span data-contrast=\"auto\">Initiative<\/span><\/i><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Segoe UI,Times New Roman\" data-listid=\"3\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Type:\u00a0<\/span><i><span data-contrast=\"auto\">Built-in<\/span><\/i><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Segoe UI,Times New Roman\" data-listid=\"3\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Category<\/span><span data-contrast=\"auto\">:<\/span><i><span data-contrast=\"auto\">\u00a0Regulatory Compliance<\/span><\/i><span data-contrast=\"auto\">.\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"Segoe UI,Times New Roman\" data-listid=\"3\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Select the\u00a0<\/span><i><span data-contrast=\"auto\">[<\/span><\/i><i><span data-contrast=\"auto\">Preview<\/span><\/i><i><span data-contrast=\"auto\">]:<\/span><\/i><i><span data-contrast=\"auto\">\u00a0CMMC Level 3<\/span><\/i><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">i<\/span><span data-contrast=\"auto\">nitiative<\/span><span data-contrast=\"auto\">\u00a0then\u00a0<\/span><span data-contrast=\"auto\">select<\/span><span data-contrast=\"auto\">\u00a0an appropriate\u00a0<\/span><span data-contrast=\"auto\">scope<\/span><span data-contrast=\"auto\">,<\/span><span data-contrast=\"auto\"> and\u00a0<\/span><span data-contrast=\"auto\">scope and<\/span><span data-contrast=\"auto\">\u00a0click assign.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<\/ol>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-2.png\"><img decoding=\"async\" class=\"alignnone wp-image-20450\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-2.png\" alt=\"Image CMMC 2\" width=\"700\" height=\"517\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-2.png 659w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-2-300x222.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p><em>Azure Policy initiative deployment<\/em><\/p>\n<p>The initiative\u00a0preview\u00a0release includes\u00a0150+\u00a0policy definitions\u00a0that address\u00a0several\u00a0controls in the CMMC Level 3 framework.\u00a0There often is not a one-to-one or complete match between\u00a0a control\u00a0and one or more policy definitions. There are cases where a\u00a0control may have multiple policy definitions associated\u00a0with\u00a0it, and there are cases where a\u00a0policy definition may apply to multiple controls.\u00a0The compliance dashboard in\u00a0Azure\u00a0Policy allows customers to sort and filter by each of these categories\u00a0and view\u00a0individual controls, policies,\u00a0and resource compliance\/non-compliance\u00a0to gather additional information\u00a0as needed.<\/p>\n<p><figure id=\"attachment_20451\" aria-labelledby=\"figcaption_attachment_20451\" class=\"wp-caption alignnone\" ><a style=\"font-weight: bold; font-size: inherit; background-color: #f7f7f9;\" href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-3.png\"><img decoding=\"async\" class=\"wp-image-20451\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-3.png\" alt=\"Image CMMC 3\" width=\"700\" height=\"239\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-3.png 635w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-3-300x103.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><figcaption id=\"figcaption_attachment_20451\" class=\"wp-caption-text\">Azure Policy compliance dashboard<\/figcaption><\/figure><\/p>\n<p>While working toward compliance, it\u2019s important for customers to maintain awareness of controls that may not be addressed directly by the initiative. From the Azure Policy compliance dashboard (pictured above), customers can sort using the Total policies column in the Controls tab to determine which controls have no policy definitions associated with them. While we expect future releases to expand the number of addressable controls, many controls within regulatory frameworks require non-Azure implementations such as written policies and procedures, management of personnel, or intangibles that do not have a technical implementation. Therefore, compliance in Azure Policy is only a partial view of your overall compliance status.<\/p>\n<p><span data-contrast=\"auto\">Here<\/span><span data-contrast=\"auto\">&#8216;s\u00a0<\/span><span data-contrast=\"auto\">how to use the\u00a0<\/span><span data-contrast=\"auto\">CMMC L3\u00a0<\/span><span data-contrast=\"auto\">initiative to assess compliance:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-4.png\"><img decoding=\"async\" class=\"alignnone wp-image-20452\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-4.png\" alt=\"Image CMMC 4\" width=\"700\" height=\"289\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-4.png 628w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-4-300x124.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p><em>Azure Policy Control Overview<\/em><\/p>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\"> <a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-5.png\"><img decoding=\"async\" class=\"wp-image-20457 alignnone\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-5.png\" alt=\"Image CMMC 5\" width=\"700\" height=\"176\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-5.png 628w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-5-300x75.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/span><\/p>\n<p><span data-contrast=\"auto\">T<\/span><span data-contrast=\"auto\">he above image <\/span><span data-contrast=\"auto\">shows\u00a0<\/span><span data-contrast=\"auto\">details<\/span><span data-contrast=\"auto\">\u00a0for one of the CMMC\u00a0<\/span><span data-contrast=\"auto\">c<\/span><span data-contrast=\"auto\">ontrols<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-contrast=\"auto\">T<\/span><span data-contrast=\"auto\">he overview\u00a0<\/span><span data-contrast=\"auto\">shows<\/span><span data-contrast=\"auto\">:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<ol>\n<li><span data-contrast=\"auto\">Control ID\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Control Title\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Description<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Customer Actions<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Additional Content<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<\/ol>\n<p style=\"text-align: left;\"><span data-contrast=\"auto\">The Policies tab<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">shows\u00a0<\/span><span data-contrast=\"auto\">all the\u00a0<\/span><span data-contrast=\"auto\">policy definitions\u00a0<\/span><span data-contrast=\"auto\">associated with this specific control. In this instance the Control specifies to \u201ccontrol and monitor user-installed software<\/span><span data-contrast=\"auto\">.&#8221;<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">To meet this requirement, <\/span><span data-contrast=\"auto\">three<\/span><span data-contrast=\"auto\">\u00a0policy definitions\u00a0<\/span><span data-contrast=\"auto\">are used\u00a0<\/span><span data-contrast=\"auto\">to\u00a0<\/span><span data-contrast=\"auto\">assess\u00a0<\/span><span data-contrast=\"auto\">the control<\/span><span data-contrast=\"auto\">:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<ol>\n<li><span data-contrast=\"auto\">Adaptive application control is the primary mechanism in Azure to manage software installed on the guest OS.\u00a0<\/span><span data-contrast=\"auto\">A policy is included to\u00a0<\/span><span data-contrast=\"auto\">audit that this feature is\u00a0<\/span><span data-contrast=\"auto\">enabled<\/span><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">An additional policy is included to\u00a0<\/span><span data-contrast=\"auto\">ensure<\/span><span data-contrast=\"auto\">\u00a0that<\/span><span data-contrast=\"auto\">\u00a0the\u00a0<\/span><span data-contrast=\"auto\">allow list<\/span><span data-contrast=\"auto\">\u00a0within the application control policy is configured.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">B<\/span><span data-contrast=\"auto\">ecause adaptive application control is a feature of Security Center\u00a0<\/span><span data-contrast=\"auto\">with Azure De<\/span><span data-contrast=\"auto\">f<\/span><span data-contrast=\"auto\">ender enabled,\u00a0<\/span><span data-contrast=\"auto\">a policy\u00a0<\/span><span data-contrast=\"auto\">definition\u00a0<\/span><span data-contrast=\"auto\">is\u00a0<\/span><span data-contrast=\"auto\">included\u00a0<\/span><span data-contrast=\"auto\">to ensure that the\u00a0<\/span><span data-contrast=\"auto\">correct Security Center mode\u00a0<\/span><span data-contrast=\"auto\">is enabled.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">A\u00a0<\/span><span data-contrast=\"auto\">Windows\u00a0<\/span><span data-contrast=\"auto\">guest configuration policy\u00a0<\/span><span data-contrast=\"auto\">definition\u00a0<\/span><span data-contrast=\"auto\">is also included to ensure non-privileged users\u00a0<\/span><span data-contrast=\"auto\">cannot elevate permissions and install unauthorized software<\/span><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<\/ol>\n<p><span data-contrast=\"auto\">The resource compliance tab\u00a0<\/span><span data-contrast=\"auto\">shows<\/span><span data-contrast=\"auto\">\u00a0which resources are being audited by the policy\u00a0<\/span><span data-contrast=\"auto\">assignment\u00a0<\/span><span data-contrast=\"auto\">as well as their current compliance state<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">As you can see<\/span><span data-contrast=\"auto\">,<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">Azure\u00a0<\/span><span data-contrast=\"auto\">Policy provides an intuitive workflow for customers to implement and continuously monitor CMMC compliance in Azure<\/span><span data-contrast=\"auto\">\u00a0using the CMMC L3 initiative<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Azure Blueprints<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Azure Blueprints enable cloud architects and central information technology groups to define a repeatable set of Azure resources that implement and adhere to an organization&#8217;s standards, patterns, and requirements. This makes it possible for development teams to rapidly build and stand-up new environments in accordance with organizational compliance. Blueprints orchestrate the deployment of various artifacts including\u00a0<\/span><span data-contrast=\"none\">p<\/span><span data-contrast=\"none\">olicy\u00a0<\/span><span data-contrast=\"none\">a<\/span><span data-contrast=\"none\">ssignments,\u00a0<\/span><span data-contrast=\"none\">r<\/span><span data-contrast=\"none\">ole\u00a0<\/span><span data-contrast=\"none\">a<\/span><span data-contrast=\"none\">ssignments,<\/span><span data-contrast=\"none\">\u00a0and<\/span><span data-contrast=\"none\">\u00a0Azure Resource Manager\u00a0<\/span><span data-contrast=\"none\">templates resource<\/span><span data-contrast=\"none\">\u00a0groups<\/span><span data-contrast=\"none\">. Several\u00a0<\/span><span data-contrast=\"none\">built-in\u00a0<\/span><span data-contrast=\"none\">blueprint<\/span><span data-contrast=\"none\">\u00a0<\/span><span data-contrast=\"none\">samples\u00a0<\/span><span data-contrast=\"none\">are available\u00a0<\/span><span data-contrast=\"none\">in\u00a0<\/span><span data-contrast=\"none\">the Azure portal, and the CMMC Level 3\u00a0<\/span><span data-contrast=\"none\">b<\/span><span data-contrast=\"none\">lueprint is our latest preview release.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">CMMC Level 3\u00a0<\/span><\/b><b><span data-contrast=\"auto\">blueprint<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Customers can\u00a0<\/span><span data-contrast=\"auto\">find<\/span><span data-contrast=\"auto\">\u00a0the CMMC Level 3\u00a0<\/span><span data-contrast=\"auto\">blueprint sample in the Azure\u00a0<\/span><span data-contrast=\"auto\">portal by browsing to Blueprints<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">then\u00a0<\/span><span data-contrast=\"auto\">Blueprint\u00a0<\/span><span data-contrast=\"auto\">definitions\u00a0<\/span><span data-contrast=\"auto\">and clicking Create\u00a0<\/span><span data-contrast=\"auto\">b<\/span><span data-contrast=\"auto\">lueprint<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-6.png\"><img decoding=\"async\" class=\"alignnone wp-image-20458\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-6.png\" alt=\"Image CMMC 6\" width=\"700\" height=\"672\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-6.png 624w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-6-300x288.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p><em>Azure Blueprint sample deployment<\/em><\/p>\n<p><span data-contrast=\"auto\">The CMMC Level 3\u00a0<\/span><span data-contrast=\"auto\">b<\/span><span data-contrast=\"auto\">lueprint\u00a0<\/span><span data-contrast=\"auto\">sample\u00a0<\/span><span data-contrast=\"auto\">currently contains\u00a0<\/span><span data-contrast=\"auto\">a single<\/span><span data-contrast=\"auto\">\u00a0artifact, which is a\u00a0<\/span><span data-contrast=\"auto\">policy a<\/span><span data-contrast=\"auto\">ssignment that deploys the CMMC <\/span><span data-contrast=\"auto\">p<\/span><span data-contrast=\"auto\">olicy\u00a0initiative<\/span><span data-contrast=\"auto\">,<\/span><span data-contrast=\"auto\">\u00a0described above. This approach\u00a0<\/span><span data-contrast=\"auto\">allows\u00a0<\/span><span data-contrast=\"auto\">customization of the b<\/span><span data-contrast=\"auto\">lueprint<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">representative to\u00a0<\/span><span data-contrast=\"auto\">the\u00a0<\/span><span data-contrast=\"auto\">environment and specific needs<\/span><span data-contrast=\"auto\">\u00a0of each\u00a0<\/span><span data-contrast=\"auto\">customer<\/span><span data-contrast=\"auto\">.<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">For example, when deploying the\u00a0<\/span><span data-contrast=\"auto\">blueprint<\/span><span data-contrast=\"auto\">, customers can click\u00a0<\/span><i><span data-contrast=\"auto\">Add\u00a0<\/span><\/i><i><span data-contrast=\"auto\">artifact<\/span><\/i><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">to include one or more<\/span><span data-contrast=\"auto\">\u00a0Azure resource manager<\/span><span data-contrast=\"auto\">\u00a0template<\/span><span data-contrast=\"auto\">s<\/span><span data-contrast=\"auto\">\u00a0to include during the\u00a0<\/span><span data-contrast=\"auto\">blueprint\u00a0<\/span><span data-contrast=\"auto\">deployment<\/span><span data-contrast=\"auto\">.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-7.png\"><img decoding=\"async\" class=\"alignnone wp-image-20459\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-7.png\" alt=\"Image CMMC 7\" width=\"700\" height=\"357\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-7.png 619w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-7-300x153.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p><em>Azure Blueprint add artifact<\/em><\/p>\n<p><span data-contrast=\"auto\">This release will be followed by\u00a0<\/span><span data-contrast=\"auto\">an additional CMMC Level 3\u00a0<\/span><span data-contrast=\"auto\">blueprint\u00a0<\/span><span data-contrast=\"auto\">that will include\u00a0<\/span><span data-contrast=\"auto\">resource manager<\/span><span data-contrast=\"auto\">\u00a0templates to scaffold a CMMC reference architecture. This will include automated implementation and configuration of services\u00a0<\/span><span data-contrast=\"auto\">such as Security Center, Sentinel, Log Analytics, and Azure Active Directory Premium features to address specific controls that are audited by the policy initiative<\/span><span data-contrast=\"auto\">, and we are targeting an early summer preview release for this update.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">A<\/span><\/b><b><span data-contrast=\"auto\">zure Security Center r<\/span><\/b><b><span data-contrast=\"auto\">egulatory\u00a0<\/span><\/b><b><span data-contrast=\"auto\">c<\/span><\/b><b><span data-contrast=\"auto\">ompliance\u00a0<\/span><\/b><b><span data-contrast=\"auto\">d<\/span><\/b><b><span data-contrast=\"auto\">ashboard<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Azure Security Center<\/span><span data-contrast=\"auto\">\u00a0(ASC)<\/span><span data-contrast=\"auto\">\u00a0is<\/span><span data-contrast=\"auto\">\u00a0a\u00a0<\/span><span data-contrast=\"auto\">c<\/span><span data-contrast=\"auto\">l<\/span><span data-contrast=\"auto\">oud security posture management (CSPM) and\u00a0<\/span><span data-contrast=\"auto\">c<\/span><span data-contrast=\"auto\">loud workload protection (CWP)\u00a0<\/span><span data-contrast=\"auto\">platform that provides customers with<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">c<\/span><span data-contrast=\"auto\">entralized<\/span><span data-contrast=\"auto\">\u00a0views o<\/span><span data-contrast=\"auto\">f<\/span><span data-contrast=\"auto\">\u00a0Azure<\/span><span data-contrast=\"auto\">\u00a0resources\u00a0<\/span><span data-contrast=\"auto\">and security controls<\/span><span data-contrast=\"auto\">.<\/span><span data-contrast=\"auto\">\u00a0\u00a0<\/span><span data-contrast=\"auto\">The platform\u00a0<\/span><span data-contrast=\"auto\">includes<\/span><span data-contrast=\"auto\">\u00a0several advanced\u00a0<\/span><span data-contrast=\"auto\">p<\/span><span data-contrast=\"auto\">rotection<\/span><span data-contrast=\"auto\">\u00a0features in addition to offering recommendations to mitigate risks.<\/span><span data-contrast=\"auto\">\u00a0\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">One of these features can be found under the\u00a0<\/span><span data-contrast=\"none\">regulatory compliance section,\u00a0<\/span><span data-contrast=\"none\">where\u00a0<\/span><span data-contrast=\"none\">customers can gain<\/span><span data-contrast=\"none\">\u00a0insight into\u00a0<\/span><span data-contrast=\"none\">their\u00a0<\/span><span data-contrast=\"none\">compliance posture for a set of supported standards and regulations<\/span><span data-contrast=\"none\">\u00a0<\/span><span data-contrast=\"none\">based on continuous assessments of\u00a0<\/span><span data-contrast=\"none\">the<\/span><span data-contrast=\"none\">ir Azure environment.<\/span><span data-contrast=\"none\">\u00a0 In fact, these dashboards are derivatives of the underl<\/span><span data-contrast=\"none\">y<\/span><span data-contrast=\"none\">ing<\/span><span data-contrast=\"none\">\u00a0policy initiative, and will be automatically added when the initiative is assigned to a subscription that is monitored by\u00a0Security\u00a0Center.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The CMMC Level 3 regulatory compliance dashboard\u00a0<\/span><span data-contrast=\"auto\">consolidates\u00a0<\/span><span data-contrast=\"auto\">all<\/span><span data-contrast=\"auto\">\u00a0the controls within the framework\u00a0<\/span><span data-contrast=\"auto\">into<\/span><span data-contrast=\"auto\">\u00a0a drop-down\u00a0<\/span><span data-contrast=\"auto\">view\u00a0<\/span><span data-contrast=\"auto\">which is organized by\u00a0<\/span><span data-contrast=\"auto\">family &gt; maturity level &gt; and control.<\/span><span data-contrast=\"auto\"> When a control is expanded,\u00a0<\/span><span data-contrast=\"auto\">the associated policies are displayed as customer responsibilities, along with resource compliance status.<\/span><span data-contrast=\"auto\">\u00a0\u00a0<\/span><span data-contrast=\"auto\">Customers can click on a recommendation to see additional information, remediate via quick fix (<\/span><span data-contrast=\"auto\">limited to specific recommendations), trigger a logic app, or create an exemption<\/span><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">*C<\/span><span data-contrast=\"auto\">ertain controls will be greyed out, as these\u00a0<\/span><span data-contrast=\"auto\">represent\u00a0<\/span><span data-contrast=\"auto\">controls\u00a0<\/span><span data-contrast=\"auto\">that\u00a0<\/span><span data-contrast=\"auto\">are not currently address<\/span><span data-contrast=\"auto\">able<\/span><span data-contrast=\"auto\">\u00a0by Azure policy.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><a style=\"font-weight: bold; font-size: inherit; background-color: #f7f7f9;\" href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-8.png\"><img decoding=\"async\" class=\"alignnone wp-image-20460\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-8.png\" alt=\"Image CMMC 8\" width=\"700\" height=\"334\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-8.png 684w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/CMMC-8-300x143.png 300w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p><em>CMMC Level 3 regulatory compliance dashboard<\/em><\/p>\n<p><b><span data-contrast=\"auto\">Azure Sentinel Cybersecurity Maturity Model Certification (CMMC) Workbook<\/span><\/b><\/p>\n<p>The Azure Sentinel CMMC Workbook provides a mechanism for viewing log queries aligned to CMMC controls across the Azure cloud including Microsoft security offerings, Office 365, Teams, Intune, Windows Virtual Desktop and many more. This workbook enables Security Architects, Engineers, SecOps Analysts, Managers, and IT Pros to gain situational awareness for the security posture of cloud workloads. There are also recommendations for selecting, designing, deploying, and configuring Microsoft offerings for alignment with respective CMMC requirements\u00a0and practices.\u00a0The workbook features 250+ control cards aligned to the 17 CMMC control families across all 5 maturity levels with selectable GUI buttons for navigation.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/sentinel-wb.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-20543\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/sentinel-wb.png\" alt=\"Image sentinel wb\" width=\"736\" height=\"322\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/sentinel-wb.png 736w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/05\/sentinel-wb-300x131.png 300w\" sizes=\"(max-width: 736px) 100vw, 736px\" \/><\/a><\/p>\n<p><b>Deploying the Workbook<\/b><\/p>\n<p>Follow the steps below to enable the workbook: Requirements: Azure Sentinel Workspace and Security Reader rights.<\/p>\n<ol>\n<li>From the <a href=\"https:\/\/portal.azure.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-auth=\"NotApplicable\" data-linkindex=\"1\">Azure portal<\/a>, navigate to\u00a0<b>Azure Sentinel<\/b><\/li>\n<li>Select <b>Workbooks &gt; Templates<\/b><\/li>\n<li>Search <i>CMMC<\/i>\u00a0and select\u00a0<b>Save\u00a0<\/b>to add to\u00a0<b>My Workbooks<\/b><\/li>\n<\/ol>\n<p><b><span data-contrast=\"auto\">Learn more about CMMC with Microsoft:\u00a0<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/public-sector-blog\/accelerating-cmmc-compliance-for-microsoft-cloud-in-depth-review\/ba-p\/1825671\">Accelerating CMMC Compliance for Microsoft Cloud<\/a><\/p>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/public-sector-blog\/microsoft-cmmc-acceleration-program-update-january-2021\/ba-p\/2033499\"><span data-contrast=\"none\">CMMC Acceleration Program January Update<\/span><\/a><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Azure team just released a new CMMC Level 3 initiative for Azure Policy and a corresponding blueprint sample. These preview releases are available in Azure and Azure Government. In this blog post we break down the releases and how customers can use these tools to accelerate CMMC compliance in Azure.<\/p>\n","protected":false},"author":60096,"featured_media":20496,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[75,91,95,3055,216],"class_list":["post-20448","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azuregov","tag-azure","tag-azure-gov","tag-azure-government","tag-cmmc","tag-cybersecurity"],"acf":[],"blog_post_summary":"<p>The Azure team just released a new CMMC Level 3 initiative for Azure Policy and a corresponding blueprint sample. These preview releases are available in Azure and Azure Government. In this blog post we break down the releases and how customers can use these tools to accelerate CMMC compliance in Azure.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20448","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/60096"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=20448"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20448\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/20496"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=20448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=20448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=20448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}