Bağımsız Azure güvenlik değerlendirmesiIndependent Azure security assessment

Azure ortamınızın güvenlik duruşunu kanıtlayın — tek yazma izni vermeden. Prove your Azure security posture — without granting a single write permission.

Controlio, Azure aboneliklerinizi salt-okunur erişimle bağımsız olarak değerlendirir; yanlış yapılandırmaları bulur, bulguları güvenlik çerçevelerine eşler ve yönetime ya da denetçiye sunabileceğiniz denetime hazır bir rapor üretir. Microsoft'un araçlarının yerine geçmez — onların söylediğini bağımsız olarak doğrular. Controlio independently assesses your Azure subscriptions with read-only access: it finds misconfigurations, maps findings to security frameworks and produces an audit-ready report you can hand to management or an auditor. It does not replace Microsoft's tools — it independently verifies what they say.

Yalnız Reader rolüReader role only Secret değerleri asla okunmazSecret values are never read 120+ otomatik kontrol120+ automated checks
Azure Güvenlik Değerlendirme RaporuAzure Security Assessment Reportsalt-okunur tarama · 43 snread-only scan · 43 s
%72
Uyum skoruCompliance score
19
BaşarısızFailed
33
İncelenmeliReview
35
GeçtiPassed
NET-01 İnternetten RDP/SSH açık NSG kurallarıNSG rules exposing RDP/SSH to the internet KRİTİKCRITICAL
KV-01 Key Vault purge protection kapalıKey Vault purge protection disabled YÜKSEKHIGH
LOG-01 Activity Log export tanımsızNo Activity Log export configured YÜKSEKHIGH
BCK-01 Backup korumasız üretim VM'leriProduction VMs without backup İNCELEREVIEW
MCSB · NIST · ISO her bulgu çerçeve maddelerine eşlenirevery finding maps to framework clauses
ProblemThe problem

Duruş bilgisi bol; güven ve kanıt kıt.Posture data is abundant; trust and evidence are scarce.

Azure size ne yapmanız gerektiğini söyleyen araçlar sunar. Ama üç soru açıkta kalır:Azure gives you tools that tell you what to do. Three questions remain open:

"Bunu bağımsız biri doğruladı mı?""Has anyone verified this independently?"

Platformun kendi kendine verdiği not, yönetim kurulu ve denetçi için tek başına kanıt değildir. Bağımsız üçüncü göz, aynı gerçeği dışarıdan doğrular.A score the platform gives itself is not, on its own, evidence for a board or an auditor. An independent third eye verifies the same facts from outside.

"ISO / NIS2 denetçisine ne göstereceğim?""What do I show the ISO / NIS2 auditor?"

Ekran görüntüsü denetim kanıtı değildir. Tarihli, çerçeve-eşlemeli, tekrarlanabilir bir değerlendirme raporu gerekir — teknik ekip dışındakilerin de okuyabileceği dilde.A screenshot is not audit evidence. You need a dated, framework-mapped, repeatable assessment report — in language people outside the engineering team can read.

"Onayladığım durumdan sapınca kim haber verecek?""Who tells me when we drift from what I approved?"

Öneri listeleri "olması gerekeni" söyler. Sizin onayladığınız yapılandırmayı bilen ve ondan sapmayı izleyen bir mekanizma ise Azure'da yoktur. TrueState tam bunu yapar.Recommendation lists describe an ideal. A mechanism that knows the configuration you approved and watches for drift from it does not exist in Azure. That is exactly what TrueState does.

Salt-okunur mimariRead-only architecture

Erişim modelimiz ürünün kendisi kadar önemli.Our access model matters as much as the product.

Tek istediğimiz izin, Azure'un yerleşik Reader rolü. Yazma izni, data-plane erişimi ya da dizin izni hiçbir akışta istenmez. Ne gördüğümüz kadar ne göremediğimiz de tasarımın parçası:The only permission we ask for is Azure's built-in Reader role. No flow ever requests write access, data-plane access or directory permissions. What we cannot see is as much a part of the design as what we can:

OkuduklarımızWhat we read

  • Kaynak yapılandırmaları (NSG kuralları, TLS sürümleri, ağ erişim ayarları)Resource configurations (NSG rules, TLS versions, network access settings)
  • RBAC rol atamaları ve custom rol tanımlarıRBAC role assignments and custom role definitions
  • Policy uyum durumu ve muafiyetlerPolicy compliance state and exemptions
  • Defender for Cloud plan kapsamı ve mevcut önerileriDefender for Cloud plan coverage and existing recommendations
  • Tanılama/loglama ve yedeklilik yapılandırmalarıDiagnostics/logging and resilience configurations

Yapısal olarak erişemediklerimizWhat we structurally cannot access

  • Secret, anahtar ve sertifika değerleri (Reader data-plane'e ulaşamaz)Secret, key and certificate values (Reader cannot reach the data plane)
  • Storage içerikleri, veritabanı verileri, dosyalarStorage contents, database data, files
  • Herhangi bir kaynağı değiştirme, silme, oluşturmaModifying, deleting or creating any resource
  • Entra ID dizin verisi (o alan Controlio M365 ürünündedir)Entra ID directory data (that is the Controlio M365 product's domain)
  • Kullanıcılarınızın kişisel verileriYour users' personal data
az role assignment create --assignee <controlio-app> --role "Reader" --scope <subscription|management-group>
// Onboarding tek rol atamasıdır. İptal = atamayı silmek. Anında ve tek taraflı.Onboarding is a single role assignment. Revoking = deleting it. Instant and unilateral.
Neyi tarıyoruzWhat we scan

18 alanda 120'den fazla otomatik kontrol.120+ automated checks across 18 areas.

Kimlik ve ayrıcalıklı erişimden ağ güvenliğine, veri korumadan loglamaya — her kontrol ya tam otomatik doğrulanır ya da dürüstçe "incelenmeli" olarak işaretlenir. Ölçemediğimiz hiçbir ayarı "izleniyor" göstermeyiz.From identity and privileged access to network security, data protection and logging — every check is either fully automated or honestly marked "review". We never present a setting we cannot measure as "monitored".

Kimlik & RBACIdentity & RBAC

Owner yoğunluğu, wildcard custom roller, PIM kullanımı, blast-radius haritasıOwner density, wildcard custom roles, PIM usage, blast-radius map

Ağ güvenliğiNetwork security

İnternete açık yönetim ve veritabanı portları, NSG kapsaması, DDoS, BastionInternet-exposed management and database ports, NSG coverage, DDoS, Bastion

Veri korumaData protection

TLS asgari sürümleri, şifreleme, public erişim, soft delete ve purge protectionMinimum TLS versions, encryption, public access, soft delete and purge protection

Loglama & izlemeLogging & monitoring

Activity Log export, tanılama ayarları, flow log ve retention kapsamasıActivity Log export, diagnostic settings, flow log and retention coverage

Compute & containerCompute & containers

VM/VMSS/AKS/ACR sertleştirmesi, emekli kaynak tipleri, boot diagnosticsVM/VMSS/AKS/ACR hardening, retired resource types, boot diagnostics

PaaS yüzeyiPaaS surface

App Service, SQL, Cosmos, Redis, APIM, Service Bus, AI servisleri yapılandırmasıApp Service, SQL, Cosmos, Redis, APIM, Service Bus, AI services configuration

Yedekleme & dayanıklılıkBackup & resilience

Backup kapsaması, vault güvenliği, tek-region riskiBackup coverage, vault security, single-region risk

Governance

Policy atamaları ve muafiyetleri, resource lock, MG hiyerarşisi, tag disipliniPolicy assignments and exemptions, resource locks, MG hierarchy, tag discipline

Çerçeve eşlemesiFramework mapping

Bir bulgu, birden fazla çerçevede kanıt.One finding, evidence across multiple frameworks.

Her teknik bulgu ilgili çerçeve maddelerine eşlenir. Rapor "uyumlusunuz" demez — hangi teknik kontrolün hangi maddeye kanıt ürettiğini gösterir. Sertifikasyon iddiası değil, denetim kanıtı üretiriz.Every technical finding maps to the relevant framework clauses. The report never says "you are compliant" — it shows which technical control produces evidence for which clause. We produce audit evidence, not certification claims.

MCSB Microsoft Cloud Security Benchmark v1
NIST 800-53 Rev. 5 kontrol aileleriRev. 5 control families
ISO/IEC 27001 Annex A eşlemesiAnnex A mapping
NIST CSF 2.0 fonksiyon eşlemesifunction mapping
MITRE ATT&CK® bulut tehdit bağlamı (overlay)cloud threat context (overlay)
Microsoft Defender for Cloud ile ilişkiRelationship with Microsoft Defender for Cloud

Rakip değil, bağımsız doğrulayıcı.Not a competitor — an independent verifier.

Defender for Cloud güçlü bir üründür ve açıksa bulgularını okuyup raporumuzda tek listede birleştiririz (çift kayıtları ayıklayarak). Controlio'nun eklediği katman farklı:Defender for Cloud is a strong product; when enabled, we read its findings and merge them into one deduplicated list in our report. The layer Controlio adds is different:

Defender for CloudControlio
DeğerlendirenAssessed byPlatformun kendisiThe platform itselfBağımsız üçüncü tarafIndependent third party
Çerçeve görünümü (ISO, NIST, DORA/NIS2)Framework view (ISO, NIST, DORA/NIS2)Ücretli plan gerektirirRequires a paid planDahilIncluded
Onaylı yapılandırma baseline'ı + sapma izlemeApproved configuration baseline + drift monitoringYokNot availableTrueState yol haritasıroadmap
Denetime hazır, paylaşılabilir raporAudit-ready, shareable reportPortal ekranları / workbook kurulumuPortal views / self-built workbooksTek tık PDF, yönetici özeti dahilOne-click PDF, executive summary included
Tehdit koruması, attack path, ajan tabanlı analizThreat protection, attack paths, agent-based analysisDefender'ın alanıDefender's domainöneririzwe recommend itBu alana girmeyizWe stay out of this space
Nasıl çalışırHow it works

Kurulumdan rapora üç adım.Three steps from setup to report.

BağlanınConnect

Microsoft hesabınızla giriş yapın veya Controlio uygulamasına management group / subscription kapsamında Reader rolü atayın. Ajan yok, script yok, yazma izni yok.Sign in with your Microsoft account, or assign the Reader role to the Controlio app at management-group or subscription scope. No agents, no scripts, no write permissions.

Tarama dakikalar içinde biterThe scan finishes in minutes

Azure Resource Graph üzerinden envanter çıkarılır, 120+ kontrol değerlendirilir, Defender bulguları (varsa) birleştirilir. Tipik ortamda tarama bir kahve molasından kısa sürer.Inventory is built via Azure Resource Graph, 120+ checks are evaluated and Defender findings (if any) are merged. In a typical environment the scan takes less than a coffee break.

Kanıtı teslim alınReceive the evidence

Skor, kritik bulgular, çerçeve eşlemesi ve düzeltme rehberiyle denetime hazır rapor — yönetici özeti C-level diliyle, teknik ek mühendis diliyle.An audit-ready report with the score, critical findings, framework mapping and remediation guidance — the executive summary in C-level language, the technical annex in engineering language.

Yol haritasıRoadmap

Bugün değerlendirme; sırada sürekli güvence.Assessment today; continuous assurance next.

BugünToday

Azure Security Snapshot

Tek seferlik salt-okunur değerlendirme: skor, bulgular, çerçeve eşlemesi, düzeltme rehberi, PDF rapor.A one-time read-only assessment: score, findings, framework mapping, remediation guidance, PDF report.

Yol haritasıRoadmap

TrueState for Azure

Onayladığınız yapılandırma dondurulur; sapmalar saatlik izlenir, kritik değişiklikler e-posta/Teams ile bildirilir. Onay disiplini çift kontrollüdür.The configuration you approve is frozen; drift is monitored hourly and critical changes are notified by email/Teams. Approval follows a dual-control discipline.

Yol haritasıRoadmap

MSP & danışman moduMSP & consultant mode

Azure Lighthouse ile çok-müşterili görünüm, müşteri karşılaştırması ve white-label raporlama.Multi-customer view via Azure Lighthouse, customer comparison and white-label reporting.

Sık sorulanlarFAQ

Dürüst cevaplar.Honest answers.

Defender for Cloud kullanıyorum. Bu ürün bana ne katar?I already use Defender for Cloud. What does this add?

Defender'ı kapatmanızı asla önermeyiz; tam tersine bulgularını okur ve raporumuza katarız. Controlio'nun kattığı şey bağımsızlık ve kanıt: platformun kendi kendine verdiği notu dışarıdan doğrulayan, ücretli plan istemeden çerçeve eşlemesi sunan ve denetçiye verebileceğiniz tarihli rapor üreten bir katman.We would never suggest turning Defender off; on the contrary, we read its findings and include them in our report. What Controlio adds is independence and evidence: a layer that verifies the platform's self-assessment from outside, provides framework mapping without a paid plan, and produces a dated report you can hand to an auditor.

Gerçekten hiç yazma izni yok mu?Really no write permissions at all?

Yok. Tek istediğimiz rol Azure'un yerleşik Reader rolüdür ve bu rol yapısal olarak hiçbir değişiklik yapamaz, hiçbir secret değeri okuyamaz. İsteğe bağlı Key Vault son-kullanma kontrolü için ayrı ve açık onayla Key Vault Reader (yalnız metadata) eklenebilir — o da değer okuyamaz.None. The only role we request is Azure's built-in Reader, which structurally cannot make any change or read any secret value. For the optional Key Vault expiry check, Key Vault Reader (metadata only) can be added with separate, explicit consent — it cannot read values either.

"ISO 27001 uyumlu olursunuz" mu diyorsunuz?Are you saying "you'll be ISO 27001 compliant"?

Hayır ve hiçbir araç bunu diyemez. Uyum, süreçleri de kapsayan bir denetim sonucudur. Biz teknik kontrollerin hangi çerçeve maddelerine kanıt ürettiğini gösteririz; raporun kapağında bunun bir sertifikasyon denetimi olmadığı açıkça yazar.No — and no tool can say that. Compliance is the outcome of an audit that also covers processes. We show which framework clauses your technical controls produce evidence for; the report cover states explicitly that it is not a certification audit.

Verilerim nerede tutuluyor, neler saklanıyor?Where is my data kept, and what is stored?

Yalnız güvenlik-anlamlı yapılandırma alanları ve bulgular saklanır; kaynak içerikleri, secret değerleri ve kişisel veriler hiçbir zaman toplanmaz. Veri minimizasyonu ürünün tasarım ilkesidir.Only security-relevant configuration fields and findings are stored; resource contents, secret values and personal data are never collected. Data minimisation is a design principle of the product.

Erişimi nasıl iptal ederim?How do I revoke access?

Reader rol atamasını silerek — tek taraflı ve anında. Sonraki tarama erişimin kesildiğini dürüstçe raporlar ve durur; arka kapı ya da kalıcı bağımlılık yoktur.By deleting the Reader role assignment — unilaterally and instantly. The next scan honestly reports that access was cut and stops; there is no back door and no lasting dependency.

Fiyatlandırma nasıl?What about pricing?

Erken erişim döneminde fiyatlandırmayı pilot kullanıcılarla birlikte şekillendiriyoruz. Erken erişime katılanlar lansman koşullarından öncelikli yararlanır.During early access we are shaping pricing together with pilot users. Early-access participants get priority on launch terms.

Erken erişimEarly access

Azure duruşunuzu kanıtlamaya hazır mısınız?Ready to prove your Azure posture?

İlk değerlendirmenizi dakikalar içinde alın; yazma izni vermeden.Get your first assessment in minutes — without granting write access.