{"id":40627,"date":"2021-04-27T16:00:59","date_gmt":"2021-04-27T16:00:59","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=93379"},"modified":"2021-04-27T16:00:59","modified_gmt":"2021-04-27T16:00:59","slug":"meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/","title":{"rendered":"Meet critical infrastructure security compliance requirements with Microsoft 365"},"content":{"rendered":"<p>Critical infrastructure operators face a hostile cyber threat environment and a complex compliance landscape. Every operator of an industrial control system also operates an IT network to service its productivity needs. A supervisory control and data acquisition (SCADA) system operator of a power grid or chemical plant needs email, databases, and business applications to support it, much like any enterprise.<\/p>\n<p>IT environments, with their large attack surface, can be the entryway to attack critical infrastructure even where those IT systems are not critical infrastructure themselves. Security and compliance failures may include life safety, environmental, or national security consequences\u2014a different risk management challenge from other enterprise IT systems.<\/p>\n<p>Ransomware, thought more of as an IT problem as opposed to an industrial control system (ICS) one, has been used to attack critical infrastructure operators <a href=\"https:\/\/news.microsoft.com\/transform\/hackers-hit-norsk-hydro-ransomware-company-responded-transparency\/\" target=\"_blank\" rel=\"noopener noreferrer\">Norsk Hydro<\/a>, <a href=\"https:\/\/latesthackingnews.com\/2021\/02\/08\/two-brazil-electric-power-utility-firms-disclosed-ransomware-attack-around-the-same-time\/#:~:text=Brazil%20Electric%20Power%20Utility%20Firms%20Suffered%20Ransomware%20Attack,1962%2C%20it%E2%80%99s%20also%20the%20tenth-largest%20in%20the%20world.\" target=\"_blank\" rel=\"noopener noreferrer\">Brazilian utilities Electrobras and Copel<\/a>, as well as <a href=\"https:\/\/www.securityweek.com\/massachusetts-electric-utility-hit-ransomware\" target=\"_blank\" rel=\"noopener noreferrer\">Reading Municipal Light Department<\/a> and <a href=\"https:\/\/www.securityweek.com\/michigan-power-and-water-utility-hit-ransomware-attack\" target=\"_blank\" rel=\"noopener noreferrer\">Lansing Board of Water and Light<\/a> among other US utilities. Dragos and IBM X-Force identified <a href=\"https:\/\/www.dragos.com\/resource\/ransomware-in-ics-environments\/\" target=\"_blank\" rel=\"noopener noreferrer\">194 ransomware attacks against industrial entities<\/a> between 2018 and 2020, including <a href=\"https:\/\/www.dragos.com\/blog\/industry-news\/ekans-ransomware-and-ics-operations\/\" target=\"_blank\" rel=\"noopener noreferrer\">ICS-specific strains like EKANS<\/a>.<\/p>\n<p>The range of threats to our increasingly converged IT and ICS environments highlights the need for a combined approach to IT and ICS security.<\/p>\n<p><a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Defender for IoT<\/a> is the cornerstone of security for on-premises, cloud, and hybrid ICS. In addition to the <a href=\"https:\/\/docs.microsoft.com\/en-us\/compliance\/assurance\/assurance-malware-and-ransomware-protection\" target=\"_blank\" rel=\"noopener noreferrer\">anti-malware features of Microsoft 365<\/a>, the integration of Advanced Threat Protection (ATP) and Microsoft Compliance Manager to manage, visualize, and report on standards-based compliance are also foundational.<\/p>\n<h2>Complex compliance landscape<\/h2>\n<p>As the cyber threat landscape to ICS has grown more hostile and publicized, the compliance responsibilities of critical infrastructure operators have increased as well. In the US and Canada, Bulk Electric System (BES) participants need to comply with the North American Electric Reliability Corporation Critical Infrastructure Protection Standards (NERC CIP), as well as using NIST 800-53 as the basis for their organizational security policies and benchmarking to the <a href=\"https:\/\/docs.microsoft.com\/en-us\/compliance\/regulatory\/offering-nist-csf\" target=\"_blank\" rel=\"noopener noreferrer\">National Institute of Standards and Technology (NIST) Cybersecurity Framework<\/a>. They may also be architecting their ICS to <a href=\"https:\/\/www.isa.org\/standards-and-publications\/isa-standards\/isa-standards-committees\/isa99\" target=\"_blank\" rel=\"noopener noreferrer\">IEC62443\/ISA 99<\/a>. Many forward-looking utilities are increasing their use of the cloud through infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS) like Microsoft 365 with Zero Trust architecture.<\/p>\n<p>While NERC CIP standards were written around on-premises systems, NERC has become more open to Registered Entities\u2019 use of the cloud for <a href=\"https:\/\/www.nerc.com\/files\/Glossary_of_Terms.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Bulk Electric System Cyber System Information (BCSI)<\/a>. This includes <a href=\"https:\/\/www.nerc.com\/FilingsOrders\/us\/FERCOrdersRules\/FERC%20Order%20-%2020201217-3128(14915634).pdf\" target=\"_blank\" rel=\"noopener noreferrer\">NERC\u2019s Order on Virtualization and Cloud Computing Services<\/a> and their <a href=\"https:\/\/www.nerc.com\/pa\/Stand\/Project201902BCSIAccessManagement\/2019-02_Technical%20Rationale_CIP-011-3_201912.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Technical Rationale for Reliability Standard CIP-011-3<\/a>, where they discuss risk assessment of a cloud services provider. This risk assessment will include the ongoing standards-based assessment of the cloud service provider.<\/p>\n<h2>Comprehensive and efficient compliance<\/h2>\n<p>As an organization moves workloads to the cloud, they move responsibility for a portion of the security controls to the cloud service provider.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93400 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility.png\" alt=\"The shared responsibility model for cloud security. As cloud service provider takes responsibility for controls, the cloud customer can use their resources to focus on the controls for which they remain responsible.\" width=\"1410\" height=\"795\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility.png 1410w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility-300x169.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility-1024x577.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility-768x433.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility-767x431.png 767w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/updated-shared-responsibility-539x303.png 539w\" sizes=\"auto, (max-width: 1410px) 100vw, 1410px\"><\/p>\n<p>The organization can thus focus its resources on the remaining security controls and on vetting how the cloud service provider manages the security controls for which it is responsible.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93391 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST.jpg\" alt=\"With Office 365, customers dramatically reduce the number of NIST 800-53 controls they are responsible for as opposed to an on premises deployment.\" width=\"800\" height=\"450\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST.jpg 800w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST-300x169.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST-768x432.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST-687x385.jpg 687w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST-767x431.jpg 767w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/NIST-539x303.jpg 539w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\"><\/p>\n<p>When customers use Office 365, Microsoft helps them manage 79 percent of the 1,021 NIST 800-53 controls, so customers need only focus on implementing and maintaining the remaining 21 percent of the controls. By using the shared responsibility model, these customer resources are made available to further secure their systems. Customers that are using on-premises infrastructure to provide those functions need to implement and maintain all 1,021 controls.<\/p>\n<h2>Tools for comprehensive and efficient compliance<\/h2>\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager?view=o365-worldwide\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Compliance Manager<\/a> is a feature in Microsoft 365 compliance center. It uses signals from the customer\u2019s Microsoft 365 tenant, Microsoft\u2019s compliance program, and workflows completed by the customer to manage and report compliance against regulatory and industry-standard templates. These templates include NERC CIP, NIST Cybersecurity Framework (CSF), NIST 800-53, and the US Protecting and Securing Chemical Facilities from Terrorist Attacks Act (H.R. 4007), as well as <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager-templates-list?view=o365-worldwide\" target=\"_blank\" rel=\"noopener noreferrer\">more than 330 standards-based assessments<\/a> globally. You can also create custom templates based on other standards or mapped to your own policies and control set.<\/p>\n<p>With each Compliance Manager assessment template, you get simplified guidance on \u201cwhat to do\u201d to meet the regulatory requirements. In this regard, you get to understand what controls are Microsoft\u2019s responsibility as your cloud service provider and what controls are your responsibility. Furthermore, for each of the controls that are your responsibility, we break down actions that you need to take to meet these control requirements. These actions can be procedural, documentation, or technical.<\/p>\n<p>For technical actions, you get step-by-step guidance on how to use Microsoft security, compliance, identity, or management solutions to implement and test technical actions. With this detailed information, you can efficiently implement, test, and demonstrate your compliance against regulations as per your industry and region. This information also helps you to draw maximum benefits from your Microsoft 365 security and compliance solutions. Once you create assessments within Compliance Manager, we make it very easy for you to understand what solutions you can use to implement and test technical actions on Compliance Manager.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93392 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/CM.png\" alt=\"The Microsoft 365 Compliance Manager Solutions page, showing how the various solutions contribute to Compliance Score and compliance posture.\" width=\"1808\" height=\"807\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/CM.png 1808w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/CM-300x134.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/CM-1024x457.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/CM-768x343.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/CM-1536x686.png 1536w\" sizes=\"auto, (max-width: 1808px) 100vw, 1808px\"><\/p>\n<p>You can use the <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager-templates?view=o365-worldwide#creating-and-modifying-templates-overview\" target=\"_blank\" rel=\"noopener noreferrer\">custom assessment feature<\/a> to \u201cextend\u201d Compliance Manager assessment templates to track compliance against any non-Microsoft 365 assets as well. With this functionality, Compliance Manager helps you to track and manage compliance across all your assets.<\/p>\n<p>There are different template sets <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager-templates-list?view=o365-worldwide#included-templates\" target=\"_blank\" rel=\"noopener noreferrer\">available for the different license levels<\/a>.<\/p>\n<p>Microsoft updates the assessment templates when the standards change, relieving the customer of this responsibility. The changes are called out to the customer and the option to <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager-assessments?view=o365-worldwide#what-causes-an-update\" target=\"_blank\" rel=\"noopener noreferrer\">update the assessment<\/a> is provided.<\/p>\n<p>Compliance Manager tracks, reports, and provides visualizations for:<\/p>\n<ul>\n<li><strong>Microsoft-managed controls:<\/strong> these are controls for Microsoft cloud services, for which Microsoft is responsible for implementing.<\/li>\n<li><strong>Your controls:<\/strong> these are controls implemented and managed by your organization, sometimes referred to as \u201ccustomer-managed controls.\u201d<\/li>\n<li><strong>Shared controls:<\/strong> these are controls that both your organization and Microsoft share responsibility for implementing.<\/li>\n<\/ul>\n<p>The assessments are provided with visualizations that allow the user to drill down into the individual control status and view evidence. High impact improvement actions are suggested.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93393 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess.jpg\" alt=\"Microsoft 365 Compliance Manager NIST Cybersecurity Framework assessment dashboard.\" width=\"2093\" height=\"1360\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess.jpg 2093w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-300x195.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-1024x665.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-768x499.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-1536x998.jpg 1536w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-2048x1331.jpg 2048w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-200x130.jpg 200w\" sizes=\"auto, (max-width: 2093px) 100vw, 2093px\"><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93394 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-3.png\" alt=\"Microsoft 365 Compliance Manager NIST Cybersecurity Framework controls view with benchmark visualization.\" width=\"1685\" height=\"871\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-3.png 1685w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-3-300x155.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-3-1024x529.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-3-768x397.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Assess-3-1536x794.png 1536w\" sizes=\"auto, (max-width: 1685px) 100vw, 1685px\"><\/p>\n<p>Compliance Manager covers both the Microsoft and customer-managed controls as part of the shared cloud security and compliance responsibility model. Automated workflows and evidence repositories are provided for customer-managed and shared controls.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93395 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Audit.jpg\" alt=\"Microsoft 365 customer control workflow. Assign a control to a team member to provide input and upload evidence on a schedule to support customer's compliance program.\" width=\"1785\" height=\"935\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Audit.jpg 1785w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Audit-300x157.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Audit-1024x536.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Audit-768x402.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/Audit-1536x805.jpg 1536w\" sizes=\"auto, (max-width: 1785px) 100vw, 1785px\"><\/p>\n<p>You can assign a stakeholder and an automated message with instructions and upload link is provided on a schedule to remind them of the compliance activity required, report status, and upload evidence. This provides an efficient and defensible system to respond to auditors and benchmark compliance programs.<\/p>\n<p>Many of the controls that enable compliance for critical infrastructure operators are common across the standards, so implementing a control once enables compliance across multiple standards.<\/p>\n<p><strong>Mapping controls across standards such as:<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td><strong class=\"x-hidden-focus\">NIST CSF Category<\/strong><\/td>\n<td><strong>NIST CSF Subcategory<\/strong><\/td>\n<td><strong>NIST 800-53 Rev. 4 Control<\/strong><\/td>\n<td><strong>ISO 27001 Control<\/strong><\/td>\n<td><strong>NERC CIP Control<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Access Control (PR.AC):&nbsp;Access to assets and associated facilities is limited to authorized users, processes, or devices, and to authorized activities and transactions.<\/td>\n<td>PR.AC-1: Identities and credentials are managed for authorized devices and users.<\/td>\n<td>NIST SP 800-53 Rev. 4 AC-2, IA Family<\/td>\n<td>ISO\/IEC 27001:2013 A.9.2.1, A.9.2.2, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3<\/td>\n<td class=\"x-hidden-focus\">CIP-004-6 \u2013 Access Management Program,&nbsp;parts 4 and 5<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This crosswalk across standards is part of the Compliance Manager and populated automatically across a customer\u2019s assessments.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-93396 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/AC.jpg\" alt=\"Microsoft 365 Compliance Manager, control mapped across multiple standards. New standards based assessments in Compliance Manager are automatically populated with controls that have been implemented. \" width=\"1496\" height=\"661\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/AC.jpg 1496w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/AC-300x133.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/AC-1024x452.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/04\/AC-768x339.jpg 768w\" sizes=\"auto, (max-width: 1496px) 100vw, 1496px\"><\/p>\n<p>The level of effort to benchmark and report compliance with a new standards regime is dramatically reduced.<\/p>\n<p>IT and ICS convergence is a continuing trend for critical infrastructure operators. Attack methodologies, surfaces, and threat actors are crossing over to put our most critical resources at risk. Compliance regimes must be efficiently met in an auditable way to protect the availability of our systems. Microsoft provides the range of tools described above to help you manage across the IT and ICS environments.<\/p>\n<h2>Learn more<\/h2>\n<p>Learn more about <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager?view=o365-worldwide\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Compliance Manager<\/a> and how it helps simplify compliance and reduce risk.<\/p>\n<p>To learn more about Microsoft Security solutions <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener noreferrer\">visit our website<\/a>. Bookmark the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\">Security blog<\/a> to keep up with our expert coverage on security matters. Also, follow us at <a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">@MSFTSecurity<\/a> for the latest news and updates on cybersecurity.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/04\/27\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical infrastructure operators face a hostile cyber threat environment and a complex compliance landscape. Operators must manage industrial control systems as well as IT environments that are part of critical infrastructure or can form attack surfaces for control systems.<br \/>\nThe post Meet critical infrastructure security compliance requirements with Microsoft 365 appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":40628,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[941,125,347,6420],"class_list":["post-40627","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-compliance","tag-critical-infrastructure","tag-cybersecurity","tag-microsoft-365"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Meet critical infrastructure security compliance requirements with Microsoft 365 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Meet critical infrastructure security compliance requirements with Microsoft 365 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-27T16:00:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1410\" \/>\n\t<meta property=\"og:image:height\" content=\"795\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Meet critical infrastructure security compliance requirements with Microsoft 365\",\"datePublished\":\"2021-04-27T16:00:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/\"},\"wordCount\":1336,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png\",\"keywords\":[\"compliance\",\"Critical Infrastructure\",\"Cybersecurity\",\"Microsoft 365\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/\",\"name\":\"Meet critical infrastructure security compliance requirements with Microsoft 365 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png\",\"datePublished\":\"2021-04-27T16:00:59+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png\",\"width\":1410,\"height\":795},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"compliance\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/compliance\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Meet critical infrastructure security compliance requirements with Microsoft 365\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Meet critical infrastructure security compliance requirements with Microsoft 365 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/","og_locale":"en_US","og_type":"article","og_title":"Meet critical infrastructure security compliance requirements with Microsoft 365 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-04-27T16:00:59+00:00","og_image":[{"width":1410,"height":795,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Meet critical infrastructure security compliance requirements with Microsoft 365","datePublished":"2021-04-27T16:00:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/"},"wordCount":1336,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png","keywords":["compliance","Critical Infrastructure","Cybersecurity","Microsoft 365"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/","url":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/","name":"Meet critical infrastructure security compliance requirements with Microsoft 365 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png","datePublished":"2021-04-27T16:00:59+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365.png","width":1410,"height":795},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/meet-critical-infrastructure-security-compliance-requirements-with-microsoft-365\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"compliance","item":"https:\/\/www.threatshub.org\/blog\/tag\/compliance\/"},{"@type":"ListItem","position":3,"name":"Meet critical infrastructure security compliance requirements with Microsoft 365"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40627","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=40627"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40627\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/40628"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=40627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=40627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=40627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}