<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Global Foundation Services Blog</title><link>http://blogs.technet.com/b/gfs/</link><description /><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Offering Support to Help Victims of the Japanese Earthquake</title><link>http://blogs.technet.com/b/gfs/archive/2011/03/11/offering-support-to-help-victims-of-the-japanese-earthquake.aspx</link><pubDate>Sat, 12 Mar 2011 01:43:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3412180</guid><dc:creator>GFS1</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3412180</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2011/03/11/offering-support-to-help-victims-of-the-japanese-earthquake.aspx#comments</comments><description>&lt;p&gt;By Charlie McNerney, GM, Business Management, GFS&lt;/p&gt;
&lt;p&gt;On Friday, March 11th, 2011, a magnitude 8.9 earthquake hit Japan followed by a series of tsunamis, causing widespread damage. In response, Microsoft activated its Disaster Response protocol. We are currently accounting for all our employees and assessing all of our facilities for any impact.&lt;/p&gt;
&lt;p&gt;We are saddened by the devastation caused by the earthquake in Japan. We are reaching out to our customers and partners to conduct impact assessments, and we are providing those impacted by the earthquake with free incident support to help get their operations back up and running. There has been no disruption to our cloud based and hosted services, and we continue to monitor the situation closely. Microsoft also has a cloud-based disaster response communications portal running on Windows Azure that is available to governments and nonprofits to use for communication between agencies and with citizens.&lt;/p&gt;
&lt;p&gt;More information on Microsoft&amp;rsquo;s response to the disaster is on our Microsoft Corporate Citizenship website which will be updated with any new developments.&amp;nbsp; &lt;br /&gt;News and Resources:&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&amp;bull;&amp;nbsp;Search &lt;a target="_blank" href="http://www.bing.com/search?q=japan+earthquake&amp;amp;form=MSNXNM&amp;amp;ocid=xnetr2-3"&gt;Bing&lt;/a&gt; for the latest quake information&lt;br /&gt;&amp;bull;&amp;nbsp;Get the latest news from &lt;a target="_blank" href="http://www.msnbc.msn.com/"&gt;MSNBC&lt;/a&gt;&lt;br /&gt;&amp;bull;&amp;nbsp;&lt;a target="_blank" href="http://www.msnbc.msn.com/id/42024158/displaymode/1247/?beginSlide=1&amp;amp;gt1=43001"&gt;See&lt;/a&gt; updated images&lt;br /&gt;&amp;bull;&amp;nbsp;&lt;a target="_blank" href="http://www.bing.com/videos/search?q=japan+earthquake&amp;amp;form=QBVR&amp;amp;qs=SQ&amp;amp;sk=&amp;amp;pq=japan&amp;amp;sp=1&amp;amp;sc=8-5"&gt;Watch &lt;/a&gt;related videos&lt;br /&gt;&amp;bull;&amp;nbsp;Get breaking news on &lt;a target="_blank" href="http://twitter.com/msn"&gt;Twitter&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;//cm&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3412180" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/tsunami/">tsunami</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Japanese+Earthquake/">Japanese Earthquake</category></item><item><title>Shedding Light on Our New Cloud Farms</title><link>http://blogs.technet.com/b/gfs/archive/2011/01/04/shedding-light-on-our-new-cloud-farms.aspx</link><pubDate>Tue, 04 Jan 2011 15:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3377971</guid><dc:creator>GFS1</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3377971</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2011/01/04/shedding-light-on-our-new-cloud-farms.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-size: xx-small;"&gt;By Kevin Timmons, &lt;br /&gt;General Manager of Datacenter Services&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s an exciting time for Microsoft&amp;rsquo;s datacenter program.&amp;nbsp; In addition to operating one of the largest global datacenter footprints in the industry, we have been super busy working on multiple next-generation, modular facilities that are in various phases of construction.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;One of our most innovative new datacenters is set to open in Quincy, WA in early 2011 and incorporates key learnings from award-winning facilities that Microsoft opened last year in Chicago and Dublin.&amp;nbsp;&amp;nbsp; The &lt;a href="http://blogs.technet.com/b/msdatacenters/archive/2009/09/24/dublin-data-center-celebrates-grand-opening.aspx"&gt;Dublin facility &lt;/a&gt;uses server PODs and outside air economization to cool the servers, which significantly reduces cooling expense and infrastructure costs. We took a slightly different approach with our &lt;a href="http://blogs.technet.com/b/msdatacenters/archive/2009/09/28/microsoft-celebrates-chicago-data-center-grand-opening.aspx"&gt;Chicago datacenter &lt;/a&gt;which utilizes water-side economization for cooling and improves scalability by using IT Pre-Assembled Components (ITPACs.)&amp;nbsp;&amp;nbsp; An ITPAC is a pre-manufactured, fully-assembled module that can be built with a focus on sustainable materials such as steel and aluminum and can house as little as 400 servers and as many as 2,000 servers, significantly increasing flexibility and scalability. You can learn more about our ITPACs by going to the &lt;a href="http://www.globalfoundationservices.com/infrastructure/index.html"&gt;ITPAC video&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/300x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-75-87/6518.MS_2D00_ModularDC.JPG" border="0" /&gt;&lt;br /&gt;&lt;em&gt;&lt;a target="_blank" href="http://www.youtube.com/watch?v=ogev514yy8k&amp;amp;feature=player_detailpage"&gt;View&amp;nbsp;our Modular Datacenter slide deck&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The expansion in Quincy takes these ideas a step further by extending the flexibility of PACs across the entire facility using modular &amp;ldquo;building blocks&amp;rdquo; for electrical, mechanical, server and security subsystems.&amp;nbsp; This increase in flexibility enables us to even better support the needs of what can often be a very unpredictable online business and allows us to build datacenters incrementally as capacity grows.&amp;nbsp; Our modular design enables us to build a facility in significantly less time while reducing capital costs by an average of 50 to 60 percent over the lifetime of the project.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;When Phase 1 opens in Quincy it will be located adjacent to our existing 500,000-square-foot facility.&amp;nbsp; However, the new datacenter is radically different.&amp;nbsp; The building will actually resemble slightly more modern versions of the tractor sheds I spent so much time around during my childhood in rural Illinois.&amp;nbsp; &lt;br /&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/250x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-75-87/4863.TractorHome.jpg" border="0" /&gt;&lt;br /&gt;&lt;em&gt;Tractor shed in my home town of Mt. Pulaski, IL&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The building&amp;rsquo;s utilitarian appearance belies its many hidden innovations. The structure is virtually transparent to ambient outdoor conditions, allowing us to essentially place our servers and storage outside in the cool air while still protecting it from the elements. The interior layout is specifically designed to allow us to further innovate in the ways that we deploy equipment in future phases of the project. And, like any good barn, the protective shell serves to keep out critters and tumbleweeds. Additional phases have been planned for the Quincy site and will be built based on demand.&amp;nbsp; Those phases will incorporate even more cutting-edge methods to deploy servers and storage in ways that have never been seen before in the industry.&amp;nbsp;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We will open other modular datacenters later in 2011 in Virginia and Iowa and I&amp;rsquo;ll be sharing more information about those facilities at that time.&amp;nbsp; Our modular approach to design and construction with these facilities will allow us to substantially lower cost per megawatt to build and run our datacenters while significantly reducing time to market.&amp;nbsp;&amp;nbsp; This is the holy grail for most datacenter professionals&amp;hellip;. fast, cheap and reliable &amp;ndash; what more could you ask for?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve been sharing our research and best practices around modularity with our partners and others in the industry for a number of years and I&amp;rsquo;m thrilled to see the industry begin moving in this direction.&amp;nbsp; By sharing our learnings, we&amp;rsquo;ve helped others build more sustainable facilities and reduce our collective carbon footprint.&amp;nbsp;&amp;nbsp; &lt;br /&gt;Stay tuned for more information about our future datacenter projects in 2011.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;//Kev&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3377971" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Kevin+Timmons/">Kevin Timmons</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Chicago/">Chicago</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/containers/">containers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/PUE/">PUE</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Efficiency/">Efficiency</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Environmental+Sustainability/">Environmental Sustainability</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Gen+4-0+Data+Center/">Gen 4.0 Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft+Data+Center+Video/">Microsoft Data Center Video</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Infrastructure/">Infrastructure</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Generation+4/">Generation 4</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft+Data+Center/">Microsoft Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/energy+efficiency/">energy efficiency</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/IT+Infrastructure/">IT Infrastructure</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Modular+Data+Center/">Modular Data Center</category></item><item><title>Watt Matters in Energy Efficiency!</title><link>http://blogs.technet.com/b/gfs/archive/2010/12/13/watt-matters-in-energy-efficiency.aspx</link><pubDate>Mon, 13 Dec 2010 15:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3374108</guid><dc:creator>GFS1</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3374108</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2010/12/13/watt-matters-in-energy-efficiency.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;span lang="EN-IE" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN-IE; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;By Dileep Bhandarkar, Ph. D. &lt;br /&gt;Distinguished Engineer&lt;br /&gt;Global Foundation Services, Microsoft&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span lang="EN" style="color: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span lang="EN" style="font-family: 'Tahoma','sans-serif'; color: #0070c0; font-size: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;I recently had the privilege to deliver a keynote speech titled &amp;ldquo;Watt Matters in Datacenters&amp;rdquo; at the Server Design Summit in Santa Clara, CA on December 1, 2010. My keynote focused on energy efficiency in datacenters and the need for holistic optimization of the server hardware and datacenter infrastructure. I have covered this topic in a&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri; color: #0000ff;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;previous blog&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span style="color: #0000ff;"&gt; &lt;span style="color: #000000;"&gt;but&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;wanted to take this opportunity to discuss some of the work that we have been doing with our industry hardware partners to optimize server design for cloud computing.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;As part of our commitment to driving efficiencies in our datacenters, we have been working actively with server OEMs, microprocessor manufacturers, disk drive vendors, memory suppliers and other component suppliers to increase the efficiency of server designs. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;We share our detailed requirements, develop concept designs, and work with our partners on optimized designs that are then shared out and available to the industry at large. We firmly believe that this strong partnership approach and sharing our best practices is the best way to advance the state of the datacenter industry and meet our cloud computing needs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;img src="http://blogs.technet.com/resized-image.ashx/__size/450x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-75-87/6138.Performance_2D00_Watt.jpg" border="0" /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;I also presented some opportunities that server designers should consider to further optimize for cloud computing including:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Better Alignment with Datacenter Technologies&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;480V 3 phase power supplies at rack level&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;In rack UPS instead of current central UPS&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Rightsizing of platforms for major workloads&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Low Power DIMMs and Processors&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Tiny CPU cores &amp;ndash; Atom? Bobcat? ARM?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;System on a Chip for lower platform power&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Dynamic Power Capping&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Designs for higher temperature operation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Rack level power and cooling&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Enhanced support of virtualization&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;After the holidays, I will discuss these topics in greater detail in an upcoming white paper. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;I witnessed a huge amount of interest in what I shared at the Server Design Summit and have made my presentation &lt;/span&gt;&lt;/span&gt;&lt;a target="_blank" href="http://69.20.67.221/ms/infrastructure/documents/ServerDesignSummitKeynote.pdf"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;available here&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;o:p&gt;&lt;/o:p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Wishing you and yours a very happy holiday season!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;- Dileep &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #333333; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&lt;br /&gt;Find more information on our datacenter strategies on GFS&amp;rsquo; web site at &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.globalfoundationservices.com/"&gt;&lt;span style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;www.globalfoundationservices.com&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #333333; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: verdana,geneva;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3374108" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Chicago/">Chicago</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/containers/">containers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/PUE/">PUE</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Efficiency/">Efficiency</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Environmental+Sustainability/">Environmental Sustainability</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Gen+4-0+Data+Center/">Gen 4.0 Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft+Data+Center+Video/">Microsoft Data Center Video</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Infrastructure/">Infrastructure</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Generation+4/">Generation 4</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Dileep+Bhandarkar/">Dileep Bhandarkar</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft+Data+Center/">Microsoft Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/energy+efficiency/">energy efficiency</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/IT+Infrastructure/">IT Infrastructure</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Modular+Data+Center/">Modular Data Center</category></item><item><title>Microsoft’s Cloud Infrastructure Receives FISMA Approval</title><link>http://blogs.technet.com/b/gfs/archive/2010/12/02/microsoft-s-cloud-infrastructure-receives-fisma-approval.aspx</link><pubDate>Thu, 02 Dec 2010 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3372497</guid><dc:creator>GFS1</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3372497</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2010/12/02/microsoft-s-cloud-infrastructure-receives-fisma-approval.aspx#comments</comments><description>&lt;p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"&gt;By &lt;/span&gt;&lt;span style="font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Mark Estberg, Senior Director of Risk and Compliance,&lt;/span&gt;&lt;span style="color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"&gt; &lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"&gt;Global Foundation Services&lt;/span&gt;&lt;span style="color: #1f497d; font-size: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;Although cloud computing has emerged as a hot topic only in the past few years, Microsoft has been running some of the largest and most reliable online services in the world for over 16 years. Our cloud infrastructure supports more than 200 cloud services, 1 billion customers, and 20 million businesses in over 76 markets worldwide. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;
&lt;p&gt;
&lt;p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Today, I am pleased to announce that Microsoft&amp;rsquo;s cloud infrastructure has achieved another milestone in receiving its Federal Information Security Management Act of 2002 (FISMA) Authorization to Operate (ATO).&amp;nbsp; Meeting the requirements of FISMA is an important security requirement for US Federal agencies.&amp;nbsp;The ATO was issued to Microsoft&amp;rsquo;s Global Foundation Services organization.&amp;nbsp;It covers Microsoft&amp;rsquo;s cloud infrastructure that provides a trustworthy foundation for the company&amp;rsquo;s cloud services, including&amp;nbsp;Exchange Online and SharePoint Online, which are currently in the FISMA certification and accreditation process.&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This ATO represents the government&amp;rsquo;s reliance on our security processes and covers Microsoft&amp;rsquo;s General Support System and follows &lt;/span&gt;&lt;/span&gt;&lt;a href="http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final.pdf"&gt;&lt;span style="color: #0000ff; font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;NIST Special Publication 800-53 Revision 3&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt; &amp;ldquo;Recommended Security Controls for Federal Information Systems and Organizations.&amp;rdquo;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Government organizations require specialized compliance and regulatory processes. Operating under FISMA requires transparency and frequent security reporting to our US Federal customers. And we are applying these specialized processes across our infrastructure to even further enhance our Online Services Security &amp;amp; Compliance program. The company &lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;has been designing and testing our cloud applications and infrastructure for over a decade to continually address emerging, internationally-recognized standards. We are focused on excelling in demonstrating our capabilities and compliance with these laws and with our stringent internal security and privacy policies.&amp;nbsp; As a result, all our customers can benefit from highly-focused testing and monitoring, automated patch delivery, cost-saving economies of scale, and ongoing security improvements.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-no-proof: yes"&gt;&lt;span style="mso-spacerun: yes"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;img height="221" width="341" src="http://blogs.technet.com/resized-image.ashx/__size/300x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-75-87/8182.CHI_2D00_DC.jpg" style="border: 0px;" /&gt;&amp;nbsp;&amp;nbsp;&lt;img height="222" width="344" src="http://blogs.technet.com/resized-image.ashx/__size/300x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-75-87/8032.CHI_2D00_DC2.jpg" style="border: 0px;" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;i style="mso-bidi-font-style: normal"&gt;&lt;span style="FONT-SIZE: 9pt"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;Microsoft&amp;rsquo;s Chicago datacenter (a FISMA-approved facility), provides over 17 football fields worth of cloud computing capacity.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;&lt;span style="FONT-SIZE: 9pt"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;&lt;span style="FONT-SIZE: 9pt"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;&lt;span style="FONT-SIZE: 9pt"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #000000;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #000000;"&gt;The company opened its first datacenter in September 1989 and today its globally-distributed, high-availability datacenters are managed by our Global Foundation Services (GFS) group. GFS&amp;rsquo;s Online Services Security &amp;amp; Compliance team has built upon the company&amp;rsquo;s existing capabilities, including being &lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN;"&gt;one of the first major online service providers to achieve&lt;/span&gt; our ISO/IEC 27001:2005 certification and SAS 70 Type II attestation, which also met the FISMA requirements.&amp;nbsp; &lt;span lang="EN" style="mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN;"&gt;We have also gone beyond the ISO standard, which includes some 150 security controls and developed over 300 security controls to account for the unique challenges of the cloud infrastructure and what it takes to mitigate some of the risks involved. &lt;/span&gt;The additional rigorous testing and continuous monitoring required by FISMA have already been incorporated into our overall information security program, which is described in several white papers located our Global Foundation Services &lt;/span&gt;&lt;span style="color: #0000ff;"&gt;&lt;a target="_blank" href="http://www.globalfoundationservices.com"&gt;web site&lt;/a&gt;&lt;/span&gt;.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;More information about FISMA is available at the National Institute of Standards and Technology &lt;span style="color: #0000ff;"&gt;&lt;a target="_blank" href="http://csrc.nist.gov/groups/SMA/fisma/index.html"&gt;web site&lt;/a&gt;&lt;/span&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;
&lt;/p&gt;
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3372497" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/BPOS/">BPOS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/SAS+70/">SAS 70</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/ISO+27001/">ISO 27001</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Chicago+data+center/">Chicago data center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance+framework/">compliance framework</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+security/">cloud security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance+framew/">compliance framew</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Efficiency/">Efficiency</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Servers/">Servers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Datacenter/">Datacenter</category></item><item><title>Information Security Management System for Microsoft Cloud Infrastructure</title><link>http://blogs.technet.com/b/gfs/archive/2010/11/12/information-security-management-system-for-microsoft-cloud-infrastructure.aspx</link><pubDate>Fri, 12 Nov 2010 18:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3368057</guid><dc:creator>GFS1</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3368057</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2010/11/12/information-security-management-system-for-microsoft-cloud-infrastructure.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;By Mark Estberg, Senior Director of Risk and Compliance, Global Foundation Services&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;I often hear questions that are variations of &amp;ldquo;How does Microsoft secure its cloud?&amp;rdquo; and &amp;ldquo;How does Microsoft manage compliance in the cloud?&amp;rdquo;&amp;nbsp; The answer is similar to how any enterprise operates a comprehensive security program and is based on our information security program described in a white paper titled &amp;ldquo;&lt;a target="_blank" href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" title="Securing Microsoft's Cloud Infrastructure"&gt;Securing Microsoft's Cloud Infrastructure&lt;/a&gt;.&amp;rdquo;&amp;nbsp; The paper describes a framework that includes risk based decision making, defense in depth and a compliance framework.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN" style="color: #333333; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;
&lt;p class="MsoNormal"&gt;&lt;br /&gt;How we operate that program is as important as the instructions in a recipe.&amp;nbsp; Ingredients alone &amp;ndash; such as 1 egg, &amp;frac12; teaspoon salt, 1 cup of flour and 2 tablespoons of water &amp;ndash; are not enough information to make pasta without additional instructions.&amp;nbsp; For Microsoft&amp;rsquo;s cloud infrastructure, you can think of the control framework we describe in &amp;ldquo;&lt;a href="http://www.globalfoundationservices.com/documents/MicrosoftComplianceFramework1009.pdf" title="Microsoft Compliance Framework for Online Services"&gt;Microsoft&amp;rsquo;s Compliance Framework for Online Services&lt;/a&gt;&amp;rdquo; and security controls that are part of our defense in depth capabilities as &amp;ldquo;ingredients.&amp;rdquo;&amp;nbsp; How we operate the program &amp;ndash; the Information Security Management System &amp;ndash; can be thought of as the &amp;ldquo;recipe,&amp;rdquo; or instructions.&amp;nbsp; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;br /&gt;The Information Security Management System &amp;ndash; the &amp;ldquo;recipe&amp;rdquo; &amp;ndash; is described in a paper that we are releasing today called &amp;ldquo;&lt;a target="_blank" href="http://globalfoundationservices.com/security/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf" title="Information Security Management System for Microsoft Cloud Infrastructure"&gt;Information Security Management System for Microsoft Cloud Infrastructure&lt;/a&gt;.&amp;rdquo;&amp;nbsp;&amp;nbsp; This paper is another step in our effort to share how Microsoft approaches cloud security and which, I believe will promote the continuation of an important industry discussion on cloud security.&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3368057" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance+framework/">compliance framework</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+security/">cloud security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Mark+Estberg/">Mark Estberg</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Datacenter/">Datacenter</category></item><item><title>Security Best Practices for Developing Windows Azure Applications</title><link>http://blogs.technet.com/b/gfs/archive/2010/06/11/security-best-practices-for-developing-windows-azure-applications.aspx</link><pubDate>Fri, 11 Jun 2010 16:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3337646</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3337646</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2010/06/11/security-best-practices-for-developing-windows-azure-applications.aspx#comments</comments><description>&lt;p&gt;&lt;em&gt;By Mark Estberg, Senior Director of Risk and Compliance, Global Foundation Services&lt;/em&gt;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Security challenges exist in the cloud and applications must take these challenges into account.&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;Our team recently collaborated with other security experts to publish a white paper which describes these challenges and recommend approaches to design and develop more secure applications for Microsoft&amp;rsquo;s Windows Azure platform. The Windows Azure provides Platform as a Service capabilities that give developers flexibility and access to highly scalable compute and storage.&amp;nbsp; &lt;br /&gt;&amp;nbsp;&lt;br /&gt;I would like to thank Microsoft&amp;rsquo;s Security Engineering Center and Online Services Security and Compliance teams that worked to provide this paper which builds on the security principles that the company has developed through years of experience managing security risks in traditional development and our large scale operating environment. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;We hope that by sharing our best practices that we can help others in the industry provide a more secure cloud computing experience and develop common standards for those practices to benefit customers globally. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;The paper can be found via this &lt;a href="http://download.microsoft.com/download/7/3/E/73E4EE93-559F-4D0F-A6FC-7FEC5F1542D1/SecurityBestPracticesWindowsAzureApps.docx"&gt;link&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3337646" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Mark+Estberg/">Mark Estberg</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Azure/">Azure</category></item><item><title>Rightsizing Servers to Achieve Cost and Power Savings </title><link>http://blogs.technet.com/b/gfs/archive/2009/12/16/rightsizing-servers-to-achieve-cost-and-power-savings.aspx</link><pubDate>Wed, 16 Dec 2009 19:18:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3301026</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3301026</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/12/16/rightsizing-servers-to-achieve-cost-and-power-savings.aspx#comments</comments><description>&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;For Production Datacenters - White paper published &amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;This week our team published a new white paper on “Rightsizing Servers to Achieve Cost and Power Savings,” written by Dileep Bhandarkar and Kushagra Vaid, distinguished engineer and principal hardware architect in our Global Foundation Services (GFS) datacenter team.&amp;nbsp;The paper offers best practices on how GFS is lowering its total cost of ownership (of its servers) and achieving power savings for the company’s production datacenters. The paper can be found on GFS’ web site at &lt;A href="http://www.globalfoundationservices.com/" mce_href="http://www.globalfoundationservices.com/"&gt;&lt;FONT color=#0000ff&gt;www.globalfoundationservices.com&lt;/FONT&gt;&lt;/A&gt; on the Infrastructure page &lt;A href="http://www.globalfoundationservices.com/infrastructure/index.html" mce_href="http://www.globalfoundationservices.com/infrastructure/index.html"&gt;&lt;FONT color=#0000ff&gt;here&lt;/FONT&gt;&lt;/A&gt; and is discussed in Dileep’s &lt;A href="http://blogs.technet.com/msdatacenters/default.aspx" mce_href="http://blogs.technet.com/msdatacenters/default.aspx"&gt;&lt;FONT color=#0000ff&gt;blog post&lt;/FONT&gt;&lt;/A&gt;&lt;SPAN style="COLOR: blue"&gt; &lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;under the same title. More information is posted on Microsoft’s &lt;/SPAN&gt;Environmental Sustainability blog &lt;A href="http://blogs.msdn.com/see/archive/2009/12/15/rightsizing-servers-to-achieve-cost-and-power-savings-in-the-datacenter.aspx" mce_href="http://blogs.msdn.com/see/archive/2009/12/15/rightsizing-servers-to-achieve-cost-and-power-savings-in-the-datacenter.aspx"&gt;&lt;FONT color=#0000ff&gt;post&lt;/FONT&gt;&lt;/A&gt;&lt;U&gt;&lt;SPAN style="COLOR: #1a0ff9"&gt;&lt;FONT color=#0000ff&gt;.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="COLOR: #1f497d"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Today more than ever, IT departments need to make sure that the servers they deploy are as efficient as possible in terms of acquisition cost and energy consumption. This paper describes how GFS, the team that manages and operates the company’s vast production datacenters, rightsizes its servers to achieve maximum efficiency. The paper details the processes used for collecting detailed performance data using representative workloads, and then analyzing that dataset to select balanced servers that are optimally sized for “production scenarios”. &amp;nbsp;By sharing these best practices, Microsoft hopes to help other industry IT departments stretch their purchasing budgets significantly to help achieve organizational goals even in times of constraint.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;/gfs&lt;/P&gt;&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3301026" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/PUE/">PUE</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Efficiency/">Efficiency</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Servers/">Servers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Green+IT/">Green IT</category></item><item><title>Continuing to Share Best Practices on Security and Privacy for the Cloud </title><link>http://blogs.technet.com/b/gfs/archive/2009/11/16/continuing-to-share-best-practices-on-security-and-privacy-for-the-cloud.aspx</link><pubDate>Mon, 16 Nov 2009 18:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3294169</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3294169</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/11/16/continuing-to-share-best-practices-on-security-and-privacy-for-the-cloud.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;&lt;FONT face=Calibri&gt;By Mark Estberg, Senior Director of Risk and Compliance,&lt;SPAN style="COLOR: black"&gt; &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;Global Foundation Services&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 42pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; COLOR: #1f497d; FONT-FAMILY: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=normal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN class=normalchar&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Microsoft has released several papers over the last couple of months on how we secure the cloud infrastructure, manage online service security, and how we developed and manage our compliance framework. Together, these papers describe some of the factors that are necessary to deliver a trustworthy cloud environment.&amp;nbsp; Recently, another paper was released describing how we address&amp;nbsp;potential security vulnerabilities during the development of “client and cloud” applications by using a methodical Security Development Lifecycle (SDL) process.&amp;nbsp; This paper provides insight both in how Microsoft applies&amp;nbsp;SDL to services that we offer in the cloud as well as guidance on how these same concepts can be applied by anyone developing their own cloud applications on platforms, including Windows Azure.&amp;nbsp; This paper called “Security Considerations for Client and Cloud Applications” is available at &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://www.microsoft.com/sdl"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/sdl&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=normal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=normal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&amp;nbsp;&lt;SPAN class=normalchar&gt;Additionally, the paper illustrates how services at the Software as a Service (SaaS) and Platform as a Service (PaaS) cloud layers rely on capabilities at the Infrastructure as a Service layer (IaaS).&amp;nbsp; The two other papers, “Securing Microsoft's Cloud Infrastructure” and “Microsoft’s Compliance Framework for Online Services,” go into more detail about security at the&amp;nbsp;IaaS layer and how this extends up the stack to&amp;nbsp;SaaS and PaaS.&amp;nbsp; These papers are available at &lt;/SPAN&gt;&lt;A href="http://www.globalfoundationservices.com/security" target=_blank&gt;&lt;SPAN class=hyperlinkchar&gt;&lt;SPAN style="COLOR: windowtext"&gt;&lt;FONT color=#0000cc&gt;www.globalfoundationservices.com/security&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class=normalchar&gt;.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=normal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=normal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN class=normalchar&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Microsoft will continue to release papers revealing our online, live and cloud security best practices in an effort to provide insight into the key learnings we are gaining from providing online services to customers 24x7x365 since 1994. We hope such sharing will help to advance an industry dialogue that will benefit the entire cloud ecosystem and our customers.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3294169" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/ISO+27001/">ISO 27001</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance+framework/">compliance framework</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+security/">cloud security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Mark+Estberg/">Mark Estberg</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance+framew/">compliance framew</category></item><item><title>Introducing the Microsoft Compliance Framework for Online Services</title><link>http://blogs.technet.com/b/gfs/archive/2009/10/25/introducing-the-microsoft-compliance-framework-for-online-services.aspx</link><pubDate>Mon, 26 Oct 2009 05:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3288876</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;By &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Mark Estberg, Senior Director of Risk and Compliance,&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt; &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;Global Foundation Services&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; COLOR: #1f497d; FONT-FAMILY: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Sometimes it can seem like half the battle of securing online services involves satisfying audits and otherwise demonstrating that you are complying with industry and government regulations. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Just like any online service provider, Microsoft is subject to a large number of regulations, statutes and industry requirements.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Our service delivery and operations teams found themselves spending increasing amounts of time responding to a variety of audits that often asked for the same types of information repeatedly over the course of a year.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In addition, compliance obligations are increasing and becoming more complex as Microsoft moves into new markets and businesses and also as regulations and industry standards change.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;IMG title="Industry Standards and Regulations" style="WIDTH: 422px; HEIGHT: 212px" height=169 alt="Industry Standards and Regulations" hspace=3 src="http://blogs.technet.com/photos/gfs/images/3288891/500x169.aspx" width=500 align=left vspace=3 border=0 mce_src="http://blogs.technet.com/photos/gfs/images/3288891/500x169.aspx"&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;We are often asked how we have built and then operate our framework, so today we are releasing a&amp;nbsp;&lt;/FONT&gt;&lt;A href="http://www.globalfoundationservices.com/documents/MicrosoftComplianceFramework1009.pdf"&gt;&lt;FONT size=3&gt;white paper&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;&lt;FONT size=3&gt;to share our approach.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The white paper includes our approach, processes, and reference tables.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=Default style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: windowtext"&gt;&lt;FONT face=Calibri&gt;To put our approach to this problem in context, it’s important to have some background about Microsoft’s online environment. My group is part of the Global Foundation Services (GFS) division within Microsoft.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;GFS provides the cloud infrastructure for over 200 Microsoft services ranging from familiar consumer-oriented services such as Windows Live Hotmail and Bing to business-oriented services such as Microsoft Dynamics CRM Online and Microsoft Business Productivity Online Standard Suite from Microsoft Online Services. This environment also includes the Windows Azure platform which is used to host online services built by third parties.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Default style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: windowtext"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;We developed a compliance framework for online services to better manage our obligations in this large environment and to minimize the impact to our operations teams.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The compliance framework is a set of processes and documentation that we put together that are based on the ISO 27001 security standard.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We use this framework to manage a large variety of obligations which include the Payment Card Industry Data Security Standard, Sarbanes-Oxley requirements and obligations imposed by the Health Insurance Portability and Accountability Act.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These are in addition to our own business and customer driven security requirements.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;There are two major components of the framework.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The first is a control set (often referred to as a controls framework) that maps our obligations to a single set of controls rather than independent requirements.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The second component is the compliance process and predictable audit schedule that minimize disruptions to our teams and reduce the number and impact of audits.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This framework results in third party validation and certifications which allow us to clearly communicate our capabilities to our customers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For example, Global Foundation Services is ISO 27001 certified and we also have Statement of Auditing Standard 70 Type I and Type II attestations.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This structure is represented in the following illustration:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;IMG title="Framework Methodology" style="WIDTH: 449px; HEIGHT: 400px" height=342 alt="Framework Methodology" hspace=3 src="http://blogs.technet.com/photos/gfs/images/3288893/original.aspx" width=391 align=left vspace=3 border=0 mce_src="http://blogs.technet.com/photos/gfs/images/3288893/original.aspx"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How we manage our processes is critical to the success of our compliance program.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We have based our compliance framework processes on the “Plan, Do, Check, Act” steps found in ISO 27001.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We execute this process on a regular rhythm and also when our environment changes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;
&lt;P class=Default style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: windowtext"&gt;Microsoft’s compliance framework for online services provides confidence that we are meeting our obligations, minimizes audit disruption to our teams and allows us to communicate our capabilities through third party verification.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;A standard does not exist for cloud security and this is a challenge for all online service providers and customers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We are sharing our approach to contribute to an industry dialogue.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Our hope is that by sharing best practices with industry counterparts we can improve together and customers can benefit.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Default style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: windowtext"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A class="" title=_Toc239238092 name=_Toc239238092&gt;&lt;/A&gt;&lt;SPAN style="mso-bookmark: _Toc239238092"&gt;This &lt;A href="http://www.globalfoundationservices.com/documents/MicrosoftComplianceFramework1009.pdf"&gt;white paper&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="mso-bookmark: _Toc239238092"&gt;is one of a series that introduces the OSSC team’s strategic approach to cloud security. For more about how OSSC manages security risks to the cloud infrastructure, read the &lt;/SPAN&gt;&lt;A href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" target=_blank mce_href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf"&gt;&lt;SPAN style="mso-bookmark: _Toc239238092"&gt;Securing Microsoft’s Cloud Infrastructure&lt;/SPAN&gt;&lt;SPAN style="mso-bookmark: _Toc239238092"&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bookmark: _Toc239238092"&gt; white paper.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Head2 style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="mso-bookmark: _Toc239238092"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: windowtext; LINE-HEIGHT: 115%"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt" mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3288876" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Pete+Boden/">Pete Boden</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/SAS+70/">SAS 70</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/ISO+27001/">ISO 27001</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance+framework/">compliance framework</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+security/">cloud security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Mark+Estberg/">Mark Estberg</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Center/">Data Center</category></item><item><title>Microsoft Celebrates Chicago Data Center Grand Opening</title><link>http://blogs.technet.com/b/gfs/archive/2009/09/30/microsoft-celebrates-chicago-data-center-grand-opening.aspx</link><pubDate>Wed, 30 Sep 2009 16:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3284071</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3284071</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/09/30/microsoft-celebrates-chicago-data-center-grand-opening.aspx#comments</comments><description>&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-bidi-font-family: Tahoma; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Microsoft’s cloud computing infrastructure takes another big step forward this week with the grand opening of our Chicago data center. At more than 700,000 square feet, this facility significantly expands our ability &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;to &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-bidi-font-family: Tahoma; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;meet the demand generated from our Live, Online, and Cloud Computing services offerings for our customers. To find out more &lt;A href="http://blogs.technet.com/msdatacenters/archive/2009/09.aspx" target=_blank mce_href="http://blogs.technet.com/msdatacenters/archive/2009/09.aspx"&gt;&lt;FONT color=#09528d&gt;read today's posting&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;&lt;FONT size=3&gt;on our Microsoft Data Centers blog&lt;/FONT&gt;.&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3284071" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Chicago+data+center/">Chicago data center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Chicago/">Chicago</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Arne+Josefsberg/">Arne Josefsberg</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/containers/">containers</category></item><item><title>Dublin Data Center Celebrates Grand Opening</title><link>http://blogs.technet.com/b/gfs/archive/2009/09/24/dublin-data-center-celebrates-grand-opening.aspx</link><pubDate>Fri, 25 Sep 2009 01:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3283077</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3283077</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/09/24/dublin-data-center-celebrates-grand-opening.aspx#comments</comments><description>&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: black; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-themecolor: text1"&gt;This is a big week for Microsoft’s online, live, and cloud services as we celebrate the grand opening of our new data center in Dublin, Ireland. The Dublin facility delivers two key advances for Microsoft’s Software plus Services initiatives. &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: black; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA" lang=EN&gt;One is expanded support for all our customers in the Europe, Middle East, and Africa region, thanks to Microsoft’s first mega data center built outside of the U.S&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: black; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-themecolor: text1"&gt;.&amp;nbsp; The other is dramatically improved environmental sustainability, resulting from innovative technology that takes advantage of the naturally cool climate in Ireland. To find out more &lt;A href="http://blogs.technet.com/msdatacenters/archive/2009/09/24/dublin-data-center-celebrates-grand-opening.aspx" target=_blank mce_href="http://blogs.technet.com/msdatacenters/archive/2009/09/24/dublin-data-center-celebrates-grand-opening.aspx"&gt;read today's posting&lt;/A&gt;&amp;nbsp;&lt;FONT size=3&gt;on our Microsoft Data Centers blog&lt;/FONT&gt;.&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3283077" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Dublin+data+center/">Dublin data center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Arne+Josefsberg/">Arne Josefsberg</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/air_2D00_side+economization/">air-side economization</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/PUE/">PUE</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Dublin/">Dublin</category></item><item><title>Microsoft Brings Two More Mega Data Centers Online in July</title><link>http://blogs.technet.com/b/gfs/archive/2009/06/29/microsoft-brings-two-more-mega-data-centers-online-in-july.aspx</link><pubDate>Mon, 29 Jun 2009 19:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3259688</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3259688</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/06/29/microsoft-brings-two-more-mega-data-centers-online-in-july.aspx#comments</comments><description>&lt;FONT face=Calibri&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;July marks the launch of our two newest mega data centers in Chicago and Dublin. Our Dublin facility will go live on July 1, followed by our Chicago facility on July 20 to support our growing Online, Live, and Cloud services.&amp;nbsp;Together these Generation 3 facilities demonstrate Microsoft’s continuing commitment to improving data center efficiency with a focus on environmental sustainability. To find out more &lt;A class="" title="read today's posting" href="http://blogs.technet.com/msdatacenters/archive/2009/06/29/microsoft-brings-two-more-mega-data-centers-online-in-july.aspx" target=_blank mce_href="http://blogs.technet.com/msdatacenters/archive/2009/06/29/microsoft-brings-two-more-mega-data-centers-online-in-july.aspx"&gt;read today's posting&lt;/A&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;on our Microsoft Data Centers blog.&lt;SPAN style="mso-bidi-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3259688" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Dublin+data+center/">Dublin data center</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Chicago+data+center/">Chicago data center</category></item><item><title>Microsoft’s Infrastructure Services Team Welcomes Kevin Timmons</title><link>http://blogs.technet.com/b/gfs/archive/2009/06/22/microsoft-s-infrastructure-services-team-welcomes-kevin-timmons.aspx</link><pubDate>Mon, 22 Jun 2009 20:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3257508</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3257508</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/06/22/microsoft-s-infrastructure-services-team-welcomes-kevin-timmons.aspx#comments</comments><description>&lt;FONT face=Calibri size=3&gt;Building an organization around exceptional leaders with the deepest industry expertise is core to how we evolve our organization. &lt;A class="" title="GFS welcomes Kevin Timmons" href="http://blogs.technet.com/msdatacenters/archive/2009/06/22/microsoft-s-infrastructure-services-team-welcomes-kevin-timmons.aspx" target=_blank mce_href="http://blogs.technet.com/msdatacenters/archive/2009/06/22/microsoft-s-infrastructure-services-team-welcomes-kevin-timmons.aspx"&gt;Read&amp;nbsp;today's posting&lt;/A&gt; on our Microsoft Data Centers blog about Kevin Timmons joining&amp;nbsp;Global Foundation Services&amp;nbsp;to head up our Data Center Services organization. Kevin brings a wealth of knowledge and passion in this space, most recently serving as vice president of Operations at Yahoo!, where he led the build-out of their data centers and infrastructure.&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3257508" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Kevin+Timmons/">Kevin Timmons</category></item><item><title>Response to Question about SAS 70 Objectives</title><link>http://blogs.technet.com/b/gfs/archive/2009/06/16/response-to-question-about-sas-70-objectives.aspx</link><pubDate>Wed, 17 Jun 2009 02:45:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3255614</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3255614</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/06/16/response-to-question-about-sas-70-objectives.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;By Pete Boden, GM, Online Services Security &amp;amp; Compliance&lt;SPAN style="COLOR: black"&gt;, Global Foundation Services&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;Following our posting further below we received a question about what the objectives were for our SAS 70 certification. Here's our response:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;The Global Foundation Services (GFS)-managed online operating environment is required to meet a number of government-mandated and industry security requirements, many of which require a periodic review to validate that compliance is being maintained.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;These are in addition to our business requirements.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The GFS Online Services Security and Compliance team operates a comprehensive security program and control framework that is evaluated regularly by external parties.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;The ISO standard is the foundation of our program. While the ISO/IEC 27001:2005 certification standard includes about 150 security controls for our scope, we have increased our security controls to 291 at this point. The reason we’ve done this is to account for the uniqueness of the cloud infrastructure and risk management. In addition, the security program and capabilities are subject to a SAS 70 Type II review.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The ISO certification and SAS 70 Type II attestation demonstrate Microsoft’s commitment to delivering a trustworthy cloud computing infrastructure.&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3255614" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Pete+Boden/">Pete Boden</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/SAS+70/">SAS 70</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/ISO+27001/">ISO 27001</category></item><item><title>Securing Microsoft’s Cloud Infrastructure: Part 2</title><link>http://blogs.technet.com/b/gfs/archive/2009/06/08/securing-microsoft-s-cloud-infrastructure-part-2.aspx</link><pubDate>Mon, 08 Jun 2009 19:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3251952</guid><dc:creator>GFS1</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3251952</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/06/08/securing-microsoft-s-cloud-infrastructure-part-2.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;By Pete Boden, GM, Online Services Security &amp;amp; Compliance&lt;SPAN style="COLOR: black"&gt;, Global Foundation Services&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black"&gt;&lt;IMG style="WIDTH: 330px; HEIGHT: 271px" height=271 hspace=3 src="http://blogs.technet.com/photos/gfs/images/3252549/original.aspx" width=330 align=right vspace=3 mce_src="http://blogs.technet.com/photos/gfs/images/3252549/original.aspx"&gt;The release last week of our &lt;/SPAN&gt;white&lt;SPAN style="COLOR: #1f497d"&gt; &lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;paper on &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A class="" title="Securing Microsoft's Cloud Infrastructure" href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" target=_blank mce_href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf"&gt;&lt;FONT face=Calibri size=3&gt;Securing Microsoft’s Cloud Infrastructure&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black"&gt; has generated a lot of discussion in the industry, which was our intent. We wrote the &lt;/SPAN&gt;paper in part to communicate our practices to customers concerned about security in the cloud environment and to generate a healthy dialogue within the industry in order to share best practices for creating more secure cloud-based services. &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Many people who responded to last week’s release wanted to know more about Microsoft’s history in online services and security. Our background in these areas goes back further than many people might think. Microsoft built its first data center in 1989, four years before launching its first Web sites. Microsoft.com and MSN (Beta) went public in 1994, followed by the acquisition of Hotmail in 1997. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;After successfully responding to a number of security issues at the time, in 2002 the company formed the Trustworthy Computing initiative, with Bill Gates committing Microsoft to fundamentally changing our security strategy in key areas.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Microsoft understands that success in the online services business depends on its ability to safeguard customers’ data and to maintain the availability of its services.&amp;nbsp; Accordingly, Microsoft designs and tests applications and infrastructure to internationally recognized standards in order to demonstrate these capabilities and comply with laws and with internal security and privacy policies.&amp;nbsp; As a result, Microsoft’s customers benefit from highly focused testing and monitoring, automated patch delivery, cost-saving economies of scale, and ongoing security improvements.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;“Ongoing” is a particularly important part of the equation, as the information technology industry faces the following evolving challenges related to online service delivery:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: black"&gt;Emerging cloud business models create a growing interdependence amongst public and private sector entities and the people they serve:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: black"&gt; Such organizations and their customers will become more interdependent on each other through use of the cloud.&amp;nbsp; With these new dependencies come mutual expectations that platform services and hosted applications need to be secure and available.&amp;nbsp; Microsoft provides a trustworthy infrastructure—a base upon which public and private sector entities and their partners can build a trustworthy experience for their users.&amp;nbsp; Microsoft actively works with these groups and the development community at large to encourage adoption of security-centric risk management processes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: black"&gt;Acceleration of adoption of cloud services, including the continuing evolution of technologies and business models, creates a dynamic hosting environment, which is of itself a security challenge: &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: black"&gt;Keeping pace with growth and anticipating future needs is essential to running an effective security program.&amp;nbsp; The latest wave of change has already begun with the rapid move to virtualization and a growing adoption of Microsoft’s Software-plus-Services strategy, which combines the power and capabilities of computers, mobile devices, online services, and enterprise software.&amp;nbsp; The advent of cloud platforms enables custom applications to be developed by third parties and hosted in the Microsoft cloud.&amp;nbsp; Through the online services Information Security Program, Microsoft maintains strong internal partnerships among security, product, and service delivery teams to provide a trustworthy Microsoft cloud environment while these changes occur.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: black"&gt;Attempts to infiltrate or disrupt online service offerings grow increasingly sophisticated as more commerce and business occurs in this venue:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: black"&gt; While pranksters still seek attention through a variety of techniques including domain squatting and man-in-the-middle attacks, more sophisticated attempts aimed at obtaining identities or blocking access to sensitive business data have emerged, along with a more organized underground market for stolen information.&amp;nbsp; Microsoft works closely with law enforcement, industry partners and peers, and research groups to understand and respond to this evolving threat landscape.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="COLOR: black"&gt;Complex compliance requirements must be addressed as new and existing services are delivered globally: &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR: black"&gt;Regulatory, statutory, and industry compliance is a highly complex area because worldwide each country can and does pass its own laws that can govern the provision and use of online environments.&amp;nbsp; Microsoft must be able to comply with a myriad of regulatory obligations because it has data centers in a number of countries and offers online services to a global customer base.&amp;nbsp; In addition, many industries impose their own requirements.&amp;nbsp; Microsoft has implemented a compliance framework (described in our white paper) whereby it &lt;/SPAN&gt;manages various compliance obligations under a single program.&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;To stay ahead of all these challenges, Microsoft focuses on three key areas to provide a trustworthy cloud:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Utilizing a risk-based information security program that assesses and prioritizes security and operational threats to the business&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Maintaining and updating a detailed set of security controls that mitigate risk&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;•&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Operating a compliance framework that ensures controls are designed appropriately and are operating effectively&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Microsoft’s Information Security Program defines the compliance framework and how our security team operates.&amp;nbsp; The program has been independently certified by British Standards Institute (BSI) Management Systems America as being compliant with ISO/IEC 27001:2005. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black"&gt;The framework that enabled Microsoft to earn the ISO 27001:2005 accreditation and SAS Type I and Type II attestations for our cloud &lt;/SPAN&gt;infrastructure also sets the stage for product and service delivery teams to more efficiently obtain additional certifications and attestations as appropriate. Microsoft’s independently certified programs help to demonstrate the continued relevance of these programs to the evolution of challenges and opportunities in the online services marketplace.&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;If you’d like to know more, please &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;&lt;A class="" title="read our security white paper" href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" target=_blank mce_href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf"&gt;read our &lt;SPAN style="COLOR: #1f497d"&gt;security &lt;/SPAN&gt;white paper&lt;/A&gt;&lt;SPAN style="COLOR: black"&gt;. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;We’re proud of the innovations we’ve made in the areas of security, privacy, reliability, and business practices.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And we’ll continue innovating as we respond to the evolving challenges of cloud computing.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;SPAN style="COLOR: black"&gt;While our advancements are competitive advantages to Microsoft’s online service offerings, we hope they will help others make the cloud a safer and more reliable place that public and private organizations and individual consumers can trust.&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3251952" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/BPOS/">BPOS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Charlie+McNerney/">Charlie McNerney</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Pete+Boden/">Pete Boden</category></item><item><title>Securing Microsoft’s Cloud Infrastructure</title><link>http://blogs.technet.com/b/gfs/archive/2009/05/27/securing-microsoft-s-cloud-infrastructure.aspx</link><pubDate>Wed, 27 May 2009 19:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3246253</guid><dc:creator>GFS1</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/gfs/rsscomments.aspx?WeblogPostID=3246253</wfw:commentRss><comments>http://blogs.technet.com/b/gfs/archive/2009/05/27/securing-microsoft-s-cloud-infrastructure.aspx#comments</comments><description>&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face="trebuchet ms,geneva"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=Calibri&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;By Charlie McNerney, GM, Business &amp;amp; Risk Management, Global Foundation Services&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;IMG style="WIDTH: 300px; HEIGHT: 202px" height=202 hspace=3 src="http://blogs.technet.com/photos/gfs/images/3252199/original.aspx" width=300 align=right vspace=3 mce_src="http://blogs.technet.com/photos/gfs/images/3252199/original.aspx"&gt;When we talk with business customers about what they expect from cloud computing, two main themes emerge. On the one hand, technology business decision makers are enticed by the idea that purchasing services from a cloud environment could allow them to save money and focus on their core business, especially in the current economic climate.&amp;nbsp; At the same time, certain themes have emerged as potential barriers to rapid adoption of cloud services. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;At the top the list are concerns about security, privacy, reliability, and operational control.&amp;nbsp; Microsoft recognizes that business decision makers have many questions about these issues and want to know how Microsoft is addressing them in our cloud computing environment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black"&gt;The &lt;A class="" title="white paper" href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" target=_blank mce_href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf"&gt;white paper&lt;/A&gt; we’re releasing today describes how our coordinated and strategic application of people, processes, technologies, and experience with consumer and enterprise security has resulted in continuous improvements to the security practices and policies of the Microsoft cloud infrastructure.&amp;nbsp; The Online Services Security and Compliance (OSSC) team within the Global Foundation Services division that supports Microsoft’s infrastructure for online services builds on the same security principles and processes the company has developed through years of experience managing security risks in traditional software development and operating environments. Independent, third-party validation of OSSC’s approach includes Microsoft’s cloud infrastructure achieving both SAS 70 Type I and Type II attestations and ISO/IEC 27001:2005 certification. &lt;FONT color=#000000&gt;&lt;SPAN style="FONT-SIZE: 12pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-themecolor: text1"&gt;We are proud to be one of the first major online service providers to achieve ISO 27001 certification for our infrastructure&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT color=#000000&gt;. We have also gone beyond the ISO standard, which includes some 150 security controls&lt;/FONT&gt;. We have developed 291 security controls to date to account for the unique challenges of the cloud infrastructure and what it takes to mitigate some of the risks involved.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The amount of time and&amp;nbsp;money we put into managing these resources, and the innovations we’ve developed in the security space, are in one sense a competitive advantage.&amp;nbsp; But Microsoft feels that sharing security best practices is also important to help the industry improve together for the benefit of customers and to promote a safer and more secure environment for cloud services.&lt;B&gt; &lt;/B&gt;Whether you’re a business decision maker evaluating various cloud options, a consumer, or a cloud provider, we invite you to &lt;U&gt;&lt;A class="" title="read our white paper" href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" target=_blank mce_href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf"&gt;read our white paper&lt;/A&gt;&lt;/U&gt;. We’re proud of the processes we’ve developed to add security, privacy, reliability, and operational control to the reasons companies choose Microsoft’s offerings, and we hope this information will help others make the cloud a safer and more reliable environment that companies can trust for their operations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Here again is a link to our white paper: &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;A class="" title="Securing Microsoft's Cloud Infrastructure" href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf" target=_blank mce_href="http://www.globalfoundationservices.com/security/documents/SecuringtheMSCloudMay09.pdf "&gt;Securing Microsoft’s Cloud Infrastructure&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Please&amp;nbsp;also read&amp;nbsp;this new white paper focused on &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;A class="" title="Security in Microsoft's Business Productivity Online Suite" href="http://technet.microsoft.com/en-us/library/cc742708.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/cc742708.aspx"&gt;&lt;FONT color=#0000ff&gt;Security in Microsoft's Business Productivity Online Suite&lt;/FONT&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: black; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;To read&amp;nbsp; the second installment of this posting addressing questions we've received since releasing our white paper, see the &lt;A class="" title="Securing Microsoft’s Cloud Infrastructure, Part 2 blog post" href="http://blogs.technet.com/gfs/" target=_blank mce_href="http://blogs.technet.com/gfs/"&gt;Securing Microsoft’s Cloud Infrastructure, Part 2 blog post&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3246253" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/gfs/archive/tags/security/">security</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/risk/">risk</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Global+Foundation+Services/">Global Foundation Services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/compliance/">compliance</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/GFS/">GFS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/online+services/">online services</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/BPOS/">BPOS</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Charlie+McNerney/">Charlie McNerney</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/cloud+computing/">cloud computing</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/gfs/archive/tags/Data+Centers/">Data Centers</category></item></channel></rss>
