You are on page 1of 4

BSI Case Study Microsoft ISO/IEC 27018

Microsoft sets a high bar


for Information Security

BSI has certified several Microsoft Background


Innovation in business increasingly relies on technology.
divisions that provide Trusted Cloud For IT departments to remain competitive, use of the
Services to ISO/IEC 27001, including cloud is not just more cost effective but can unlock
additional business value through the use of big data
Microsoft Office 365, Microsoft Azure analytics and other cloud technologies. By facilitating the
and Microsoft Dynamics CRM services as ability to bring new services and products online quickly,
with increased agility, cloud services are transforming
well as Online Data Centers and Physical even traditional businesses. But, with innovation comes
concern. Millions of people have had their personal
Infrastructure provided by Microsoft information stolen in the course of everyday transactions.
Global Foundation Services and has Data breaches reached a record high in 2014. Enterprise
customers, in particular, need to feel that their
verified conformance of each to information is properly protected. As the world’s leading
ISO/IEC 27018, the first international provider of software services, Microsoft wanted to
improve the trust customers have in cloud services.
cloud privacy standard.
BSI Case Study Microsoft ISO/IEC 27018

As the cloud becomes more prevalent in business, the The goals reflect Microsoft’s focus on building trusted
regulatory environment also continues to tighten. While cloud services by continuously improving the reliability,
the US requires companies to undergo a variety of privacy controls and security features of its services.
audits, many US-centric schemes rely on self-assertions Cloud computing has become an extension of virtually
and attestations. International standards, like ISO/IEC every IT department, by providing greater flexibility, but
27001, however, demand independent third-party audits requiring fewer resources. The cloud provides access
by experts who test the veracity and applicability of the to a variety of services, from Software as a Service,
scope and relevant controls. In the US, there are a number to Platform as a Service as well as Infrastructure as a
of regulations addressing the use of information, but Service. From the consumers’ standpoint, as cloud usage
there is no overarching protection guarantee of privacy expands, so do concerns about how data is processed
of personally identifiable information (PII). In Europe, by and protected.
contrast, the Data Protection Directive (Directive 95/46/
Microsoft has been certified to ISO/IEC 27001 since
EC) imposes restrictions on the control, processing
2006 and has proactively instituted policies and controls
and transmission of personal data. For international
to restrict access and transmission of information.
organizations or companies wanting to work globally,
Microsoft Office 365, Microsoft Azure, Microsoft
compliance to US regulations alone is simply not enough.
Dynamics CRM services as well as Online Data Centers
and Physical Infrastructure all act as conduits of personal
Customer Needs
information and protectors of key customer data which
In working towards certification to ISO/IEC 27001 and to
must be protected. To build trust, Microsoft needed to
include ISO/IEC 27018, Microsoft identified its goals as
be able to demonstrate information security controls
the need to:
were in place in each of these areas with the enhanced
• Meet the expectations of customers and regulators certification that ISO/IEC 27018 brings.
worldwide that processors will protect customer data
and personal information Complexity of the problem
• Use of cloud computing services is being inhibited by
• Improve trust in cloud computing
concerns over security and privacy
• Protect customer data, particularly PII, stored in
• Cloud regulations continue to evolve
the cloud
• Delivering a global service to global customers requires
• Ensure global legislative requirements are consistently
consistent communication of commitments about
applied for the protection of PII
security and privacy for cloud services
• Create a mechanism for independent and accredited
• Although ISO/IEC 27001 certification provides trusted
third party verification of underlying practices and
evidence of a comprehensive information security
policies of a cloud service provider
management process, ISO/IEC 27001 does not address
the cloud specifically
BSI Case Study Microsoft ISO/IEC 27018

Specific Solutions • Customers can point to Microsoft’s certificates as


The ISO/IEC 27000 family of standards for Information evidence to data protection authorities that they
Security provides the framework for companies have chosen a responsible processor for personal
to develop processes and procedures to address information
information security concerns. ISO/IEC 27001 offers 114 • Clear communication and trusted verification of
controls, which, when properly instituted, recognize and commitment to protect the security and privacy of
mitigate the various risks involved with the collection and customer data in cloud services improves customer
dissemination of information. trust in Microsoft services
In 2014, ISO/IEC 27018 was developed to address Microsoft has raised the bar for all cloud services
the rising concerns about cloud computing and the providers. ISO/IEC 27018 outlines the model for ensuring
protection of PII by public cloud service providers. protection of PII no matter where the information travels,
By conforming to controls outlined by this standard, allowing ready access to markets across Europe, Asia as
Microsoft has been independently-assessed to confirm well as the US.
that the policies and procedures are in place regarding
the secure return, transfer and deletion of PII that is Why BSI
stored in its data centers. In addition, ISO/IEC 27018
Microsoft’s long-standing relationship with BSI allows
provides a number of detailed restrictions on how data is
it to continuously improve its information security
to be retained, transmitted and accessed.
practices. As the originator of the world’s first standard
Bringing these two international standards together to address the concerns of information security, BSI
under one scope for third-party certification provides understands that information is often an organization’s
both overarching information security assurances for most valuable asset and thus, must be protected.
Microsoft’s customers as well as the specific guarantees
Today, BSI leads the market in certification to ISO/IEC
needed for cloud users.
27001. As of 2013, over 70% of certifications in the US
“Microsoft has invested heavily to build ISO/IEC 27001 were issued by BSI. Microsoft required a consistent
practices into the core of our cloud services—it’s not approach to bring all the data centers across the globe
just a certificate to us. Adding protection of PII using under one scope. BSI’s worldwide presence made that
the controls in ISO/IEC 27018 is a great fit for our cloud possible.
services and operations, and further proof that we take
protection of customer data and PII seriously,” stated Tom Benefits and ROI of certification
Keane, Partner Director, Program Management, Azure Brad Smith, Microsoft’s General Counsel & Executive
Services. Vice President, Legal and Corporate Affairs outlined a
number of benefits the customer receives as a result
Benefits of Certification of Microsoft’s certification of ISO/IEC 27001 and its
• Microsoft’s customers have evidence of specific conformance with ISO/IEC 27018:
measures taken to address processing personal and
• “You are in control of your data. Our adherence to the
confidential information in Microsoft cloud services
standard ensures that we only process personally
• Customers can trust BSI’s assessment of Microsoft’s identifiable information according to the instructions
commitment to security and data protection, avoiding that you provide to us as our customer.
the need for their individual on-site audit
BSI Case Study Microsoft ISO/IEC 27018

• You know what’s happening with your data. Adherence • Your data won’t be used for advertising. Enterprise
to the standard ensures transparency about our customers are increasingly expressing concerns about
policies regarding the return, transfer, and deletion of cloud service providers using their data for advertising
personal information you store in our data centers. purposes without consent. The adoption of this standard
We’ll not only let you know where your data is, but if reaffirms our longstanding commitment not to use
we work with other companies who need to access enterprise customer data for advertising purposes.
your data, we’ll let you know who we’re working with. In
• We inform you about government access to data.
addition, if there is unauthorized access to personally
The standard requires that law enforcement requests
identifiable information or processing equipment or
for disclosure of personally identifiable data must be
facilities resulting in the loss, disclosure or alteration
disclosed to you as an enterprise customer, unless this
of this information, we’ll let you know about this.
disclosure is prohibited by law. We’ve already adhered
• We provide strong security protection for your to this approach (and more), and adoption of the
data. Adherence to ISO 27018 provides a number of standard reinforces this commitment.” 1
important security safeguards. It ensures that there
are defined restrictions on how we handle personally Next steps
identifiable information, including restrictions on • Microsoft continues to work with BSI to help message
its transmission over public networks, storage on its security and privacy capabilities to their customers
transportable media, and proper processes for data and the industry at large.
recovery and restoration efforts. In addition, the
standard ensures that all of the people, including • Continue evolution of Microsoft’s ISO/IEC 27001
our own employees, who process personally certification with support for new controls as they
identifiable information must be subject to a emerge.
confidentiality obligation. • Other large cloud service providers hope to follow
Microsoft’s lead on the protection of PII and consumer
data in cloud services.

1
 rad Smith, General Counsel & Executive Vice President, Legal and Corporate Affairs, Microsoft.
B
http://blogs.microsoft.com/on-the-issues/2015/02/16/microsoft-adopts-first-international-cloud-privacy-standard. Accessed 4/12/2015.

Any business could benefit by choosing a cloud service provider that


implements ISO/IEC 27018 just like Microsoft.
BSI/USA/455/MS/715/E

All cloud service providers could benefit from ISO/IEC 27001 just like Microsoft.
To find out more, visit www.bsiamerica.com.
BSI Group America Inc. BSI Group Canada Inc. The BSI certification mark may be used on your stationery, literature
12950 Worldgate Drive, Suite 800 6205B Airport Road, Suite 414 and vehicles when you have successfully achieved certification and
Herndon, VA 20170 Mississauga, Ontario conform with applicable guidelines.
USA L4V 1E3
Canada The mark shall never be applied directly on the product or service.
Tel: +1 888 429 6178
Fax: 1 703 437 9001 Tel: 1 800 862 6752
Email: inquiry.msamericas@bsigroup.com Fax: 1 416 620 9911
Web: www.bsiamerica.com Email: Inquiry.canada@bsigroup.com
Web: www.bsigroup.ca
www.bsigroup.ca/fr Copyright © 2015 The British Standards Institution. All Rights Reserved.

You might also like