Compliance là claim có scope
Bắt đầu bằng framework, geography, service, data classification và control objective. Sau đó hỏi: ai sở hữu control, evidence ở đâu, thu thập bao lâu một lần và auditor cần gì?
Provider evidence và customer evidence
Trust Center/Compliance Manager có thể cung cấp information, assessment hoặc mapping; certification của Azure có phạm vi nhất định. Customer vẫn phải cấu hình identity, encryption, logging, retention, access review, incident response và vendor/process controls.
Đừng viết “Azure compliant” mà không ghi framework/version/region/service/date. Một evidence cũ hoặc sai scope không đủ để đóng finding.
Bài tập
Tạo compliance brief và gap register cho storage chứa PII. Map access review, encryption và audit logging; ghi provider/customer responsibility, evidence, owner, frequency, retention và remediation.
Checkpoint
Bạn đạt bài khi biến một yêu cầu mơ hồ thành control/evidence có scope và có thể audit.