that help customers deploy and run Windows Server and Linux virtual machines in minutes. Migrate workloads without having to change existing code. Securely connect your on-premises corporate network to virtual machines running in the public cloud. Agenda What is Cloud/Azure Azure Services Security & Compliance Pricing
Redundant power supplies from separate providers, battery and diesel backup generators, climate control, and fire prevention and suppression LOGICAL: • Windows Azure is optimized for cloud access with no admin access to guests or applications • Applications and users do not update the OS CONTINUITY: • Multiple data centers in different geographies • Users can choose single location or geo-distributed data centers • Storage data is replicated multiple times • Fabric is designed to be backed up and restored from checkpoints COMPLIANCE & CERTIFICATION: • Microsoft is committed to complying with all local laws • Industry certification is a core part of the Windows Azure roadmap • Customers are ultimately responsible for the security and compliance of their services or applications– Windows Azure is a platform
Scanning and monitoring AV Configuration/patch Host Security (hardened operating system) Application-Level Countermeasures Application Authentication Authentication to Data World-class Security Data
data to Microsoft from within EU Done ISO 27001 Broad international information security standard Done (for core services) SAS70 US accounting audit standard Replaced by SSAE16 SSAE16 Replacement for SAS70 Done (for core services) FISMA / FedRAMP Required by law for US Federal agencies and looked on favorably by other government agencies In progress EU Model Clauses Robust commitment for handling EU PII and transfer to US Done (for core services) PCI DSS Storing or processing credit card information In progress HIPAA BAA Protected health information in the US Done (for core services)