14:47
Donnerstag, 05. März 2015
Datensicherheit bei
Microsoft Azure und Offrice 365
Martina Grom
Rainer Stropek
Harald Leitenmüller
Global Foundation Services
Lowest $/MW, Rapid Deployment
Geo-independent design
ISO27001, SSAE16, FISMA
Security & Compliance
Data Centers
Design, Build, Operate
Modular Cloud-Scale Designs
Utility Pricing
Cost Transparency
Global Capacity
Microsite Strategy
300+ Product Teams
Microsoft IT (1900 LOB Apps)
Cloud Hosting – O365/Windows
Azure/CRM
Global Network
Dark Fiber, Routing, Switching,
Load-Balancing
Lower DC to DC costs
MOC
Microsoft Operation Centers
Tools & Automation
SCRY & System Center 2012
Large infrastructure scale is the enabler
19 Regions ONLINE…large datacenter capacity around the world…and we’re growing
 100+ datacenters
 One of the top 3 networks in the world (coverage, speed, connections)
 2 x and 6x number of offered regions vs. competition
 G Series – Largest VM available in the market – 32 cores, 448GB Ram, SSD…
Operational Announced
Central US
Iowa
West US
California
North Europe
Ireland
East US
Virginia
East US 2
Virginia
US Gov
Virginia
North CentralUS
Illinois
US Gov
Iowa
South Central US
Texas
Brazil South
Sao Paulo
West Europe
Netherlands
China North *
Beijing
China South *
Shanghai
Japan East
Saitama
Japan
West
Osaka
India West
TBD
India East
TBD
East Asia
HongKong
SE Asia
Singapore
Australia West
Melbourne
Australia East
Sydney
* Operated by 21Vianet
Datacenter evolution
Server
Capacity
20yearTechnology
30m$/MW
2.0+ PUE
Colocation
Generation 1
Density
Rack
Density&Deployment
MinimizedResourceImpact
1.4 – 1.6 PUE
Generation 2
201220091989-2005 2007
Containment
1.2 – 1.5 PUE
Containers,PODs
Scalability&Sustainability
Air&Water
Economization
DifferentiatedSLAs
Generation 3
Modular
1.12 – 1.20 PUE
ITPACs&Colocations
ReducedCarbon
FasterTime-to-Market
OutsideAirCooled
3-5m$/MW
Generation 4
Hyper Scale
1.07 – 1.19 PUE
IntegratedSystem
ResilientSoftware
CommonInfrastructure
OperationalSimplicity
Flexible&Scalable
Generation 5
Future
Boydton, VA Data Center
Colocation Rooms
Contained Server Racks and Hot Aisles
Adiabatic – Air Cooled
Outdoor ITPAC’s
Adiabatic Air Cooled
Air-Cooled Colocation design
connected by a Spine
Global Foundation Services
Microsoft’s cloud environment
Platform as a Service
(PaaS)
Infrastructure as a
Service (IaaS)
Consumer and
small business
services
Enterprise
services
Third-party
hosted services
Software as a Service (SaaS)
Microsoft IT
Security Global delivery SustainabilityInfrastructure
Security Controls in the Cloud
Secure Data
Centres
Secure
Services
Security
Practices
Office 365 Azure
Tenant Isolation Access Controls
Physical Security Secure Network
Geo-redundancy
Breach detection
and mitigation
Update
Management
Denial-of-service
mitigations
Single Global
ISMS
Compliance
Management
Risk
Management
Independent
Verification
Customer
Controls
Multi-Factor
Authentication Access Controls
Identity Federation Antimalware
Data Loss
Prevention
Encryption Monitoring
3rd Party
Additions
Vertrauen in
Photo: Ken Teegardin, https://flic.kr/p/andneR, Creative Commons License
Wir:
Kleines Team
Expertise rund um Public Cloud Lösungen
Development und Deployment
Consulting und Strategie
Kunde:
Fokus auf Kernkompetenz
Kostenorientiert
Lösungsorientiert
Zukunftsorientiert
Photo: George Thomas, https://flic.kr/p/bz2dNP, Creative Commons License
Sicherheit im Wandel der Zeit
Entwickeln eines gemeinsamen Sicherheitskonzeptes
Photo: Victoria Pickering, https://flic.kr/p/7Cy6qP, Creative Commons License
Verständnis und Vertrauen schaffen
Photo: Joi Ito, https://flic.kr/p/5tWgh4, Creative Commons License
Datenstandort <> Datensicherheit
Photo: DonkeyHotey, https://flic.kr/p/amTCWH, Creative Commons License
Kunde
Eigentum
Kontrolle
Verantwortung
Vertrauen
Microsoft
Service
SaaS
Sicherheitswerkzeuge
Photo: winnifredxoxo, https://flic.kr/p/9LdVCR, Creative Commons License
Photo: Dennis Skley, https://flic.kr/p/oq2MwM, Creative Commons License
Vertrauen in Software als
Wir:
Kleines Team
Domänenwissen und Entwicklungsexpertise
Photo: Domenico, https://flic.kr/p/7EpxL3, Creative Commons License
Kunde:
Lösung, die funktioniert
Fokus auf Kernkompetenz
Photo: Christian, https://flic.kr/p/9uBKNu, Creative Commons License
Kostengünstig durch Economy of Scale
Leistbare Sicherheit
Photo: Steve Jurvetson, https://flic.kr/p/chEftd, Creative Commons License
Software Factory
Nutzung fertiger Plattformen und Komponenten
Source: http://innovatus.org.uk/2012/01/empathy-maps/
Photo: Marc Wathieu, https://flic.kr/p/nTvy8o, Creative Commons License
Photo: Martin Abegglen, https://flic.kr/p/7AUF3h, Creative Commons License
Hybride Lösungen, Escrow Services
Transparenz
Danke
Harald Leitenmüller
haraldle@microsoft.com

Datensicherheit bei Microsoft Azure und Office 365

  • 1.
    14:47 Donnerstag, 05. März2015 Datensicherheit bei Microsoft Azure und Offrice 365 Martina Grom Rainer Stropek Harald Leitenmüller
  • 2.
    Global Foundation Services Lowest$/MW, Rapid Deployment Geo-independent design ISO27001, SSAE16, FISMA Security & Compliance Data Centers Design, Build, Operate Modular Cloud-Scale Designs Utility Pricing Cost Transparency Global Capacity Microsite Strategy 300+ Product Teams Microsoft IT (1900 LOB Apps) Cloud Hosting – O365/Windows Azure/CRM Global Network Dark Fiber, Routing, Switching, Load-Balancing Lower DC to DC costs MOC Microsoft Operation Centers Tools & Automation SCRY & System Center 2012
  • 3.
    Large infrastructure scaleis the enabler 19 Regions ONLINE…large datacenter capacity around the world…and we’re growing  100+ datacenters  One of the top 3 networks in the world (coverage, speed, connections)  2 x and 6x number of offered regions vs. competition  G Series – Largest VM available in the market – 32 cores, 448GB Ram, SSD… Operational Announced Central US Iowa West US California North Europe Ireland East US Virginia East US 2 Virginia US Gov Virginia North CentralUS Illinois US Gov Iowa South Central US Texas Brazil South Sao Paulo West Europe Netherlands China North * Beijing China South * Shanghai Japan East Saitama Japan West Osaka India West TBD India East TBD East Asia HongKong SE Asia Singapore Australia West Melbourne Australia East Sydney * Operated by 21Vianet
  • 4.
    Datacenter evolution Server Capacity 20yearTechnology 30m$/MW 2.0+ PUE Colocation Generation1 Density Rack Density&Deployment MinimizedResourceImpact 1.4 – 1.6 PUE Generation 2 201220091989-2005 2007 Containment 1.2 – 1.5 PUE Containers,PODs Scalability&Sustainability Air&Water Economization DifferentiatedSLAs Generation 3 Modular 1.12 – 1.20 PUE ITPACs&Colocations ReducedCarbon FasterTime-to-Market OutsideAirCooled 3-5m$/MW Generation 4 Hyper Scale 1.07 – 1.19 PUE IntegratedSystem ResilientSoftware CommonInfrastructure OperationalSimplicity Flexible&Scalable Generation 5 Future
  • 5.
    Boydton, VA DataCenter Colocation Rooms Contained Server Racks and Hot Aisles Adiabatic – Air Cooled Outdoor ITPAC’s Adiabatic Air Cooled Air-Cooled Colocation design connected by a Spine
  • 6.
    Global Foundation Services Microsoft’scloud environment Platform as a Service (PaaS) Infrastructure as a Service (IaaS) Consumer and small business services Enterprise services Third-party hosted services Software as a Service (SaaS) Microsoft IT Security Global delivery SustainabilityInfrastructure
  • 7.
    Security Controls inthe Cloud Secure Data Centres Secure Services Security Practices Office 365 Azure Tenant Isolation Access Controls Physical Security Secure Network Geo-redundancy Breach detection and mitigation Update Management Denial-of-service mitigations Single Global ISMS Compliance Management Risk Management Independent Verification Customer Controls Multi-Factor Authentication Access Controls Identity Federation Antimalware Data Loss Prevention Encryption Monitoring 3rd Party Additions
  • 8.
    Vertrauen in Photo: KenTeegardin, https://flic.kr/p/andneR, Creative Commons License
  • 9.
    Wir: Kleines Team Expertise rundum Public Cloud Lösungen Development und Deployment Consulting und Strategie Kunde: Fokus auf Kernkompetenz Kostenorientiert Lösungsorientiert Zukunftsorientiert Photo: George Thomas, https://flic.kr/p/bz2dNP, Creative Commons License
  • 10.
  • 11.
    Entwickeln eines gemeinsamenSicherheitskonzeptes Photo: Victoria Pickering, https://flic.kr/p/7Cy6qP, Creative Commons License
  • 12.
    Verständnis und Vertrauenschaffen Photo: Joi Ito, https://flic.kr/p/5tWgh4, Creative Commons License
  • 13.
    Datenstandort <> Datensicherheit Photo:DonkeyHotey, https://flic.kr/p/amTCWH, Creative Commons License
  • 14.
  • 15.
    Photo: Dennis Skley,https://flic.kr/p/oq2MwM, Creative Commons License Vertrauen in Software als
  • 16.
    Wir: Kleines Team Domänenwissen undEntwicklungsexpertise Photo: Domenico, https://flic.kr/p/7EpxL3, Creative Commons License Kunde: Lösung, die funktioniert Fokus auf Kernkompetenz
  • 17.
    Photo: Christian, https://flic.kr/p/9uBKNu,Creative Commons License Kostengünstig durch Economy of Scale Leistbare Sicherheit
  • 18.
    Photo: Steve Jurvetson,https://flic.kr/p/chEftd, Creative Commons License Software Factory Nutzung fertiger Plattformen und Komponenten
  • 19.
    Source: http://innovatus.org.uk/2012/01/empathy-maps/ Photo: MarcWathieu, https://flic.kr/p/nTvy8o, Creative Commons License
  • 20.
    Photo: Martin Abegglen,https://flic.kr/p/7AUF3h, Creative Commons License Hybride Lösungen, Escrow Services Transparenz
  • 21.

Editor's Notes

  • #8 Ohne ins Detail gehen zu wollen und hier nicht den zeitlichen Rahmen sprengen zu wollen, ein Beispiel welche Bereiche hier zur Bewertung herangezogen werden.
  • #12 (Bausteine aus dem Service heraus)
  • #13 Verwendung schafft Vertrauen Szenario Kunde entwickelt Sicherheitsstrategie Multi Factor Hybrid Datenklassifizierung IRM Verschlüsselung
  • #16 Vertrauen in Cloud aus der Sicht von Software-as-a-Service Unterscheiden in Kunden- und Anbietersicht