{"id":1562,"date":"2018-08-01T01:00:00","date_gmt":"2018-08-01T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/service-trust-portal\/"},"modified":"2018-08-01T01:00:00","modified_gmt":"2018-08-01T01:00:00","slug":"service-trust-portal","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/secure-workplace\/service-trust-portal\/","title":{"rendered":"Service Trust Portal"},"content":{"rendered":"<p style=\"text-align: justify;\">It seems that every year a new piece of major legislation passes that causes businesses to stop and really think about the way they address compliance. Many small and mid-sized organisations don\u2019t have the resources to either employ dedicated staffing departments to track and audit legislative compliance or outsource their compliance requirements to specialist organisations.<\/p>\n<p style=\"text-align: justify;\">If that\u2019s the case for you, Microsoft may be able to help.\u00a0 The<span>\u00a0<\/span><a rel=\"noopener noreferrer nofollow\" href=\"https:\/\/servicetrust.microsoft.com\/\" target=\"_blank\">Microsoft Service Trust Portal<\/a><span>\u00a0<\/span>(STP) provides a variety of content, tools and other resources about Microsoft security, privacy and compliance practices. Along with that, they provide information on how their online services can help organisations maintain and track compliance with various standards, laws, and regulations. While the STP is a free resource, access to the really cool stuff (cool for compliance nerds anyway!) requires a Microsoft Cloud Services account in the form of a paid subscription to Office 365 or a free Microsoft account.<\/p>\n<p style=\"text-align: justify;\">Detailing the amount of information available in the STP is beyond the scope of this blog, but I did want to highlight the Compliance Manager component. Compliance Manager is a workflow-based risk assessment tool designed to help you manage regulatory compliance within what Microsoft describes as their \u201cshared responsibility model\u201d for cloud services. This model highlights the fact that there are commitments that Microsoft makes, and that there are responsibilities you have has the cloud service administrator.<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>COMPLIANCE MANAGER<\/span><\/h3>\n<p style=\"text-align: justify;\">The Compliance Manager dashboard provides a Compliance Score and a summary of your data protection and compliance posture as measured against various standards and data protection regulations. It includes recommended actions to improve data protection and compliance for your organisation and allows you to capture all your compliance processes and artefacts in a single location.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 839px; height: 517px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/stp_img_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/1c499c0ba29f424b8e72b6da0caecae1\" \/><\/p>\n<p style=\"text-align: justify;\">Figure 1 \u2013 Compliance Manager Dashboard Source: Microsoft<\/p>\n<p style=\"text-align: justify;\">Compliance Manager uses Assessments and Compliance Scores as the basis for managing your compliance activities. Assessments apply to one of the Microsoft cloud services and either a standard (ie ISO-27001-2013) or a regulation (ie GDPR).<\/p>\n<p style=\"text-align: justify;\">When you first login to Compliance Manger, the ISO 27001:2013, ISO 27018:2014 and GDPR for the Azure cloud service and ISO 27001:2013, NIST 800-53, and GDPR for the Office 365 cloud service Assessments are automatically added. At the time of writing, the cloud services available are Azure, Office 365, Dynamics and Professional Services.<\/p>\n<p style=\"text-align: justify;\">Compliance Score within Compliance Manager helps you to figure out what actions you can take to improve your organisation\u2019s compliance posture. It is a risk-based score that is calculated on Assessment activity. It looks at whether each assessed control is Preventive, Detective, or Corrective and whether it is Mandatory or Discretionary. It also considers the impact of control failure on the confidentiality, integrity, and availability of data, and factors in the legal and regulatory risks arising from control failure.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 833px; height: 510px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/stp_img_2.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/cb8c37a125bb4a94965bee48dbbc9284\" \/><\/p>\n<p style=\"text-align: justify;\">Figure 2 \u2013 Compliance Manager Compliance Score Source: Microsoft<\/p>\n<p style=\"text-align: justify;\">Each Assessment provides information on the Microsoft Cloud Service and standard\/regulation that is covered and is divided into Microsoft Managed Actions and Customer Managed Actions.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 815px; height: 499px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/stp_img_3.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/0734fb6c77a645eeb6369e1c1efab0df\" \/><\/p>\n<p style=\"text-align: justify;\">Figure 3 \u2013 Compliance Manager Assessments Source: Microsoft<\/p>\n<p style=\"text-align: justify;\">The Microsoft Managed Controls section of the Assessment provides details on each of the controls assessed, how Microsoft implemented and tested the control, and when and who assessed compliance.<\/p>\n<p style=\"text-align: justify;\">While that information is important for businesses, it\u2019s the Customer Managed Controls section that offers real value for organisations. This section provides you with recommended actions that your organisation can take along with tools to facilitate data protection and compliance management. Each family of controls includes control IDs, titles and descriptions, and the Compliance Score for the control. Each control also includes workflow, tracking, and evidence gathering features that enable you to:<\/p>\n<ul>\n<li>Assign implementation or verification tasks to individuals within your organisation;<\/li>\n<li>Enter implementation details, test plan information, test details, implementation, and test dates, and test results;<\/li>\n<li>Upload evidence to verify compliance activities and control implementations.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Each activity performed in an Assessment increases your organisations overall Compliance Score. Once completed, the Assessment results are reflected on the Assessment Dashboard, along with a final Compliance Score for the Assessment.<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>ALL GOOD, BUT A COUPLE OF GOTCHAS\u2026<\/span><\/h3>\n<p style=\"text-align: justify;\">There are a few things that you need to be aware of before you start.<\/p>\n<p style=\"text-align: justify;\">Firstly, by default, all users have access to the data entered and uploaded into the Compliance Manager. If this is not appropriate for your organisation you can assign appropriate roles to your users via the Admin tab.<\/p>\n<p style=\"text-align: justify;\">Secondly, any data entered or uploaded into the Compliance Manager is stored in the United States on Tier C Microsoft Cloud Storage (for details on Microsoft\u2019s Tier C compliance commitments, see<span>\u00a0<\/span><a rel=\"noopener noreferrer nofollow\" href=\"https:\/\/aka.ms\/complianceframework\/download\" target=\"_blank\">this\u00a0<\/a>document).<\/p>\n<p>Finally, it\u2019s important you take note of Microsoft\u2019s disclaimer that following the recommendations is not necessarily a guarantee of compliance, and you should seek legal advice if needed.<\/p>\n<p><img decoding=\"async\" style=\"width: 804px; height: 230px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/stp_img_4.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/0b78913f33fe4366aed5898754122048\" \/><\/p>\n<p style=\"text-align: justify;\">Figure 4- Compliance Manager Disclaimer Source: Provided<\/p>\n<p style=\"text-align: justify;\">If you are drinking from the firehose that is your compliance responsibilities, why not take a break and check out the Microsoft Secure Trust Portal and Compliance Manager. Of course, don\u2019t hesitate to reach out if you need further assistance.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It seems that every year a new piece of major legislation passes that causes businesses to stop and really think about the way they address compliance. Many small and mid-sized organisations don\u2019t have the resources to either employ dedicated staffing departments to track and audit legislative compliance or outsource their compliance requirements to specialist organisations.&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/secure-workplace\/service-trust-portal\/\">Continue reading <span class=\"screen-reader-text\">Service Trust Portal<\/span><\/a><\/p>\n","protected":false},"author":90,"featured_media":1563,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[20],"tags":[],"class_list":["post-1562","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1562","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/90"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=1562"}],"version-history":[{"count":0,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1562\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/1563"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=1562"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=1562"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=1562"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}