Skip to content

Governance

Governance covers the tenant-wide rules and evidence that keep the platform under control: which policies apply, how resources are tagged, what is logged, how posture is measured, and where the platform knowingly departs from its own rules. The Security Model decides who can change the tenant. Governance makes sure every change is checked and leaves a record.

Policy and standards

  • Azure Policy (EPAC): policy as code, the three-layer model, moving from audit to enforcement, and exemptions.
  • Tagging Standard: the eleven mandatory tags, and how they are applied and checked.
  • Regulatory Compliance: the standards measured in Defender for Cloud, and the evidence behind them.

Logging and evidence

Measuring and reporting

Decisions and exceptions

Related: