{"id":23179,"date":"2024-10-16T09:30:16","date_gmt":"2024-10-16T16:30:16","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/?p=23179"},"modified":"2024-10-16T09:29:18","modified_gmt":"2024-10-16T16:29:18","slug":"microsoft-365-control-spotlight-information-security-risk-management","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/microsoft-365-control-spotlight-information-security-risk-management\/","title":{"rendered":"Microsoft 365 control spotlight: Information security risk management"},"content":{"rendered":"<p>For app developers and Independent Software Vendors (ISVs), the responsibility of building secure applications that protect customer data has never been more critical.<\/p>\n<p>Information security risk management is a systematic approach to identifying, assessing, and mitigating risks to an organization\u2019s information assets. For app developers and ISVs, proper risk management is not just a regulatory obligation but a crucial aspect of maintaining customer trust and ensuring the integrity of their applications.<\/p>\n<p>App developers and ISVs handle sensitive customer data, from personal information to financial records. Without adequate security measures, this data is vulnerable to breaches, which can lead to severe consequences including financial loss, reputational damage, and legal penalties.<\/p>\n<p>Many developers and ISVs face challenges in managing information security risks. These can include a lack of resources, evolving threat landscapes, and the complexity of integrating security measures into app development processes. However, overcoming these challenges is crucial for the sustainable success of any application.<\/p>\n<h2>Microsoft 365 Certification verifies information security risk management<\/h2>\n<p>To help developers and ISVs ensure their applications meet high-security standards, the Microsoft 365 Certification validates that an application has implemented necessary information security risk management controls, providing peace of mind to both developers and their customers.<\/p>\n<p>The <a href=\"https:\/\/learn.microsoft.com\/microsoft-365-app-certification\/docs\/certification\">Microsoft 365 Certification<\/a> is a comprehensive program that assesses an application\u2019s security, compliance, and data protection measures. Achieving this certification signifies that an application adheres to best practices in information security risk management.<\/p>\n<p>Auditors will verify that a ratified, formal information security risk management policy\/process is recorded and implemented. They will also ensure that a formal company-wide information security risk assessment is conducted at least annually and\/or a targeted risk analysis is performed during system changes, incidents, vulnerability discoveries, infrastructure changes, etc. This evaluation should cover all organizational assets, processes, and data to identify and assess potential vulnerabilities and threats.<\/p>\n<p>For the targeted risk analysis, auditors stress the importance of conducting risk analysis on specific scenarios with a narrower focus, such as an asset, threat, system, or control. The goal is to ensure that organizations continuously evaluate and identify risks arising from deviations from security best practices or system design limitations.<\/p>\n<h2>Next steps<\/h2>\n<p>To learn more on how Microsoft 365 Certification validates information security risk management controls are in place for your application, review the <a href=\"https:\/\/learn.microsoft.com\/microsoft-365-app-certification\/docs\/seg2_ops#information-security-risk-management\">sample evidence requirements<\/a>.<\/p>\n<p>To start certification, go to the Microsoft Partner Center <a href=\"https:\/\/partner.microsoft.com\/dashboard\/home\">dashboard<\/a>, select an app from <strong>Marketplace offers<\/strong> overview, and select <strong>App Compliance<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Read how Microsoft 365 Certification verifies information security risk management.<\/p>\n","protected":false},"author":129704,"featured_media":23189,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[30,202],"class_list":["post-23179","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-365-developer","tag-microsoft-365-certification","tag-security"],"acf":[],"blog_post_summary":"<p>Read how Microsoft 365 Certification verifies information security risk management.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/23179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/users\/129704"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/comments?post=23179"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/23179\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media\/23189"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media?parent=23179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/categories?post=23179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/tags?post=23179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}