🎯 Mục Tiêu Chương
- Bật và quản lý Microsoft Defender for Cloud trên subscription.
- Đọc, phân tích và cải thiện Secure Score.
- Đánh giá compliance theo Microsoft Cloud Security Benchmark.
- Bật Defender Plans cho Servers, Storage, Containers, Databases.
- Quản lý vulnerability assessment và workflow automation.
📚 11.1 Overview & Secure Score
Microsoft Defender for Cloud là nền tảng bảo mật tích hợp gồm 2 trụ cột: CSPM (Cloud Security Posture Management) và CWPP (Cloud Workload Protection Platform).
- • Secure Score: điểm bảo mật tổng hợp từ 0–100%
- • Recommendations: danh sách vấn đề và cách fix
- • Inventory: toàn bộ resource với trạng thái bảo mật
- • Attack path analysis: mô phỏng đường tấn công (Defender CSPM)
- • Cloud Security Explorer: query dạng graph
- • Defender Plans bật per-resource type
- • Real-time threat detection và alerts
- • Adaptive application controls
- • File integrity monitoring
- • Network map và Just-in-time access
Score = Tổng điểm đạt / Tổng điểm tối đa × 100%. Mỗi recommendation có Max Score và Current Score. Fix một recommendation → score tăng theo weight tương ứng.
📚 11.2 Regulatory Compliance
Defender for Cloud mapping resource configuration tới các security control frameworks theo chuẩn quốc tế.
- • Microsoft Cloud Security Benchmark (MCSB) — mặc định
- • NIST SP 800-53
- • ISO 27001
- • PCI DSS v4
- • SOC 2
- • CIS Benchmarks
- 1. Chọn standard (VD: MCSB)
- 2. Xem % controls passed/failed
- 3. Drill-down vào control cụ thể
- 4. Xem resource non-compliant
- 5. Export PDF/Excel report cho audit
- 6. Tạo custom standard từ policy initiative
📚 11.3 Defender Plans
Mỗi Defender Plan bật riêng cho từng loại resource. Free tier chỉ có CSPM cơ bản — Defender Plans cung cấp threat detection nâng cao.
JIT, adaptive controls, file integrity. Plan 2 thêm: agentless scanning, Defender Vulnerability Management, 500 MB free log.
Phát hiện anomaly access, malware scanning (on-upload), sensitive data discovery. Alert khi download lớn bất thường.
Runtime threat detection cho AKS/EKS/GKE. Image vulnerability scanning. Kubernetes control plane audit.
SQL injection detection, anomaly login, brute force. Bao gồm Azure SQL, SQL on VM, Open-source DB (MySQL, PostgreSQL, MariaDB).
Phát hiện tấn công web (dangling DNS, suspicious activity). Không cần agent — sử dụng telemetry App Service platform.
Alert khi truy cập bất thường: nhiều secret reads trong thời gian ngắn, access từ IP lạ, credential compromise pattern.
📚 11.4–11.6 Vulnerability Management, DevOps & Automation
- • Agentless scanning cho VM (Plan 2)
- • Microsoft Defender Vulnerability Management integration
- • CVE list với severity và remediation guide
- • Software inventory
- • Kết nối GitHub, Azure DevOps, GitLab
- • IaC scanning (Terraform, Bicep, ARM)
- • Secret scanning trong code
- • Security posture cho code repos
- • Logic App trigger khi có alert/recommendation
- • Auto-notify Teams/Email
- • Auto-remediate low-risk findings
- • ServiceNow/Jira ticket creation
🧪 Lab Trong Chương
Bật Defender for Cloud & Phân tích Secure Score
Bật plans, xem Secure Score, phân tích top recommendations, thực hiện ít nhất một remediation và xem score thay đổi.
Đánh giá Regulatory Compliance
Xem MCSB dashboard, drill-down control failed, xác định resource non-compliant, export compliance report.
Defender for Servers & Vulnerability Assessment
Bật Defender for Servers, kiểm tra VM inventory, bật agentless scanning, xem CVE findings và thực hiện remediation.
Bật Defender for Storage
Bật Defender for Storage, cấu hình malware scanning, kích hoạt activity test, xem alerts và cấu hình notification cơ bản.
✅ Checklist Cuối Chương
- Bật được Defender for Cloud và ít nhất 2 Defender Plans.
- Đọc và giải thích được Secure Score cho stakeholder.
- Xem và export được Regulatory Compliance dashboard.
- Phân biệt được các Defender Plans và use case của từng loại.
- Hiểu vulnerability management workflow và workflow automation.