risk management in microsoft online services

12
Updated August 10, 2009 Security in Business Productivity Online Suite

Upload: microsoft-private-cloud

Post on 14-Dec-2014

614 views

Category:

Technology


1 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Risk Management in Microsoft Online Services

Updated August 10, 2009

Security in Business Productivity Online Suite

Page 2: Risk Management in Microsoft Online Services

AgendaWhat is Business Productivity Online SuiteMicrosoft Online Services Risk Management

SecurityPrivacy & RegulatoryService ContinuityCompliance Management

Customer BenefitsQ&A

Page 3: Risk Management in Microsoft Online Services

Business Productivity Online Suite

Some existing customers

Page 4: Risk Management in Microsoft Online Services

Risk Management ProgramInformation Security Policy

Security PrivacyService Continui

ty

Compliance Management

Page 5: Risk Management in Microsoft Online Services

Security ProgramA risk-based, multi-dimensional approach to help safeguard services and data

Security Management Security Monitoring & Response, Threat & Vulnerability Management

Edge Routers, Firewalls, Intrusion Detection, Vulnerability Scanning

Network perimeter

Dual-factor Authentication, Intrusion Detection, Vulnerability Scanning

Internal Network

Access Control & Monitoring, Anti-Malware, Patch & Config Mgmt

Host

Secure Development Lifecycle, Access Control & Monitoring, Anti-Malware

Application

Access Control & Monitoring, File/Data IntegrityData

User Account Management, Training & Awareness, Screening

Facility Video Surveillance, biometrics, Access Control

Page 6: Risk Management in Microsoft Online Services

Privacy ProgramDesigned to establish consistent "high bar" privacy practices that support global standards for data handling and transfer

Documented & enforced privacy requirements

Microsoft Online Services Privacy Statement Microsoft Online Services Privacy and

Regulatory Divisional Requirements Specific to Software + Services

Corporate-level Privacy Guidelines for Service Development

Privacy disclosures & transparency Microsoft Online Services Privacy Statement EU Safe Harbor Certification

Notice

Choice

Disclosure

Page 7: Risk Management in Microsoft Online Services

Service Continuity Program

Service Continuity

Management

Governance

Business Impact Analysis

Dependency Analysis

Gap Analysis & Reporting

Strategies & Solutions

Planning

Maintaining & Exercising

Training & Awareness

Business Impact AssessmentSingle point of failure and dependency analysisDefined recovery objectivesDocumented recovery plans and proceduresRecovery exercises

Page 8: Risk Management in Microsoft Online Services

Compliance ManagementRationalize and harmonize requirements

Microsoft internalCorporate (security & privacy policies, etc.)Microsoft Online Services (security & privacy policies)Trustworthy Computing (SDL, Engineering Excellence, etc.)

Industry & regulatoryIndustry best practices: ISO/IEC 27001:2005, NIST SP 800-53

Customer requirements: SOX, HIPAA, FISMA, GLBA, PCI DSSData protection laws

Geo Political

Industry & Regulatory

Microsoft Internal

Inputs

Common Baseline Requirements

Conditional Requirements

Remove non-applicable, harmonize redundant, identify conditional

Page 9: Risk Management in Microsoft Online Services

Compliance Monitoring & AssessmentInternal monitoring

Technical compliance (patch and configuration mgmt, vulnerability scans, penetration tests, etc.)

Personnel compliance (training and awareness, screening, etc.) Process compliance (business process evaluation,

change control, access management, etc.) Physical security compliance (CCTV monitoring,

access control and logging, etc.)

Third Party validation Facilities & infrastructure services – ISO cert + SAS 70 BPOS Dedicated – ISO aligned + SAS 70 BPOS Standard – ISO aligned

Microsoft Online

Services

Planning

Assessmen

t

Remediatio

n

Reporting

Page 10: Risk Management in Microsoft Online Services

Commitment in ActionWhat we provide

Services are designed, engineered and operated with security as core tenet

Privacy of customer data is respected

Audits demonstrate independent validation

Service resiliency and service and data recoverability are fundamental to service operations

99.9% uptime SLA

Customer benefits

Mature and comprehensive security management

Service upgrades and security updates

Comprehensive security monitoring and response

Customer control over customer data

Compliance management capabilities available to customers

Page 11: Risk Management in Microsoft Online Services

Additional ResourcesMicrosoft Online Services: www.microsoft.com/online

Business Productivity Online Suite• 30 day free trial : http://www.microsoft.com/online/products.mspx• Technical information on TechNet http://technet.microsoft.com/msonline

• Service descriptions, developer guide, service level agreement, migration/deployment guides and tools and other technical information and blogs

• Security white paper: http://go.microsoft.com/fwlink/?LinkID=125754&clcid=0x409

• Privacy policy: http://www.microsoft.com/online/legal/MOS_Privacy_Statement_Full.htm

Page 12: Risk Management in Microsoft Online Services

Thank You!