Microsoft Azure Security, Privacy, & Compliance

Similar documents
This presentation is intended to provide an overview of GDPR and is not a definitive statement of the law.

Intermedia s Private Cloud Exchange

Introduction to AWS GoldBase

Accelerate GDPR compliance with the Microsoft Cloud Agustín Corredera

COMPLIANCE IN THE CLOUD

INTO THE CLOUD WHAT YOU NEED TO KNOW ABOUT ADOPTION AND ENSURING COMPLIANCE

Verasys Enterprise Security and IT Guide

Morgan Independent Software Vendor Lead

Accelerate GDPR compliance with the Microsoft Cloud Ole Tom Seierstad National Security Officer Microsoft Norway

TRACKVIA SECURITY OVERVIEW

How do you decide what s best for you?

U susret GDPR regulativi Dočekajmo spremni Maj 2018

Service Provider Consulting

By 2020, a corporate no-cloud policy will be as rare as a no-internet policy is today. 1

Controlled Document Page 1 of 6. Effective Date: 6/19/13. Approved by: CAB/F. Approved on: 6/19/13. Version Supersedes:

Cloud Transformation and Significance of Security

Provisioning IT at the Speed of Need with Microsoft Azure. Presented by Mark Gordon and Larry Kuhn Hashtag: #HAND5

AWS SECURITY AND COMPLIANCE QUICK REFERENCE GUIDE

Trusted Cloud: Microsoft Azure Security, Privacy, and Compliance. April 2015

AZURE CLOUD SECURITY GUIDE: 6 BEST PRACTICES. To Secure Azure and Hybrid Cloud Environments

Compliance & Security in Azure. April 21, 2018

Amit Panchal Enterprise Technology Strategist

Microsoft Security Management

SoftLayer Security and Compliance:

The Nasuni Security Model

Cloud Services. Infrastructure-as-a-Service

Google Cloud & the General Data Protection Regulation (GDPR)

Cloud Customer Architecture for Securing Workloads on Cloud Services

Agenda. What is Cloud/Azure Azure Services & Scenarios Security Pricing

10 Considerations for a Cloud Procurement. March 2017

Cloud is the 'Only' Way Forward in Information Security. Leveraging Scale to Make the Unknown Known, in Dev, Sec & Ops.

A Checklist for Compliance in the Cloud 1. A Checklist for Compliance in the Cloud

Watson Developer Cloud Security Overview

Copyright 2011 EMC Corporation. All rights reserved.

AUTOTASK ENDPOINT BACKUP (AEB) SECURITY ARCHITECTURE GUIDE

Robert Brammer. Senior Advisor to the Internet2 CEO Internet2 NET+ Security Assessment Forum. 8 April 2014

Microsoft s Cloud. Delivering operational excellence in the cloud Infrastructure. Erik Jan van Vuuren Azure Lead Microsoft Netherlands

Building Cloud Trust. Ioannis Stavrinides. Technical Evangelist MS Cyprus

Azure SQL Database Basics

Ο ρόλος της τεχνολογίας στο ταξίδι της συμμόρφωσης με τον Γενικό Κανονισμό. Αντιγόνη Παπανικολάου & Νίκος Αναστόπουλος

locuz.com SOC Services

Cloud Computing Microsoft in the Enterprise. Anthony Murphy, Cloud Solution Specialist Microsoft

Data Protection in the AWS Cloud: Implementing GDPR and Overview of C5

What the GDPR is and how to deal with it. Russell McDermott Sales Engineer +44 (0) x 2208

Microsoft 365 Business FAQs

Our Mission. Empower every person and every organization on the planet to achieve more.

ISO Professional Services Guide to Implementation and Certification AND

Automate sharing. Empower users. Retain control. Utilizes our purposebuilt cloud, not public shared clouds

CSA GUIDANCE VERSION 4 S TAT E O F T H E A R T CLOUD SECURITY AND GDPR NOTES. Hing-Yan Lee (Dr.) EVP, APAC, Cloud Security Alliance

01.0 Policy Responsibilities and Oversight

Virtual Machine Encryption Security & Compliance in the Cloud

Temenos Bringing banking to millions through Cloud Scale Innovation

Continuous auditing certification

ISACA Cincinnati Chapter March Meeting

Altius IT Policy Collection Compliance and Standards Matrix

Healthcare and the Cloud:

Top Reasons To Audit An IAM Program. Bryan Cook Focal Point Data Risk

Modern Database Architectures Demand Modern Data Security Measures

Workday s Robust Privacy Program

Security & Compliance in the AWS Cloud. Amazon Web Services

AWS SECURITY AND COMPLIANCE QUICK REFERENCE GUIDE

Altius IT Policy Collection Compliance and Standards Matrix

Magento GDPR Frequently Asked Questions

ProCloud An Overview

Virtustream Cloud and Managed Services Solutions for US State & Local Governments and Education

Swedish bank overcomes regulatory hurdles and embraces the cloud to foster innovation

zsah Cloud Offering Security FAQ In partnership with Clearswift

Security & Compliance in the AWS Cloud. Vijay Rangarajan Senior Cloud Architect, ASEAN Amazon Web

Supporting the Cloud Transformation of Agencies across the Public Sector

How to ensure control and security when moving to SaaS/cloud applications

Cloud Communications for Healthcare

ZyLAB delivers a SaaS solution through its partner data center provided by Interoute and through Microsoft Azure.

Exploring Emerging Cyber Attest Requirements

NE HIMSS Vendor Risk. October 9, 2015 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS

Klaus Schwab, Founder & Executive Chairman

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 7

Optimising cloud security, trust and transparency

HITRUST ON THE CLOUD. Navigating Healthcare Compliance

No Country for Old Security Compliance in the Cloud. Joel Sloss, CDSA Board of Directors May 2017

The Elephant in the Room: Why Many Cloud Communications Providers Don t Like to Talk About Security, Compliance and Reliability

NS2 Cloud Overview The Cloud Built for Federal Security and Export Controlled Environments. Hunter Downey, Cloud Solution Director

Avanade Zerouno : Cloud Experience. Version 1.0 May 16, 2017 Author(s): Ivan Loreti

GDPR - What does this mean for you? Accelerate GDPR compliance with the Microsoft Services. Konstantin Sviridov Andrey Ivanov.

Angela McKay Director, Government Security Policy and Strategy Microsoft

Microsoft Professional Services And Support Data Protection

Getting Started with AWS Security

Microsoft: What s new and cool FY16

What can the OnBase Cloud do for you? lbmctech.com

Mitigating Risks with Cloud Computing Dan Reis

TB+ 1.5 Billion+ The OnBase Cloud by Hyland 600,000,000+ content stored. pages stored

Future Shifts in Enterprise Architecture Evolution. IPMA Marlyn Zelkowitz, SAP Industry Business Solutions May 22 nd, 2013

Current Cloud Certification Challenges Ahead and Proposed Solutions

Custom hybrid IT solutions that meet your security, price, and performance needs. Trusted advisors since 1996.

Table of Contents. Preface xvii PART ONE: FOUNDATIONS OF MODERN INTERNAL AUDITING

Today s top THREAT ACTORS pose unique challenges

Compliance and Security in a Cloud-First Era

Cloud Security. Copyright Ramesh Nagappan. All rights reserved.

White Paper. How Organizations. Can Use The Cloud In Confidence. In business for people.

HOW SNOWFLAKE SETS THE STANDARD WHITEPAPER

Twilio cloud communications SECURITY

Transcription:

Security, Privacy, & Compliance Andreas Grigull Geschäftsentwicklung Assekuranz

Installation von 2000 Servern in 3 Stunden

Technology trends: driving cloud adoption BENEFITS Speed Scale Economics Cloud Trend: 70% 2 weeks to deliver new services vs. 6-12 months with traditional solution Scale from 30,000 to 250,000 site visitors instantly $25,000 in the cloud would cost $100,000 on premises of CIOs will embrace a cloud-first strategy in 2016 (IDC CIO Agenda webinar) 430B+ AD authentications 280% year-over-year database growth in 50% of Fortune 500 use AZURE ADOPTION 3

Cloud innovation OPPORTUNITY FOR SECURITY & COMPLIANCE BENEFITS Pre-adoption Benefits realized concern 94% 60% cited concerns around experienced security benefits data security they as didn t a barrier previously to adoption have on-premise 62% 45% concerned that the said privacy protection increased cloud would as a result in of a moving lack of data to the control cloud SECURTIY Design/Operation Infrastructure Network Identity/access Data PRIVACY COMPLIANCE

Trustworthy foundation BUILT ON MICROSOFT EXPERIENCE AND INNOVATION 1 st Microsoft Data Center Active Directory Trustworthy Computing Initiative Malware Protection Center SOC 1 UK G-Cloud Level 2 SOC 2 FedRAMP/ FISMA Operations Security Assurance 20+ Data Centers Microsoft Security Response Center Windows Update Global Data Center Services Security Development Lifecycle Digital Crimes Unit ISO/IEC 27001:2005 E.U. Data Protection Directive HIPAA/ HITECH CSA Cloud Controls Matrix PCI DSS Level 1

Transparency & independent verification AID CUSTOMERS IN MEETING SECURITY & COMPLIANCE OBLIGATIONS Third-party verification Access to audit reports Compliance packages Best practices and guidance Trust Center Cloud Security Alliance Security Response Center progress report Security intelligence report 6

Data location and redundancy AZURE: Creates three copies of data in each datacenter Offers geo-replication in a datacenter 400+ miles away Does not transfer Customer Data outside of a geo (ex: from US to Europe or from Asia to US) CUSTOMER: Chooses where data resides Configures data replication options Note: data centers, Australia Q2 FY15

Privacy by design Privacy by Design Restricted data access & use Contractual commitments Privacy controls built into Azure design and operations Customer data is only used to provide the service and is never used for advertising Data Processing Agreements, EU Model Clauses, HIPAA BAA 10101010101010101010101010101010 1010101010101010101010101010101010101010101010101010

Contractual commitments EU Data Privacy Approval Microsoft meets high bar for protecting privacy of EU customer data Microsoft offers customers EU Model Clauses for transfer of personal data across international borders Microsoft s approach was approved by the Article 29 committee of EU data protection authorities the first company to obtain this Broad contractual scope Microsoft makes strong contractual commitments to safeguard customer data covered by HIPAA BAA, Data Processing Agreement, & E.U. Model Clauses Enterprise cloud-service specific privacy protections benefit every industry & region

Simplified compliance Information security standards Effective controls Government & industry certifications ISO 27001 SOC 1 Type 2 SOC 2 Type 2 FedRAMP/FISMA PCI DSS Level 1 UK G-Cloud

Security compliance strategy Security goals set in context of business and industry requirements Security analytics & best practices deployed to detect and respond to threats Benchmarked to a high bar of certifications and accreditations to ensure compliance Continual monitoring, test and audit Test and audit Security benchmark analysis Security Compliance Framework Security analytics Risk management best practices Ongoing update of certifications for new services 11

Microsoft commitment Unified platform for modern business

Talk to a Microsoft security expert Explore additional resources: Trustworthy Computing Cloud Services: www.microsoft.com/trustedcloud Microsoft Trust Center for : http://www.windowsazure.com/en-us/support/trust-center