Skip to content

Commit 24f30e2

Browse files
committed
Added lightbox to hard to read graphic
1 parent a60d3af commit 24f30e2

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

learn-pr/wwl-sci/evaluate-regulatory-compliance/includes/2-understand-compliance-standards-controls.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ Other default benchmarks apply for non-Azure clouds. When you connect AWS accoun
2525

2626
A compliance standard consists of multiple compliance controls—logical groups of related security recommendations. Each control represents a specific security requirement from the standard. Defender for Cloud continuously assesses in-scope resources against controls that support automated evaluation.
2727

28-
:::image type="content" source="../media/compliance-hierarchy.png" alt-text="Diagram showing the hierarchy of a compliance standard: standard at the top, decomposed into control domains, each containing individual controls, each with a Pass, Fail, or Not Available assessment state.":::
28+
:::image type="content" source="../media/compliance-hierarchy.png" alt-text="Diagram showing the hierarchy of a compliance standard: standard at the top, decomposed into control domains, each containing individual controls, each with a Pass, Fail, or Not Available assessment state." lightbox="../media/compliance-hierarchy.png":::
2929

3030
Three assessment states indicate compliance status for each control:
3131

@@ -37,7 +37,7 @@ Three assessment states indicate compliance status for each control:
3737

3838
The following diagram shows how these states appear when you drill into a single control. ISO 27001 control A.9.1 breaks into two subcontrols, each with its own assessment state and the specific Defender for Cloud assessments that drive it.
3939

40-
:::image type="content" source="../media/compliance-subcontrol-drilldown.png" alt-text="Diagram showing ISO 27001 control A.9.1 broken into subcontrols A.9.1.1 and A.9.1.2, each with a Pass or Fail status and the specific Defender for Cloud assessments that determine that status.":::
40+
:::image type="content" source="../media/compliance-subcontrol-drilldown.png" alt-text="Diagram showing ISO 27001 control A.9.1 broken into subcontrols A.9.1.1 and A.9.1.2, each with a Pass or Fail status and the specific Defender for Cloud assessments that determine that status." lightbox="../media/compliance-subcontrol-drilldown.png":::
4141

4242
The third state—greyed out controls—often causes confusion during initial compliance reviews. These controls represent requirements Defender for Cloud can't automate, not missing security coverage. Grayed-out controls typically fall into three categories: procedural or process controls (like security awareness training requirements), platform responsibilities under the shared responsibility model (physical datacenter security), or controls with no implemented automated assessment yet. For Contoso Healthcare, ISO 27001 includes many process-oriented controls that require manual attestation rather than automated validation.
4343

0 commit comments

Comments
 (0)