Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This page describes the compliance security profile, its compliance controls, and supported features. To enable the compliance security profile, see Configure enhanced security and compliance settings.
Compliance security profile overview
The compliance security profile enables additional monitoring, a hardened compute image, and other features and controls on Azure Databricks workspaces. The compliance security profile includes controls that help meet the applicable security requirements of some compliance standards.
The compliance security profile is required to use Azure Databricks to process data regulated under:
- C5
- CCCS Medium (Protected B)
- HIPAA
- HITRUST
- Infosec Registered Assessors Program (IRAP)
- ISMAP
- Korean Financial Security Institute (K-FSI)
- PCI-DSS
- TISAX
- UK Cyber Essentials Plus
You can also select to enable the compliance security profile for its enhanced security features without conforming to a compliance standard.
Important
- You are solely responsible for ensuring your own compliance with all applicable laws and regulations.
- You are solely responsible for ensuring that the compliance security profile and the appropriate compliance standards are configured before processing regulated data.
- You are solely responsible for verifying that sensitive information is never entered in customer-defined input fields, such as workspace names, compute resource names, tags, job names, job run names, network names, credential names, storage account names, and Git repository IDs or URLs. These fields might be stored, processed, or accessed outside the compliance boundary.
If you enable this feature on any workspace, you are charged for the Enhanced Security and Compliance add-on as described on the pricing page.
Note
Account-level Genie One does not aggregate data from workspaces that have the compliance security profile enabled. See Use Genie One.
To provide Unity Catalog and other Azure Databricks features, Azure Databricks stores your Azure Databricks identities and their attributes in the United States and in each region you have a workspace. For more granular control over the regions in which your identities are present, create separate Azure Databricks accounts. Please contact _ for assistance if needed.
Compliance security profile security enhancements
Security enhancements include:
A CIS Level 1 hardened image.
Automatic cluster updates, ensuring clusters have the latest updates by periodically restarting them during configurable maintenance windows. See Automatic cluster update.
Enhanced security monitoring, which includes monitoring agents that generate reviewable logs. See Monitoring agents in Azure Databricks compute plane images.
Communications within the cluster and for egress use TLS 1.2 or higher, including communication with the metastore.