ITAR Compliance

Copper Contributor

If an organization is using ITAR data with Microsoft solutions, is GCC high required for the storage or processing of this data?

3 Replies

@Anon414 GCCH is only required if a customer desires a contractual level of support from Microsoft committing to ensure that access to the service is restricted to US Persons. If customers are comfortable with the screening requirements implemented in GCC; or implementing their own compensating controls with regard to end to end encryption then services other than GCCH are feasible.

Required vs not required is perhaps not exactly the decision, but rather design. As Shawn and Richard state below, you can DO E2E encryption in many different ways, but the question ffor you is workload. What do you want to DO? If you want to collaborate and use Teams, connectors, telework, etc, then yes, you'll want to use the collaboration platform built for that purpose where cloud services can reason over it. If that's the case, then yeah, I'd recommend GCCH - because you get all the compliance benefits. But if you're just looking for blob storage, then yep, you can host it in commercial in a regional data center in the US and wrap some encryption on it - that would probably pass muster from your IA folks.