Microsoft Defender for Cloud
Cloud and workloads

Determine multicloud compliance requirements for AWS and GCP

In brief

The article was retitled and restructured with new overview and compliance-planning sections. It now explicitly covers assessing AWS and GCP compliance requirements and links to enhanced security features guidance.

What Defender admins need to know

Administrators can use the updated structure and links when planning multicloud compliance requirements; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Determine compliance requirements

Overview

This article is part of a series to provide guidance as you design a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) solution across multicloud resources with Microsoft Defender for Cloud. It covers how to identify and assess compliance requirements for AWS and GCP environments, including default standards, available benchmarks, and custom assessments.

GoalCompliance planning goals

Identify compliance requirements in your organization as you design your multicloud solution.

Get started with compliance requirements assessment

Defender for Cloud continually assesses your resource configuration against compliance controls and best practices in the standards and benchmarks applied in your subscriptions.

  • Every subscription with the GCP connector has the GCP Default benchmark assigned.
  • For AWS and GCP, the compliance monitoring freshness interval is 4 hours.

After you enable enhanced security features,enhanced security features in a Defender plan, you can add other compliance standards to the dashboard. Regulatory compliance is available when you enable at least one Defender plan on the subscription where the multicloud connector is located.

Additionally, you can create custom standards and assessments to align with your organizational requirements. For guidance, see Custom standards and assessments for AWS and Custom standards and assessments for GCP.