Microsoft Azure

Amazon Web Services

Security patches

  • Software updates to resolve security vulnerabilities (“security patches”) will be made available according the following timelines:

  • CVSS scores of 9 and above (Critical): immediately

  • CVSS scores of 7 and above (High): next release (3 weeks)

  • CVSS scores between 4 and 7: within 3 releases (nine weeks)

  • CVSS scores below 4: best effort.

Idem.

Vulnerability scanning - methods in use

  • Monthly XX

  • CIS benchmark scanning

Passwords

Microsoft Azure

Amazon Web Services

Full range of ASCI characters

Password length (min/max)

8/128

Password renewal

After 4 months

Password re-use

After 3

Mandatory use of capital

Yes

Mandatory use of special character

Yes

Mandatory use of number

Yes

Password block/lock out

Yes (10 attempts)

Password lock-out time

10 minutes

Logging of lock-outs, log outs, login attempt (successfull/failed)

??

Hashed & salted

Yes

Transport via encrypted channel

Yes

(Host) Intrusion detection monitoring (e.g. malware protection)

Network traffic/nodes

Incident testing (scenario’s)

Secure communication services

Communication security ('layered access'/'trusted origin')

Time zone/time stamp source

Microsoft Azure

Amazon web services

Multi/single tenant approach

Monolithic vs (micro)services architecture

Availability & scalability

Access control security

Data retention