Skip to main content
AzureProof Docs
  • Quick start
  • Connecting your Azure tenant
  • Understanding your score
  • Your first audit
  • How SOC2 evidence works
  • Control categories explained
  • Pass / Warn / Fail criteria
  • Evidence retention policy
  • Access controls (CC6.x)
  • Threat detection (CC7.x)
  • Change management (CC8.x)
  • Availability (A1.x)
  • Microsoft Graph
  • Defender for Cloud
  • Activity Log
  • Future: AWS, GCP
  • Our security model
  • Permissions we request
  • Data we store (and don't store)
  • Encryption at rest
  • SOC2 status
  • Responsible disclosure
  • Authentication
  • Endpoints
  • Webhooks

25 pages

concepts

Control categories explained

CC6, CC7, CC8 and the Availability series.

  • CC6 — Logical and Physical Access
  • CC7 — System Operations and Monitoring
  • CC8 — Change Management
  • A1 — Availability
Previous
How SOC2 evidence works
Next
Pass / Warn / Fail criteria