Skip to main content
Microsoft AI
Published
1 min read

Find a provider with a record for addressing security 

Cybersecurity threats continue to evolve, and a cloud security provider who understands the threat landscape, has a history of protecting against them, and proven experience responding to them can give you more confidence in the security of your data.

Published
1 min read

Don’t overlook document retention and e-discovery 

Meeting and enabling legal compliance means cloud service providers should be able to manage and store data in a way that meets government data retention, e-discovery, public records obligations, legal holds, archiving, messaging rules, and more – as part of the core service, not by requiring to the purchase of expensive third-party add-on services.

Published
<1 min read

Does your data reside exclusively with other screened workloads? 

When storing sensitive data, it’s imperative to know what other data and workloads are being stored in the same cloud infrastructure. Government cloud service providers should apply rigorous screening policies and procedures to determine eligibility for all incoming requests.

Published
1 min read

IRS 1075 guidance and ITAR obligations 

IRS tax security guidelines and International Traffic in Arms (ITAR) regulations have special data storage, confidentiality, data location, and other substantive requirements that rely on specific security features.

Published
1 min read

CJIS: Make sure your provider would pass an FBI audit 

Critical in the FBI’s Criminal Justice Information Services (CJIS) standards are employee background checks, detailed security updates and the ability for the State CJIS Systems Agency (CSA) to examine and inspect cloud solution providers to meet their audit requirements.

Published
1 min read

Compliance: non-negotiable 

Requirements around compliance are complex and nuanced: from HIPAA to the IRS to the Department of Defense (DoD) and FedRAMP, cloud service providers should prove they not only understand compliance standards—but can help you meet them. Only government regulators can determine when an agency or organization is in compliance.