Online Services FAQ
Security and Reliability
Q:
How can Microsoft be sure that my data is secure?
A:
Businesses must use a combination of technology and processes to help protect their
messaging and collaboration environment from internal and external security threats.
These threats use an array of attack vectors that require the establishment of multiple
layers of protection. The threats are also constantly evolving in an effort to expose
weaknesses in old defenses, thus requiring the use of multiple technologies. Together,
the use of multiple layers of security controls and multiple technologies form Microsoft's
defense-in-depth strategy. To simplify security management and to enhance performance,
Microsoft also recommends that the solution is integrated into the business infrastructure.
Microsoft looks at security along three dimensions: security of data (virus/spam
filtering in the cloud), secure data access (HTTPS- 128-bit encryption)
and secure datacenters.
Q:
Are the Business Productivity Online Standard Suite services Sarbanes-Oxley compliant?
A:
The Dedicated version of the Business Productivity Online Standard Suite supports
your Sarbanes-Oxley compliance objectives by underpinning its services with a comprehensive
set of controls that align with your SOX requirements. The design
and operational effectiveness of these controls are internally assessed by our staff
and external auditors on an on-going basis as well as subject to an independent
SAS
70 Type II audit conducted each year.
The Standard version of the Business Productivity Online Standard Suite will be
seeking a
SAS
70 Type II audit attesting to the effectiveness of Microsoft's internal controls.
While our U.S. datacenters maintain a
SAS
70 Type II for the physical controls of each facility, the Services (Live Meeting,
EHS, Exchange Online, SharePoint Online and Office Communications Online)
themselves do not. Live Meeting maintains both the CyberTrust Service Provider Certification
and the CyberTrust Application Certification, which surpasses the control requirements
for SOX. The Business Productivity Online Standard Suite Standard
implementation is scheduled to undergo the CyberTrust certification within the next
couple of months.
Q:
What about data privacy and
EU
Safe Harbor legislation?
A:
All Microsoft Online Services allow customers in almost all cases to meet privacy
compliance, depending on jurisdiction and industry requirements.
Each of these Services has been built to adhere to Microsoft's internal privacy
standards, as described in its published document, "Microsoft's Privacy Guidelines
for Developing Software Products and Services." This set of standards helps ensure
that privacy and data protections are systematically incorporated into the development
and deployment of almost all Microsoft products and services. For more information
about Microsoft's Privacy Standards for Development, visit Microsoft's Trustworthy
Computing Privacy Web-Site.
Additionally, each of these Services has a privacy statement that describes in detail
how your data will be treated, and is enforceable through
FTC
rules and as incorporated into the Product Use Rights of your license. Microsoft
is a Safe Harbor company and European customers can safely transfer data between
Europe and the United States on these Services.
Q:
What is the availability and performance like? Is a dedicated network connection
required?
A:
Microsoft offers a 99.9% scheduled uptime Service Level Agreement. The Standard
version of the service does not require any dedicated network connectivity. Data
exchanged between our datacenters and the end users are secured with a 128 bit encryption
(https). Depending on the current customer network connection bandwidth,
some customers might have to upgrade their existing network connection. In the Dedicated
version, dedicated network connection is required and is the responsibility of the
customer.
Q:
What is the uptime
SLA
or security guarantees from Microsoft for
BPOS?
A:
Microsoft provides a 99.9% uptime Service Level Agreement for Exchange Online, SharePoint
Online, Office Live Meeting, and Office Communications Online.
|