{"id":1364,"date":"2021-11-20T13:37:26","date_gmt":"2021-11-20T16:37:26","guid":{"rendered":"https:\/\/fcnuvem.com.br\/home\/?p=1364"},"modified":"2022-12-05T11:57:37","modified_gmt":"2022-12-05T14:57:37","slug":"blog-como-manter-seus-workloads-seguros-com-o-azure-security-center","status":"publish","type":"post","link":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/","title":{"rendered":"Como Manter seus Workloads Seguros com o Azure Security Center"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Blog-FCnuvem-AzureSecCenter.png\" alt=\"\" class=\"wp-image-1365\"\/><figcaption><sub><strong>Autor:<\/strong>\u00a0Daniel Augusto Ribeiro da Rosa\u00a0<\/sub><\/figcaption><\/figure>\n\n\n\n<p>Diante dos incidentes que aconteceram nos \u00faltimos anos, \u00e9 percept\u00edvel que finalmente o mercado brasileiro est\u00e1 amadurecendo no ponto de vista de seguran\u00e7a da informa\u00e7\u00e3o.&nbsp;<\/p>\n\n\n\n<p>No ano de 2017, o&nbsp;mundo foi surpreendido com um Malware chamado&nbsp;WannaCry&nbsp;esse Malware causou preju\u00edzo de milhares de d\u00f3lares&nbsp;e tudo isso poderia ter sido evitado com uma simples atualiza\u00e7\u00e3o do Windows.&nbsp;<\/p>\n\n\n\n<p>Isso evidencia a necessidade de termos uma rotina de atualiza\u00e7\u00e3o dos nossos&nbsp;Workloads, seja no ambiente local ou na nuvem.&nbsp;<\/p>\n\n\n\n<p>Dentro do contexto de Seguran\u00e7a da Informa\u00e7\u00e3o, a Microsoft \u00e9 o \u00fanico provedor de nuvem que oferece um recurso que possibilita ter visibilidade e controle sobre a seguran\u00e7a dos&nbsp;Workloads.&nbsp;<\/p>\n\n\n\n<p>O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center.&nbsp;<\/p>\n\n\n\n<p><strong>Overview do Azure Security Center<\/strong>&nbsp;<\/p>\n\n\n\n<p>O Azure Security Center (ASC) \u00e9 um recurso dispon\u00edvel no Azure para toda e qualquer assinatura ativa, ou seja, tendo&nbsp;um assinatura&nbsp;automaticamente \u00e9 habilitado o ASC na camada<em>&nbsp;free<\/em>.&nbsp;Al\u00e9m da camada&nbsp;<em>free<\/em>, existe tamb\u00e9m a camada<em>&nbsp;standard<\/em>, que oferece uma s\u00e9rie de mecanismos de seguran\u00e7a para organiza\u00e7\u00f5es&nbsp;que precisam de mais controle, falaremos mais sobre essa camada nos pr\u00f3ximos artigos.&nbsp;<\/p>\n\n\n\n<p>O primeiro passo \u00e9 acessar o ASC, para isso&nbsp;clique em Azure Security Center no painel lateral, caso ele n\u00e3o apare\u00e7a, basta utilizar o campo de pesquisa, durante o primeiro acesso, talvez o ASC demore alguns minutos at\u00e9 popular o dashboard com recursos, recomenda\u00e7\u00f5es e demais informa\u00e7\u00f5es.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"510\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-1024x510.jpeg\" alt=\"\" class=\"wp-image-1366\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-1024x510.jpeg 1024w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-300x150.jpeg 300w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-768x383.jpeg 768w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image.jpeg 1348w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Conforme&nbsp;a imagem acima, o Dashboard do ASC fornece informa\u00e7\u00f5es relacionadas a tr\u00eas&nbsp;grupos:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Policy&nbsp;&amp;&nbsp;Compliance<\/strong>:&nbsp;Aqui voc\u00ea visualiza em que camada sua assinatura se encontra, note que nesse caso, ambas assinaturas est\u00e3o na camada&nbsp;<em>free<\/em>, al\u00e9m disso, voc\u00ea tamb\u00e9m&nbsp;pode&nbsp;visualizar&nbsp;como est\u00e1 a conformidade em rela\u00e7\u00e3o as&nbsp;politicas&nbsp;de seguran\u00e7a, neste exemplo, estou 50% alinhado com as&nbsp;politicas&nbsp;de seguran\u00e7a definidas;&nbsp;<\/li><li><strong>Resource&nbsp;Security&nbsp;Hygiene<\/strong>: Nesse grupo de informa\u00e7\u00f5es voc\u00ea tem uma vis\u00e3o geral em rela\u00e7\u00e3o as recomenda\u00e7\u00f5es separadas por grupo, veremos com mais detalhes em seguida;&nbsp;<\/li><li><strong>Threat&nbsp;Protection<\/strong>:&nbsp;Esse grupo n\u00e3o est\u00e1 aparecendo na imagem, mas ele vem logo abaixo, nesse artigo n\u00e3o iremos abordar a parte de&nbsp;<em>Threat&nbsp;Protection<\/em>.&nbsp;<\/li><\/ul>\n\n\n\n<p><strong>Security&nbsp;Policy<\/strong>&nbsp;<\/p>\n\n\n\n<p>Recentemente o ASC teve uma grande atualiza\u00e7\u00e3o no que diz&nbsp;respeito as Security Policies, agora est\u00e1 mais organizado e mais f\u00e1cil de entender o que significa cada um dos componentes, mas mesmo assim, ainda gera&nbsp;um pouco de confus\u00e3o, basicamente, as pol\u00edticas de seguran\u00e7a s\u00e3o o que definem como o ASC ir\u00e1 se&nbsp;comportar diante dos&nbsp;workloads&nbsp;e atualmente as pol\u00edticas de seguran\u00e7a do ASC possuem quatro&nbsp;componentes, veremos cada um deles na sequ\u00eancia.&nbsp;<\/p>\n\n\n\n<p><strong>Data&nbsp;Collection<\/strong>&nbsp;<\/p>\n\n\n\n<p>A coleta dos dados das&nbsp;VMs&nbsp;Azure e non-Azure s\u00e3o realizados pelo Microsoft&nbsp;Monitoring&nbsp;Agent (MMA), cujo qual, armazena os dados coletados em um&nbsp;workspace&nbsp;do Log&nbsp;Analytics.&nbsp;<\/p>\n\n\n\n<p>Por padr\u00e3o, o provisionamento autom\u00e1tico do MMA \u00e9 desabilitado, por\u00e9m, eu recomendo que voc\u00ea&nbsp;deixe ele&nbsp;no modo autom\u00e1tico, para que toda e qualquer VM nova ou existente seja monitorada pelo ASC, ou seja, o ASC ir\u00e1 instalar o MMA em todas as&nbsp;VMs&nbsp;existentes, bem como em quaisquer novas&nbsp;VMs&nbsp;que forem criadas.&nbsp;<\/p>\n\n\n\n<p>Para habilitar o provisionamento autom\u00e1tico do Microsoft&nbsp;Monitoring&nbsp;Agent:&nbsp;<\/p>\n\n\n\n<p>1 &#8211; Acesse o ASC e selecione Security&nbsp;Policy;&nbsp;<\/p>\n\n\n\n<p>2 &#8211; Clique em&nbsp;Edit&nbsp;Settings ao lado da assinatura, conforme imagem abaixo:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-1-1024x302.jpeg\" alt=\"\" class=\"wp-image-1367\"\/><\/figure>\n\n\n\n<p>3 &#8211; Em&nbsp;<em>Auto&nbsp;Provisioning<\/em>, selecione&nbsp;<em>On<\/em>&nbsp;para habilitar o provisionamento autom\u00e1tico e abaixo selecione um&nbsp;<em>workspace<\/em>&nbsp;existente ou utilize o&nbsp;<em>workspace<\/em>&nbsp;padr\u00e3o criado pelo ASC, a&nbsp;imagem abaixo ilustra esse processo:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"793\" height=\"516\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-5.jpeg\" alt=\"\" class=\"wp-image-1371\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-5.jpeg 793w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-5-300x195.jpeg 300w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-5-768x500.jpeg 768w\" sizes=\"auto, (max-width: 793px) 100vw, 793px\" \/><\/figure>\n\n\n\n<p><strong>Security&nbsp;Policy<\/strong>&nbsp;<\/p>\n\n\n\n<p>Talvez o componente que mais causa confus\u00e3o \u00e9 o Security&nbsp;policy, quando abrimos o ASC e selecionamos Security&nbsp;policy, uma nova&nbsp;<em>blade<\/em>&nbsp;chamada&nbsp;Policy&nbsp;Management ser\u00e1 aberta, conforme imagem abaixo.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"299\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-3-1024x299.jpeg\" alt=\"\" class=\"wp-image-1369\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-3-1024x299.jpeg 1024w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-3-300x88.jpeg 300w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-3-768x224.jpeg 768w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-3.jpeg 1290w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Selecione a assinatura que voc\u00ea deseja configurar e uma nova&nbsp;<em>blade&nbsp;<\/em>ser\u00e1 aberta, de acordo com a imagem abaixo.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"552\" height=\"677\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-2.jpeg\" alt=\"\" class=\"wp-image-1368\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-2.jpeg 552w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-2-245x300.jpeg 245w\" sizes=\"auto, (max-width: 552px) 100vw, 552px\" \/><\/figure>\n\n\n\n<p>Quando voc\u00ea configura as pol\u00edticas, seja uma pol\u00edtica&nbsp;de Compute&nbsp;and&nbsp;Apps, Network ou Data, voc\u00ea simplesmente est\u00e1 dizendo pro ASC o tipo de recomenda\u00e7\u00e3o que voc\u00ea deseja receber, mas caso voc\u00ea queira entender a fun\u00e7\u00e3o de cada uma das pol\u00edticas, veja o link nas refer\u00eancias.&nbsp;<\/p>\n\n\n\n<p><strong>E-mail&nbsp;Notifications<\/strong>&nbsp;<\/p>\n\n\n\n<p>Nesse componente, voc\u00ea deve informar os e-mails de contato e um telefone para receber notifica\u00e7\u00f5es de seguran\u00e7a enviadas pelo ASC.&nbsp;<\/p>\n\n\n\n<p>Para habilitar as notifica\u00e7\u00f5es:&nbsp;<\/p>\n\n\n\n<p>1 &#8211; Acesse o ASC e selecione Security&nbsp;Policy;&nbsp;<\/p>\n\n\n\n<p>2 &#8211; Clique em&nbsp;<em>Edit&nbsp;Settings<\/em>&nbsp;ao lado da assinatura;&nbsp;<\/p>\n\n\n\n<p>3 &#8211; Em E-mail&nbsp;Notifications&nbsp;voc\u00ea ver\u00e1 as seguintes op\u00e7\u00f5es:&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Security&nbsp;Contact&nbsp;E-mails:<\/strong>Aa&nbsp;Microsoft utiliza os e-mails informados nesse campo para enviar notifica\u00e7\u00f5es sobre recursos que foram comprometidos;&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Phone&nbsp;Number:<\/strong>&nbsp;Assim como os e-mails cadastrados na op\u00e7\u00e3o acima, a Microsoft vai usar esse n\u00famero para contat\u00e1-lo, caso algum dos seus recursos tenha sido comprometido, \u00e9 importante ressaltar que \u00e9 necess\u00e1rio utilizar o padr\u00e3o internacional, por exemplo: +5511999999999;&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Send&nbsp;me E-mails&nbsp;About&nbsp;Alerts:<\/strong>&nbsp;Desabilitando essa op\u00e7\u00e3o, significa que voc\u00ea vai receber apenas e-mails com alertas de alta criticidade.&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Send&nbsp;E-mail&nbsp;Also&nbsp;to&nbsp;Subscription&nbsp;Owners:<\/strong>&nbsp;Habilitando essa op\u00e7\u00e3o,&nbsp;siginifica&nbsp;que todos os&nbsp;<em>owners<\/em>&nbsp;da assinatura ir\u00e3o receber alertas de alta criticidade.&nbsp;<\/p>\n\n\n\n<p>A imagem abaixo exemplifica esse processo:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"556\" height=\"547\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-4.jpeg\" alt=\"\" class=\"wp-image-1370\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-4.jpeg 556w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-4-300x295.jpeg 300w\" sizes=\"auto, (max-width: 556px) 100vw, 556px\" \/><\/figure>\n\n\n\n<p><strong>Pricing&nbsp;tier<\/strong>&nbsp;<\/p>\n\n\n\n<p>O ASC oferece duas camadas de pre\u00e7o:&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Free:<\/strong>&nbsp;Conforme explicado anteriormente, essa camada \u00e9 habilitada automaticamente para todas as assinaturas do Azure, fornecendo pol\u00edticas de seguran\u00e7a e recomenda\u00e7\u00f5es para ajudar a proteger seus&nbsp;workloads.&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Standard:<\/strong>&nbsp;A camada standard estende os recursos da camada&nbsp;free&nbsp;para&nbsp;workloads&nbsp;em execu\u00e7\u00e3o fora do Azure, ou seja, no seu ambiente&nbsp;on-premises&nbsp;ou em outros provedores de nuvem, um dos principais&nbsp;beneficios&nbsp;\u00e9 o gerenciamento unificado de todos os seus&nbsp;Workloads.&nbsp;<\/p>\n\n\n\n<p>A camada standard tamb\u00e9m oferece recursos avan\u00e7ados de detec\u00e7\u00e3o de amea\u00e7as, que utilizam recursos de an\u00e1lise comportamental e&nbsp;Machine&nbsp;Learning para identificar ataques e zero-day&nbsp;exploits, \u00e9 importante ressaltar que a camada standard \u00e9 gratuita por 60 dias e depois dos o custo \u00e9 de U$ 15 por recomenda\u00e7\u00f5es.&nbsp;<\/p>\n\n\n\n<p>O ASC analisa constantemente nossos&nbsp;workloads&nbsp;e quando identifica uma poss\u00edvel vulnerabilidade, oferece recomenda\u00e7\u00f5es&nbsp;para resolver tais problemas e todas as recomenda\u00e7\u00f5es possuem uma severidade associada a elas, que v\u00e3o desde alta prioridade at\u00e9 baixa prioridade, o que facilita a decis\u00e3o sobre quais recomenda\u00e7\u00f5es devem ser atendidas primeiro.&nbsp;<\/p>\n\n\n\n<p>Para visualizar as recomenda\u00e7\u00f5es:&nbsp;<\/p>\n\n\n\n<p>1 &#8211; Acesse o ASC e selecione&nbsp;Recommendations, conforme imagem abaixo.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"396\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-6-1024x396.jpeg\" alt=\"\" class=\"wp-image-1372\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-6-1024x396.jpeg 1024w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-6-300x116.jpeg 300w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-6-768x297.jpeg 768w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-6.jpeg 1369w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Algumas recomenda\u00e7\u00f5es necessitam de um&nbsp;<em>reboot<\/em>&nbsp;para serem aplicadas, por exemplo, recomenda\u00e7\u00f5es sobre atualiza\u00e7\u00f5es do Windows, a&nbsp;Microsoft recomenda que no primeiro momento, todas as recomenda\u00e7\u00f5es de alta prioridade sejam atendidas.&nbsp;<\/p>\n\n\n\n<p>Atualmente, as&nbsp;recomenda\u00e7\u00f5es s\u00e3o divididas em tr\u00eas&nbsp;grupos:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Compute &amp; Apps<\/strong>: As recomenda\u00e7\u00f5es de computa\u00e7\u00e3o s\u00e3o para&nbsp;VMs&nbsp;Azure e non-Azure e incluem diversos tipos de recomenda\u00e7\u00f5es, por isso, \u00e9 importante entender a&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-recommendations#what-are-security-recommendations\" target=\"_blank\" rel=\"noreferrer noopener\">lista<\/a>&nbsp;completa de recomenda\u00e7\u00f5es que podem ser aplicadas nos&nbsp;workloads, essas recomenda\u00e7\u00f5es&nbsp;desAplicativos&nbsp;s\u00e3o voltadas para&nbsp;workloads&nbsp;que possuem aplica\u00e7\u00f5es web rodando&nbsp;em m\u00e1quinas virtuais no Azure e na maioria dos casos, a Microsoft vai recomendar que voc\u00ea utilize um Web&nbsp;Application&nbsp;Firewall (WAF), veja na imagem abaixo algumas recomenda\u00e7\u00f5es do grupo&nbsp;<em>Compute &amp; Apps<\/em>:&nbsp;<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"518\" src=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-7-1024x518.jpeg\" alt=\"\" class=\"wp-image-1373\" srcset=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-7-1024x518.jpeg 1024w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-7-300x152.jpeg 300w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-7-768x388.jpeg 768w, https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/image-7.jpeg 1206w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>\u2022Networking:<\/strong>&nbsp;As recomenda\u00e7\u00f5es de networking s\u00e3o voltadas para recursos que melhoram a seguran\u00e7a dos&nbsp;workloads&nbsp;em rela\u00e7\u00e3o a parte de redes, por exemplo:&nbsp;<\/p>\n\n\n\n<p>\u2022Configurar um NSG para&nbsp;Sub-redes;&nbsp;<\/p>\n\n\n\n<p>\u2022Configurar regras no NSG para restringir o acesso aos seus recursos a partir da internet;&nbsp;<\/p>\n\n\n\n<p>\u2022Adicionar um NGFW no ambiente.&nbsp;<\/p>\n\n\n\n<p>As recomenda\u00e7\u00f5es podem variar dependendo do ambiente, por isso, novamente, \u00e9 extremamente importante que voc\u00ea entenda a lista completa de recomenda\u00e7\u00f5es.&nbsp;<\/p>\n\n\n\n<p>\u2022<strong>Data &amp;&nbsp;Storage:<\/strong>&nbsp;As recomenda\u00e7\u00f5es de Dados s\u00e3o voltadas para contas de armazenamento e Azure SQL, aqui voc\u00ea ver\u00e1 recomenda\u00e7\u00f5es para criptografar contas de armazenamento (hoje as contas de armazenamento s\u00e3o criptografadas por padr\u00e3o), habilitar auditoria nas suas bases de dados e assim por diante, deixarei o link nas refer\u00eancias com a lista completa de recomenda\u00e7\u00f5es.&nbsp;<\/p>\n\n\n\n<p><strong>Conclus\u00e3o<\/strong>&nbsp;<\/p>\n\n\n\n<p>Existem diversos recursos dispon\u00edveis no Azure Security Center, principalmente na vers\u00e3o Standard, o objetivo desse artigo foi fazer uma introdu\u00e7\u00e3o e explicar alguns conceitos importantes para quem ainda n\u00e3o est\u00e1 se familiarizado com o ASC, nos pr\u00f3ximos artigos pretendo explorar alguns recursos espec\u00edficos do ASC, por exemplo, Just&nbsp;inTtime&nbsp;VM Access, se esse conte\u00fado fez sentido&nbsp;pAra&nbsp;voc\u00ea, escreve nos coment\u00e1rios para eu saber se estou te ajudando de alguma forma.&nbsp;<\/p>\n\n\n\n<p><strong>Refer\u00eancias<\/strong>&nbsp;<\/p>\n\n\n\n<p>Available&nbsp;Security&nbsp;Policy&nbsp;Definitions&nbsp;<\/p>\n\n\n\n<p>Protecting&nbsp;your&nbsp;Machines&nbsp;and&nbsp;Applications&nbsp;in Azure Security Center&nbsp;<\/p>\n\n\n\n<p>Protecting&nbsp;your&nbsp;Network in Azure Security Center&nbsp;<\/p>\n\n\n\n<p>Protecting&nbsp;Azure SQL Service&nbsp;and&nbsp;Data in Azure Security Center&nbsp;<\/p>\n\n\n\n<p>Livro do Yuri&nbsp;Diogenes&nbsp;e Tom&nbsp;Shinder&nbsp; Microsoft Azure Security Center&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center.\u00a0<\/p>\n","protected":false},"author":8,"featured_media":1374,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[90,94],"tags":[372],"post_series":[],"class_list":["post-1364","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-ciberseguranca","category-tutoriais","tag-azure-security-center","entry","has-media"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Como Manter seus Workloads Seguros com o Azure Security Center - Blog da FCamara<\/title>\n<meta name=\"description\" content=\"O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center com Workloads seguros\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Como Manter seus Workloads Seguros com o Azure Security Center - Blog da FCamara\" \/>\n<meta property=\"og:description\" content=\"O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center com Workloads seguros\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog da FCamara\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-20T16:37:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-05T14:57:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png\" \/>\n\t<meta property=\"og:image:width\" content=\"260\" \/>\n\t<meta property=\"og:image:height\" content=\"205\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"fcnuvem\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"fcnuvem\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\"},\"author\":{\"name\":\"fcnuvem\",\"@id\":\"https:\/\/fcamara.com\/blog\/#\/schema\/person\/62d48659a26297896002e2434a44e28a\"},\"headline\":\"Como Manter seus Workloads Seguros com o Azure Security Center\",\"datePublished\":\"2021-11-20T16:37:26+00:00\",\"dateModified\":\"2022-12-05T14:57:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\"},\"wordCount\":1732,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fcamara.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png\",\"keywords\":[\"Azure Security Center\"],\"articleSection\":[\"Cloud &amp; Ciberseguran\u00e7a\",\"Tutoriais\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\",\"url\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\",\"name\":\"Como Manter seus Workloads Seguros com o Azure Security Center - Blog da FCamara\",\"isPartOf\":{\"@id\":\"https:\/\/fcamara.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png\",\"datePublished\":\"2021-11-20T16:37:26+00:00\",\"dateModified\":\"2022-12-05T14:57:37+00:00\",\"description\":\"O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center com Workloads seguros\u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage\",\"url\":\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png\",\"contentUrl\":\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png\",\"width\":260,\"height\":205},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\/\/fcamara.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"investir em mobilidade\",\"item\":\"https:\/\/fcamara.com\/blog\/tags\/investir-em-mobilidade\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Como Manter seus Workloads Seguros com o Azure Security Center\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fcamara.com\/blog\/#website\",\"url\":\"https:\/\/fcamara.com\/blog\/\",\"name\":\"Blog da FCamara\",\"description\":\"Esta \u00e9 a \u00e1rea de insights sobre o mercado de tecnologia.\",\"publisher\":{\"@id\":\"https:\/\/fcamara.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fcamara.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fcamara.com\/blog\/#organization\",\"name\":\"Blog da FCamara\",\"url\":\"https:\/\/fcamara.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/fcamara.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2024\/07\/FCamara-Blog-laranja.webp\",\"contentUrl\":\"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2024\/07\/FCamara-Blog-laranja.webp\",\"width\":459,\"height\":68,\"caption\":\"Blog da FCamara\"},\"image\":{\"@id\":\"https:\/\/fcamara.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fcamara.com\/blog\/#\/schema\/person\/62d48659a26297896002e2434a44e28a\",\"name\":\"fcnuvem\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g\",\"caption\":\"fcnuvem\"},\"url\":\"https:\/\/fcamara.com\/blog\/author\/fcnuvem\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Como Manter seus Workloads Seguros com o Azure Security Center - Blog da FCamara","description":"O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center com Workloads seguros\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/","og_locale":"pt_BR","og_type":"article","og_title":"Como Manter seus Workloads Seguros com o Azure Security Center - Blog da FCamara","og_description":"O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center com Workloads seguros\u00a0","og_url":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/","og_site_name":"Blog da FCamara","article_published_time":"2021-11-20T16:37:26+00:00","article_modified_time":"2022-12-05T14:57:37+00:00","og_image":[{"width":260,"height":205,"url":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png","type":"image\/png"}],"author":"fcnuvem","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"fcnuvem","Est. tempo de leitura":"8 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#article","isPartOf":{"@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/"},"author":{"name":"fcnuvem","@id":"https:\/\/fcamara.com\/blog\/#\/schema\/person\/62d48659a26297896002e2434a44e28a"},"headline":"Como Manter seus Workloads Seguros com o Azure Security Center","datePublished":"2021-11-20T16:37:26+00:00","dateModified":"2022-12-05T14:57:37+00:00","mainEntityOfPage":{"@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/"},"wordCount":1732,"commentCount":0,"publisher":{"@id":"https:\/\/fcamara.com\/blog\/#organization"},"image":{"@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage"},"thumbnailUrl":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png","keywords":["Azure Security Center"],"articleSection":["Cloud &amp; Ciberseguran\u00e7a","Tutoriais"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/","url":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/","name":"Como Manter seus Workloads Seguros com o Azure Security Center - Blog da FCamara","isPartOf":{"@id":"https:\/\/fcamara.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage"},"image":{"@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage"},"thumbnailUrl":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png","datePublished":"2021-11-20T16:37:26+00:00","dateModified":"2022-12-05T14:57:37+00:00","description":"O objetivo desse artigo \u00e9 explicar alguns conceitos fundamentais para dar os primeiros passos no Azure Security Center com Workloads seguros\u00a0","breadcrumb":{"@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#primaryimage","url":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png","contentUrl":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2021\/11\/Thumb-FCnuvem-AzureSecCenter.png","width":260,"height":205},{"@type":"BreadcrumbList","@id":"https:\/\/fcamara.com\/blog\/blog-como-manter-seus-workloads-seguros-com-o-azure-security-center\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/fcamara.com\/blog\/"},{"@type":"ListItem","position":2,"name":"investir em mobilidade","item":"https:\/\/fcamara.com\/blog\/tags\/investir-em-mobilidade\/"},{"@type":"ListItem","position":3,"name":"Como Manter seus Workloads Seguros com o Azure Security Center"}]},{"@type":"WebSite","@id":"https:\/\/fcamara.com\/blog\/#website","url":"https:\/\/fcamara.com\/blog\/","name":"Blog da FCamara","description":"Esta \u00e9 a \u00e1rea de insights sobre o mercado de tecnologia.","publisher":{"@id":"https:\/\/fcamara.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fcamara.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/fcamara.com\/blog\/#organization","name":"Blog da FCamara","url":"https:\/\/fcamara.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/fcamara.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2024\/07\/FCamara-Blog-laranja.webp","contentUrl":"https:\/\/fcamara.com\/blog\/wp-content\/uploads\/2024\/07\/FCamara-Blog-laranja.webp","width":459,"height":68,"caption":"Blog da FCamara"},"image":{"@id":"https:\/\/fcamara.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fcamara.com\/blog\/#\/schema\/person\/62d48659a26297896002e2434a44e28a","name":"fcnuvem","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"fcnuvem"},"url":"https:\/\/fcamara.com\/blog\/author\/fcnuvem\/"}]}},"lang":"br","translations":{"br":1364},"pll_sync_post":[],"_links":{"self":[{"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/posts\/1364","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/comments?post=1364"}],"version-history":[{"count":1,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/posts\/1364\/revisions"}],"predecessor-version":[{"id":6145,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/posts\/1364\/revisions\/6145"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/media\/1374"}],"wp:attachment":[{"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/media?parent=1364"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/categories?post=1364"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/tags?post=1364"},{"taxonomy":"post_series","embeddable":true,"href":"https:\/\/fcamara.com\/blog\/wp-json\/wp\/v2\/post_series?post=1364"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}