Policy and Compliance Flashcards

1
Q

Core tenets of Security, Privacy, and Compliance - Azure Trusted Cloud

A

Security, privacy, compliance, resiliency and Intellectual Property protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security and Privacy

A

Azure its built with security in mind; delivers tools and technologies to help organizations protect applications and data; uses encryption; offers advanced tools to detect and defend against security threats.

You own all your data in Azure; your data will not be mined or used for marketing; control where the data is located and who has access; Microsoft follow a specific policy for government and law enforcement requests; allows remove data if you discontinue using their service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Compliance, Resiliency and Intellectual Property protection

A

Follows international standards and helps customers to follow them; has more than 90 compliance certifications; allows more than 50 regional standards; helps in more than 35 industries like health, governance finance, …

High availability – no down times, disaster recovery and backup.

Don’t steal your ip or code; protects you from patents, …

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Microsoft Privacy Statement (1), Online Services Terms (2), Data Protection Addendum (3)

A

(1) How it’s your data used, why its your data needed, terms and privacy statements.
(2) The contract and services terms that are given to you, …
(3) How they handle your data, how they store it, what happens if there is a security incident, how long is data retained, biometric data, …

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Trust Center

A

Web page with a lot of documentation, standards, rules, privacy statement, transparency. Include the compliance terms such as GDPR, ISO and NIST. It’s a portal of documentation across the world. Has tools for you to be in compliance with all of this standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

GDPR, ISO and NIST

A

GDPR: Rules that allow EU citizens more control over their personal data, and affects companies outside EU that handle EU citizens data. Data protection, data collection illegally, reporting obligations in case of data mishandled, …

ISO (International Organization for Standardization)
Azure is in compliance with ISO Standards.

NIST Cybersecurity framework (National Institute of Standards and Technology): Audited for compliance to security and privacy processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Azure Sovereign Regions

A

There are separate regions that the general public don’t have access to. Its actually needed for you to have a separate account to access some of these regions. These are isolated data centers separate from the Azure public cloud. Has specific standards and rules. (Ex: US government agencies; department of defense (DoD) has 2; Azure China has separate account, separate log in, the data remains in China).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly