The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a binding operational directive, BOD 25-01, requiring Microsoft 365 cloud environments to meet cybersecurity standards.
CISA advises both federal agencies and enterprises in the private sector to follow the directive for enhanced security.
The directive includes deploying a custom automation configuration assessment tool, integrating with CISA's monitoring infrastructure, and aligning with secure configuration baselines.
CISA also plans to include other cloud providers in future updates of the directive.