What is CISA SCuBA? Secure Cloud Business Applications Explained

8 minute read
Intermediate

CISA SCuBA is the federal government's answer key for a secure Microsoft 365 tenant, mandatory for agencies under BOD 25-01. What the baselines cover and why private companies should run them.

What the Baselines Cover

The Microsoft 365 baselines are organized by service. Each is a numbered list of policies with a rationale, a mapping to the MITRE ATT&CK techniques the policy defends against, and instructions for checking and implementing the setting.

Entra ID. Legacy authentication blocked. Phishing-resistant MFA required for all users, with a documented exception process for break-glass accounts. Privileged roles limited in number, assigned through Privileged Identity Management with activation rather than standing membership, and protected with phishing-resistant MFA. User consent to third-party applications restricted. Guest access controlled. Sign-in and audit logs retained and exported.

Exchange Online. Automatic forwarding to external domains disabled. SPF, DKIM, and DMARC configured with DMARC at reject. Mailbox auditing enabled. Anti-phishing, anti-spam, and Safe Attachments and Safe Links policies at the standard or strict preset. Mail transport rules reviewed.

SharePoint Online and OneDrive. External sharing limited, anonymous links disabled or expiring, default sharing links restricted to specific people, and download blocked on unmanaged devices where the risk profile warrants.

Teams, Defender, Power Platform, Power BI. External access controlled, anonymous meeting join restricted, Defender preset security policies applied, environment creation and connector use governed in Power Platform, and external sharing controlled in Power BI.

SHALL and SHOULD

Policies written as SHALL are required under BOD 25-01 for agencies and are the ones CISA considers non-negotiable. SHOULD policies are strongly recommended with documented risk acceptance permitted. For a private organization, the SHALL list is a reasonable floor and the SHOULD list is where the judgment lives.

Why It Exists: The Intrusion Pattern

SCuBA was not written from theory. After SolarWinds, CISA and its partners reconstructed how attackers who had compromised on-premises systems moved into Microsoft 365: forging tokens, adding credentials to service principals, granting themselves application permissions, and reading mail from tenants that had never been configured to notice. The 2023 Storm-0558 intrusion into federal Exchange Online mailboxes, and the 2024 Midnight Blizzard intrusion that reached federal agency correspondence through a compromised Microsoft corporate tenant, reinforced the same lesson. The cloud tenant is the target. Its configuration decides how long an intruder stays.

Every SCuBA policy traces to a technique used in one of those campaigns or in the business email compromise cases that cost private organizations six and seven figures. The external forwarding rule that exfiltrates invoice threads. The legacy protocol that bypasses MFA. The user consent setting that lets a malicious application read every mailbox. The unified audit log that was never turned on, so the investigation starts with nothing.

SCuBA, CIS, and NIST 800-53

The three frameworks stack. NIST SP 800-53 says what a control must achieve. The CIS Benchmark says how to achieve it on Microsoft 365, across several hundred recommendations with Level 1 and Level 2 profiles. SCuBA says which of those configurations the federal government considers mandatory after watching them fail. Most SCuBA SHALL policies correspond to CIS Level 1 recommendations. A risk register that carries the 800-53 control ID and the CIS recommendation number on each finding can add the SCuBA policy ID without changing the row. The value of the third identifier is authority: a finding tagged to a CISA baseline made mandatory by federal directive is harder for a stakeholder to dismiss than the same finding tagged to a vendor's advice.

Running ScubaGear

ScubaGear is a PowerShell module published by CISA on GitHub and the PowerShell Gallery. It authenticates to the tenant with read-only permissions, evaluates each policy, and writes an HTML conformance report with pass, fail, and manual-check results. It does not change anything. Most mid-market tenants can be assessed in under an hour. The report is the right starting point for a hardening project, a renewal conversation with an underwriter, or a diligence data room. It is not the right document to hand a board as evidence of security, because it measures configuration, not compromise.

What SCuBA Does Not Ask

A tenant can pass every SHALL policy and still be occupied. SCuBA assesses whether external forwarding is disabled today; it does not look for the inbox rules an attacker created before it was disabled. It assesses whether MFA is required; it does not look for the session token captured through an adversary-in-the-middle phishing page after MFA was satisfied. It assesses whether device-based Conditional Access is enforced; it does not look for the rogue device an attacker registered so their sign-ins would qualify as compliant. These are not gaps in SCuBA. They are the boundary of what a configuration baseline can see. The organizations that get hurt are the ones that treat a passing conformance report as the end of the question rather than the start of it.

Executive Implications

For a CFO, SCuBA is a free, authoritative, and fast answer to the question is our Microsoft 365 tenant configured the way the federal government says it should be? If the answer is no, the report names the gaps. For a GC, SCuBA is the standard of care that a regulator or opposing counsel will cite after an incident, so the time to know the conformance result is before the incident. For a PE operating partner, ScubaGear across the portfolio produces a consistent, comparable configuration baseline in a day, at no license cost, that a technical reviewer in any future sale process will recognize.

For a defense contractor or any organization in the federal supply chain, SCuBA conformance is increasingly what a prime or an agency means when it asks whether the cloud tenant is secure.

Related Reading

Real-World Example: The Settings CISA Wrote Down

The 2024 Midnight Blizzard campaign against Microsoft's corporate environment began with a password spray against a legacy, non-production test tenant account that did not have MFA enabled. From that foothold the actor found a legacy OAuth test application with elevated access to the corporate environment, created additional malicious applications, granted them mail-reading permissions, and read the mailboxes of senior leadership and security staff. Federal agencies whose correspondence with Microsoft sat in those mailboxes were notified months later.

Read against the SCuBA Entra ID baseline, the chain maps policy by policy: MFA not enforced on an account, legacy authentication not blocked, user and application consent not restricted, application permissions not reviewed, privileged access not time-bound. Each is a SHALL. CISA published them because this chain, and the SolarWinds chain before it, had already run in government tenants. The baseline is the incident report, rewritten as a checklist.

BOD 25-01

The December 2024 Binding Operational Directive that made the SCuBA Microsoft 365 baselines mandatory for every federal civilian agency. CISA wrote the baselines after watching attackers pivot into government cloud tenants through misconfigurations that the private sector still carries.

How Cloudskope Can Help

Cloudskope runs the SCuBA baselines alongside the CIS Benchmarks on every Microsoft 365 assessment, and every finding carries the SCuBA policy ID with its NIST SP 800-53 control and CIS recommendation number. Cloudskope SARTUS™ then asks the question the baseline cannot: whether the tenant was compromised before it was hardened. Three days of assessment across configuration, credential exposure, and active compromise, three days of closing what it finds, fixed fee. See how the register maps across frameworks.