What is the CIS Azure Foundations Benchmark?
The CIS Microsoft Azure Foundations Benchmark is the consensus security baseline for Azure environments, covering identity and access management, storage account security, network configuration, and logging and monitoring, among other sections. Each recommendation specifies the secure setting, the rationale, and audit and remediation steps. Because the checks read platform configuration rather than host state, the benchmark is assessed agentlessly through Azure APIs. It is the standard starting point for hardening an Azure subscription.
The longer answer.
The identity section addresses account and authentication hygiene for the tenant; storage covers encryption, access restrictions, and public-exposure settings on storage accounts; networking restricts inbound access paths; and logging and monitoring ensures activity logging and alerting are configured so changes are recorded. Together these sections close the most common Azure misconfiguration classes.
Because Azure configuration changes continuously as teams deploy resources, a one-time assessment goes stale quickly. Continuous agentless scanning with drift detection keeps the subscription verified between audits, and CISGuard maps each result to NIST 800-53, ISO 27001, and SOC 2 so the same scan feeds every framework in scope.
More questions on Fundamentals?
Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.