Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Hard
A Microsoft 365 customer wants to verify that Microsoft handles their data in a manner consistent with industry-standard security and compliance frameworks, such as ISO 27001. Which aspect of Microsoft's Trust Center and privacy principles should they review to find evidence of these certifications?
- AData Protection Addendum (DPA)
- BAudited Controls and Certifications
- CMicrosoft's Privacy Statement
- DService Level Agreements (SLAs)
Show answer & explanationAnswer & explanation
Correct answer: B. Audited Controls and Certifications
Microsoft's Trust Center provides detailed information on Audited Controls and Certifications, demonstrating their adherence to various international and industry-specific compliance standards and regulations, including ISO 27001, through third-party audits.
Why the other options are wrong
- A. The DPA is a contractual agreement on data processing, not a list of certifications.
- C. The Privacy Statement outlines how Microsoft collects and uses data, but doesn't detail specific security certifications.
- D. SLAs define uptime and performance guarantees, not security certifications.
Microsoft Trust Center - Certifications
A resource provided by Microsoft that details their adherence to various international and industry-specific compliance standards and regulations through independent third-party audits and certifications.
- Provides documentation for ISO 27001, SOC, HIPAA, etc.
- Demonstrates Microsoft's commitment to security and compliance.
- Helps customers meet their own regulatory obligations.
Memory trick: Trust the Center for Proof and Policies.