{"id":163,"date":"2015-01-15T08:00:00","date_gmt":"2015-01-15T08:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/bharry\/2015\/01\/15\/visual-studio-online-iso-27001-certification-and-european-model-clauses\/"},"modified":"2024-03-12T12:58:17","modified_gmt":"2024-03-12T19:58:17","slug":"visual-studio-online-iso-27001-certification-and-european-model-clauses","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/bharry\/visual-studio-online-iso-27001-certification-and-european-model-clauses\/","title":{"rendered":"Visual Studio Online ISO 27001 Certification and European Model Clauses"},"content":{"rendered":"<p>In December, we hit an important milestone for Visual Studio Online.\u00a0 We received <a href=\"http:\/\/en.wikipedia.org\/wiki\/ISO\/IEC_27001:2013\">ISO 27001<\/a> certification and added the <a href=\"http:\/\/blogs.microsoft.com\/on-the-issues\/2012\/07\/05\/why-cloud-customers-cant-ignore-model-clauses-especially-now\/\">European Model Clauses<\/a> to our service terms.<\/p>\n<p>We take protection of customer data very seriously and work hard to ensure your data is safe and that we comply with expected policies in all the regions in which we operate.\u00a0 These two milestones are important steps on a journey of increasing our guarantees and documenting our adherence to our policies.<\/p>\n<p>Here\u2019s a nice image of our certification document (blushing with pride :))\u2026<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/bharry\/wp-content\/uploads\/sites\/8\/2015\/01\/6170.image_thumb_51B4C4BA.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-15651\" src=\"https:\/\/devblogs.microsoft.com\/bharry\/wp-content\/uploads\/sites\/8\/2015\/01\/6170.image_thumb_51B4C4BA.png\" alt=\"Image 6170 image thumb 51B4C4BA\" width=\"730\" height=\"801\" srcset=\"https:\/\/devblogs.microsoft.com\/bharry\/wp-content\/uploads\/sites\/8\/2015\/01\/6170.image_thumb_51B4C4BA.png 730w, https:\/\/devblogs.microsoft.com\/bharry\/wp-content\/uploads\/sites\/8\/2015\/01\/6170.image_thumb_51B4C4BA-273x300.png 273w\" sizes=\"(max-width: 730px) 100vw, 730px\" \/><\/a><\/p>\n<p>You can find the documentation on our inclusion of European Model Clauses in the \u201cAdditional European Terms\u201d section of our <a href=\"http:\/\/www.microsoftvolumelicensing.com\/DocumentSearch.aspx?Mode=3&amp;DocumentTypeId=31\">Microsoft Online Service Terms<\/a>.<\/p>\n<p>This is the culmination of months\u2019 worth of work for our team to clearly define and document a wide range of processes for building and operating Visual Studio Online that enable us to ensure we are protecting customer data every step of the way.<\/p>\n<p>I\u2019m very happy to have accomplished this and am looking forward to continuing down the certification road.<\/p>\n<h3>A Word about Certification<\/h3>\n<p>I don\u2019t know about you, but I never imagined myself becoming overly involved in process certifications.\u00a0 There are a dizzying number of certifications ISO, SOC, HIPPA, FISMA, FedRAMP, and on and on.\u00a0 They often involve long, inscrutable documents and mysterious audit\/certification processes.<\/p>\n<p>Over the past year I\u2019ve learned more than I ever intended to know about them.\u00a0 Some of the certifications are broad, some are for vertical industries, but, you can kind of blur your eyes and see a progression through them.\u00a0 ISO 27001 is often the one to start with.\u00a0 It\u2019s broad and the things you need to do help build towards additional certifications.<\/p>\n<p>The way you should think about ISO 27001 certification is that it provides an independent attestation of a set of documented practices and procedures that cover a wide range of customer data protection aspects (you can see more about the specifics in the Wikipedia article I referenced at the top).\u00a0 ISO 27001 does not take a position on what those practices should be \u2013 rather, it just ensures that you have developed practices and assessed them against your business\/customer requirements.\u00a0 It also does not certify that you consistently follow those policies \u2013 only that you have them, they cover the necessary areas and that your team knows about them \u2013 for instance the auditors interviewed people on my team to ensure they were aware of the practices.<\/p>\n<p>ISO 27001 isn&#8217;t the end of our journey \u2013 it\u2019s the beginning.\u00a0 It demonstrates that we are thinking hard about customer data protection and investing in improving.\u00a0 The next step is likely SOC compliance.\u00a0 SOC \u201cbuilds on\u201d ISO by demonstrating that, over time, you are, in fact, following the procedures that have been documented.\u00a0 Further up the compliance \u201chierarchy\u201d certifications start to take a stronger point of view on what has to be in the processes and the audits get increasingly involved (and expensive :().<\/p>\n<p>More than you probably ever wanted to know but, hopefully, some useful Cliffs Notes.<\/p>\n<p>Stay tuned for more progress regarding VS Online compliance and certification over the next year.<\/p>\n<p>Brian<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In December, we hit an important milestone for Visual Studio Online.\u00a0 We received ISO 27001 certification and added the European Model Clauses to our service terms. We take protection of customer data very seriously and work hard to ensure your data is safe and that we comply with expected policies in all the regions in [&hellip;]<\/p>\n","protected":false},"author":244,"featured_media":14617,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[8],"class_list":["post-163","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-vsonline"],"acf":[],"blog_post_summary":"<p>In December, we hit an important milestone for Visual Studio Online.\u00a0 We received ISO 27001 certification and added the European Model Clauses to our service terms. We take protection of customer data very seriously and work hard to ensure your data is safe and that we comply with expected policies in all the regions in [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/posts\/163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/users\/244"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/comments?post=163"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/posts\/163\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/media\/14617"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/media?parent=163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/categories?post=163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/bharry\/wp-json\/wp\/v2\/tags?post=163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}