Online Services Security - Reliability

Online Services FAQ

Security and Reliability

Q: How can Microsoft be sure that my data is secure?

A: Businesses must use a combination of technology and processes to help protect their messaging and collaboration environment from internal and external security threats. These threats use an array of attack vectors that require the establishment of multiple layers of protection. The threats are also constantly evolving in an effort to expose weaknesses in old defenses, thus requiring the use of multiple technologies. Together, the use of multiple layers of security controls and multiple technologies form Microsoft's defense-in-depth strategy. To simplify security management and to enhance performance, Microsoft also recommends that the solution is integrated into the business infrastructure. Microsoft looks at security along three dimensions: security of data (virus/spam filtering in the cloud), secure data access (HTTPS- 128-bit encryption) and secure datacenters.

Q: Are the Business Productivity Online Standard Suite services Sarbanes-Oxley compliant?

A: The Dedicated version of the Business Productivity Online Standard Suite supports your Sarbanes-Oxley compliance objectives by underpinning its services with a comprehensive set of controls that align with your SOX requirements. The design and operational effectiveness of these controls are internally assessed by our staff and external auditors on an on-going basis as well as subject to an independent SAS 70 Type II audit conducted each year.

The Standard version of the Business Productivity Online Standard Suite will be seeking a SAS 70 Type II audit attesting to the effectiveness of Microsoft's internal controls. While our U.S. datacenters maintain a SAS 70 Type II for the physical controls of each facility, the Services (Live Meeting, EHS, Exchange Online, SharePoint Online and Office Communications Online) themselves do not. Live Meeting maintains both the CyberTrust Service Provider Certification and the CyberTrust Application Certification, which surpasses the control requirements for SOX. The Business Productivity Online Standard Suite Standard implementation is scheduled to undergo the CyberTrust certification within the next couple of months.

Q: What about data privacy and EU Safe Harbor legislation?

A: All Microsoft Online Services allow customers in almost all cases to meet privacy compliance, depending on jurisdiction and industry requirements.

Each of these Services has been built to adhere to Microsoft's internal privacy standards, as described in its published document, "Microsoft's Privacy Guidelines for Developing Software Products and Services." This set of standards helps ensure that privacy and data protections are systematically incorporated into the development and deployment of almost all Microsoft products and services. For more information about Microsoft's Privacy Standards for Development, visit Microsoft's Trustworthy Computing Privacy Web-Site.

Additionally, each of these Services has a privacy statement that describes in detail how your data will be treated, and is enforceable through FTC rules and as incorporated into the Product Use Rights of your license. Microsoft is a Safe Harbor company and European customers can safely transfer data between Europe and the United States on these Services.

Q: What is the availability and performance like? Is a dedicated network connection required?

A: Microsoft offers a 99.9% scheduled uptime Service Level Agreement. The Standard version of the service does not require any dedicated network connectivity. Data exchanged between our datacenters and the end users are secured with a 128 bit encryption (https). Depending on the current customer network connection bandwidth, some customers might have to upgrade their existing network connection. In the Dedicated version, dedicated network connection is required and is the responsibility of the customer.

Q: What is the uptime SLA or security guarantees from Microsoft for BPOS?

A: Microsoft provides a 99.9% uptime Service Level Agreement for Exchange Online, SharePoint Online, Office Live Meeting, and Office Communications Online.

© 2012 Miles Consulting Corp | Sitemap | Legal