Home
%3CLINGO-SUB%20id%3D%22lingo-sub-275126%22%20slang%3D%22en-US%22%3EAssessing%20risk%20and%20compliance%20for%20financial%20services%20institutions%20using%20the%20Microsoft%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-275126%22%20slang%3D%22en-US%22%3E%3CP%3EDue%20to%20regulatory%20and%20compliance%20concerns%2C%20many%20financial%20services%20institutions%20(FSIs)%20have%20remained%20unsure%20about%20moving%20to%20the%20cloud%2C%20even%20as%20they%20embrace%20the%20idea%20of%20digital%20transformation.%20That%E2%80%99s%20why%20completing%20a%20risk%20assessment%20is%20a%20critical%20step%20in%20the%20decision%20to%20adopt%20any%20cloud%20services%20and%20a%20precursor%20to%20notifying%20regulators%20of%20the%20cloud%20plan.%20Any%20strong%20assessment%20covers%20two%20key%20areas%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EGeneral%20risk%3C%2FSTRONG%3E%2C%20which%20helps%20you%20ensure%20that%20whatever%20systems%20or%20data%20you%20are%20planning%20to%20move%20to%20the%20cloud%20will%20not%20introduce%20any%20new%20or%20unidentified%20risks%20for%20your%20organization%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3ECompliance%3C%2FSTRONG%3E%2C%20which%20ensures%20you%E2%80%99ve%20considered%20the%20external%20regulations%20imposed%20by%20industry%20or%20governments%20on%20FSIs%20(such%20as%20privacy%20regulations%2C%20general%20banking%20and%20insurance%20regulations%2C%20or%20cloud%20and%20outsourcing%20regulations)%2C%20as%20well%20as%20your%20own%20internal%20procedures%20and%20guidelines.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EYou%20probably%20have%20mature%20assessment%20models%20for%20your%20on-premises%20systems.%20Assessing%20risk%20for%20cloud%20services%20requires%20a%20different%20approach.%20First%2C%20you%20need%20to%20think%20through%20all%20of%20the%20challenges%20moving%20to%20the%20cloud%20might%20present%20for%20your%20organization.%20For%20example%2C%20in%20almost%20all%20cases%2C%20the%20responsibility%20for%20security%20controls%20and%20compliance%20will%20shift%20between%20your%20organization%20and%20the%20cloud%20service%20provider%20(CSP)%2C%20depending%20on%20the%20type%20of%20service%20you%20choose%E2%80%94say%2C%20infrastructure%20as%20a%20service%20(IaaS)%20versus%20software%20as%20a%20service%20(SaaS).%20In%20addition%2C%20when%20you%20move%20to%20the%20cloud%2C%20your%20data%20is%20managed%20externally%3B%20your%20CSP%20may%20be%20in%20a%20different%20part%20of%20the%20world%2C%20with%20very%20different%20contractual%20terms%20and%20regulations%20for%20handling%20data.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHowever%2C%20moving%20to%20the%20cloud%20also%20presents%20considerable%20opportunities%20in%20the%20areas%20of%20security%20and%20compliance.%20Large%20CSPs%20like%20Microsoft%20operate%20at%20large%20economies%20of%20scale.%20This%20means%20we%20can%20rapidly%20develop%20best-in-class%20security%20measures%2C%20deploy%20them%2C%20and%20keep%20them%20updated.%20And%20in%20the%20shared%20responsibility%20model%20we%20mentioned%20above%2C%20we%20also%20remove%20some%20of%20our%20customers%E2%80%99%20burden%20for%20the%20cost%20of%20keeping%20systems%20compliant.%20Finally%2C%20we%20offer%20a%20high%20level%20of%20service%20availability%20across%20multiple%20geographic%20areas%20worldwide%2C%20which%20means%20your%20services%20are%20much%20more%20fault-tolerant%20and%20resilient%20against%20failures%20than%20an%20on-premises%20environment.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAt%20Microsoft%2C%20we%20understand%20that%20assessing%20risk%20and%20notifying%20regulators%20are%20critical%20steps%20in%20any%20FSI%E2%80%99s%20decision%20to%20move%20to%20the%20cloud.%20We%E2%80%99ve%20created%20a%20cloud%20risk%20assessment%20model%20to%20walk%20you%20through%20completing%20an%20effective%20end-to-end%20risk%20analysis%20of%20Microsoft%20cloud%20services%2C%20with%20guidance%20for%20steps%20including%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EIdentifying%20stakeholders%20and%20determining%20a%20governance%20approach%3C%2FSTRONG%3E.%20Determining%20who%20your%20internal%20stakeholders%20will%20be%20and%20outlining%20internal%20processes%20and%20responsibilities%20for%20internal%20governance.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EChoosing%20the%20right%20reference%20framework%20for%20your%20assessment%3C%2FSTRONG%3E.%20Selecting%20an%20external%20reference%20framework%20like%20the%20Cloud%20Security%20Alliance%E2%80%99s%20Cloud%20Controls%20Matrix%20or%20creating%20an%20assessment%20based%20on%20a%20service%20against%20regulatory%20requirements%20like%20GDPR.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EUsing%20Microsoft%20%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fservicetrust.microsoft.com%2FComplianceManager%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3ECompliance%20Manager%3C%2FA%3E%3C%2FSPAN%3E%3CU%3E*%3C%2FU%3E%20to%20assess%20risks%3C%2FSTRONG%3E.%20For%20Microsoft%20customers%2C%20assessing%20their%20deployment%20in%20the%20Microsoft%20cloud%20to%20distinguish%20between%20provider-%20and%20customer-managed%20controls.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EAssessing%20regulatory%20guidelines%20by%20country%3C%2FSTRONG%3E.%20Microsoft%20provides%20Compliance%20Guides%20by%20region%20as%20part%20of%20our%20commitment%20to%20financial%20institutions%20around%20the%20world.%20We%20developed%20these%20guides%20to%20help%20financial%20institutions%20adopt%20Microsoft%20cloud%20services%20with%20confidence%20that%20they%20are%20meeting%20the%20applicable%20regulatory%20requirements.%20Our%20most%20recent%20regional%20additions%20include%20Israel%2C%20Poland%2C%20France%2C%20India%2C%20Belgium%2C%20and%20the%20Netherlands.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EAssembling%20regulatory%20submission%3C%2FSTRONG%3E.%20Preparing%20a%20formal%20notification%20providing%20the%20information%20regulators%20expect%20about%20the%20cloud%20project%20and%20how%20risks%20have%20been%20assessed%2C%20mitigated%2C%20and%20approved.%20We%20provide%20a%20template%20for%20notifying%20regulators.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3ETo%20learn%20more%2C%20click%20%3CA%20href%3D%22https%3A%2F%2Fservicetrust.microsoft.com%2FViewPage%2FTrustDocuments%3Fcommand%3DDownload%26amp%3BdownloadType%3DDocument%26amp%3BdownloadId%3Dedee9b14-3661-4a16-ba83-c35caf672bd7%26amp%3BdocTab%3D6d000410-c9e9-11e7-9a91-892aae8839ad_FAQ_and_White_Papers%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E%20to%20download%20the%20free%20whitepaper%2C%20%E2%80%9CRisk%20Assessment%20and%20Compliance%20Guide%20for%20Financial%20Institutions%20in%20the%20Microsoft%20Cloud%2C%E2%80%9D%20or%20visit%20the%20%3CA%20href%3D%22https%3A%2F%2Fservicetrust.microsoft.com%2FViewPage%2FTrustDocuments%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EMicrosoft%20Service%20Trust%20Portal%3C%2FA%3E%20Compliance%20Guides%20to%20view%20Compliance%20Guides%20by%20region.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3E*Compliance%20Manager%20is%20a%20dashboard%20that%20provides%20a%20summary%20of%20your%20data%20protection%20and%20compliance%20stature%20and%20recommendations%20to%20improve%20data%20protection%20and%20compliance.%20This%20is%20a%20recommendation%2C%20it%20is%20up%20to%20you%20to%20evaluate%20its%20effectiveness%20in%20your%20regulatory%20environment%20prior%20to%20implementation.%20Recommendations%20from%20Compliance%20Manager%20should%20not%20be%20interpreted%20as%20a%20guarantee%20of%20compliance.%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-275126%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EDue%20to%20regulatory%20and%20compliance%20concerns%2C%20many%20financial%20services%20institutions%20(FSIs)%20have%20remained%20unsure%20about%20moving%20to%20the%20cloud%2C%20even%20as%20they%20embrace%20the%20idea%20of%20digital%20transformation.%20That%E2%80%99s%20why%20completing%20a%20risk%20assessment%20is%20a%20critical%20step%20in%20the%20decision%20to%20adopt%20any%20cloud%20services%20and%20a%20precursor%20to%20notifying%20regulators%20of%20the%20cloud%20plan.%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20286px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F57716iDA603FB70E54C6A2%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22Capture.JPG%22%20title%3D%22Capture.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-276003%22%20slang%3D%22en-US%22%3ERe%3A%20Assessing%20risk%20and%20compliance%20for%20financial%20services%20institutions%20using%20the%20Microsoft%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-276003%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20helpful%20to%20educate%20regulated%20industry%20customers%20who%20continue%20to%20believe%20that%20compliance%20and%20cloud%20are%20mutually%20exclusive.%26nbsp%3B%20We%20have%20to%20help%20land%20that%20compliance%20is%20easier%20in%20the%20cloud%20and%20this%20is%20very%20helpful!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-422215%22%20slang%3D%22en-US%22%3ERe%3A%20Assessing%20risk%20and%20compliance%20for%20financial%20services%20institutions%20using%20the%20Microsoft%20Cloud%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-422215%22%20slang%3D%22en-US%22%3E%3CP%3ESince%20financal%20services%20institutions%20handle%20very%20sensative%20personal%20information.%20I%20hope%20the%20security%20departments%20can%20handle%20any%20breach%20to%20the%20system%20since%20they%20will%20be%20sending%20a%20lot%20of%20customers%20information%20to%20some%20cloud.%20I%20would%20like%20to%20know%20how%20cloud%20security%20actually%20works.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Due to regulatory and compliance concerns, many financial services institutions (FSIs) have remained unsure about moving to the cloud, even as they embrace the idea of digital transformation. That’s why completing a risk assessment is a critical step in the decision to adopt any cloud services and a precursor to notifying regulators of the cloud plan. Any strong assessment covers two key areas:

  • General risk, which helps you ensure that whatever systems or data you are planning to move to the cloud will not introduce any new or unidentified risks for your organization
  • Compliance, which ensures you’ve considered the external regulations imposed by industry or governments on FSIs (such as privacy regulations, general banking and insurance regulations, or cloud and outsourcing regulations), as well as your own internal procedures and guidelines. 

You probably have mature assessment models for your on-premises systems. Assessing risk for cloud services requires a different approach. First, you need to think through all of the challenges moving to the cloud might present for your organization. For example, in almost all cases, the responsibility for security controls and compliance will shift between your organization and the cloud service provider (CSP), depending on the type of service you choose—say, infrastructure as a service (IaaS) versus software as a service (SaaS). In addition, when you move to the cloud, your data is managed externally; your CSP may be in a different part of the world, with very different contractual terms and regulations for handling data.

 

However, moving to the cloud also presents considerable opportunities in the areas of security and compliance. Large CSPs like Microsoft operate at large economies of scale. This means we can rapidly develop best-in-class security measures, deploy them, and keep them updated. And in the shared responsibility model we mentioned above, we also remove some of our customers’ burden for the cost of keeping systems compliant. Finally, we offer a high level of service availability across multiple geographic areas worldwide, which means your services are much more fault-tolerant and resilient against failures than an on-premises environment.

 

At Microsoft, we understand that assessing risk and notifying regulators are critical steps in any FSI’s decision to move to the cloud. We’ve created a cloud risk assessment model to walk you through completing an effective end-to-end risk analysis of Microsoft cloud services, with guidance for steps including:

  • Identifying stakeholders and determining a governance approach. Determining who your internal stakeholders will be and outlining internal processes and responsibilities for internal governance.
  • Choosing the right reference framework for your assessment. Selecting an external reference framework like the Cloud Security Alliance’s Cloud Controls Matrix or creating an assessment based on a service against regulatory requirements like GDPR.
  • Using Microsoft Compliance Manager* to assess risks. For Microsoft customers, assessing their deployment in the Microsoft cloud to distinguish between provider- and customer-managed controls.
  • Assessing regulatory guidelines by country. Microsoft provides Compliance Guides by region as part of our commitment to financial institutions around the world. We developed these guides to help financial institutions adopt Microsoft cloud services with confidence that they are meeting the applicable regulatory requirements. Our most recent regional additions include Israel, Poland, France, India, Belgium, and the Netherlands.
  • Assembling regulatory submission. Preparing a formal notification providing the information regulators expect about the cloud project and how risks have been assessed, mitigated, and approved. We provide a template for notifying regulators.

To learn more, click here to download the free whitepaper, “Risk Assessment and Compliance Guide for Financial Institutions in the Microsoft Cloud,” or visit the Microsoft Service Trust Portal Compliance Guides to view Compliance Guides by region.

 

*Compliance Manager is a dashboard that provides a summary of your data protection and compliance stature and recommendations to improve data protection and compliance. This is a recommendation, it is up to you to evaluate its effectiveness in your regulatory environment prior to implementation. Recommendations from Compliance Manager should not be interpreted as a guarantee of compliance.

2 Comments
Microsoft

This is helpful to educate regulated industry customers who continue to believe that compliance and cloud are mutually exclusive.  We have to help land that compliance is easier in the cloud and this is very helpful!

 

Senior Member

Since financal services institutions handle very sensative personal information. I hope the security departments can handle any breach to the system since they will be sending a lot of customers information to some cloud. I would like to know how cloud security actually works.