Set parameters for security policy

Steven Rook 0 Reputation points
2025-04-25T15:45:38.4066667+00:00

I want to add NCSC Cyber Assessment Framework (CAF) v3.2 to Regulatory Compliance for all subscriptions. When I toggle the standard to "On" I'm presented with a fly-out titled "Set parameters" (see attached screenshot). However, I can't find any information about this and I don't know what parameters are required to begin assessing against this standard.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,528 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 1,305 Reputation points Microsoft Employee
    2025-04-28T10:28:36.1266667+00:00

    Hi Steven Rook,

    Based on my research, as well as successfully implementing this on my test tenant, I was unable to locate any documentation or examples from Microsoft on the matter. Consequently, I have raised this issue with the PG group to inquire about the reasoning, timeline, or any plans to improve this documentation.

    Nevertheless, I was able to add the policy in Azure by utilizing the information provided through the accessibility icons adjacent to the textboxes.

    User's image

    User's image

    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.