International Organization for Standardization Logo

    The International Organization for Standardization (ISO) is an independent nongovernmental organization and the world’s largest developer of voluntary international standards. The International Electrotechnical Commission (IEC) is the world’s leading organization for the preparation and publication of international standards for electrical, electronic, and related technologies.

    Published under the joint ISO/IEC subcommittee, the ISO/IEC 27000 family of standards outlines hundreds of controls and control mechanisms to help organizations of all types and sizes keep information assets secure. These global standards provide a framework for policies and procedures that include all legal, physical, and technical controls involved in an organization’s information risk management processes.

    ISO/IEC 27001 is a security standard that formally specifies an Information Security Management System (ISMS) that is intended to bring information security under explicit management control. As a formal specification, it mandates requirements that define how to implement, monitor, maintain, and continually improve the ISMS. It also prescribes a set of best practices that include documentation requirements, divisions of responsibility, availability, access control, security, auditing, and corrective and preventive measures. Certification to ISO/IEC 27001 helps organizations comply with numerous regulatory and legal requirements that relate to the security of information.

    The international acceptance and applicability of ISO/IEC 27001 is a key reason why certification to this standard is a foundation of Microsoft’s approach to information security. In 2009, the company received its first ISO/IEC 27001 certification for Microsoft Cloud Infrastructure and Operations (formerly Global Foundation Services), which provides datacenters and networking for Microsoft cloud services. Currently, Microsoft’s cloud infrastructure and services are audited once a year for ISO/IEC 27001 compliance by the British Standards Institution (BSI), an accredited certification body, providing independent validation that Microsoft has implemented security controls end to end.

    Frequently asked questions

    Why is Microsoft compliance with ISO/IEC 27001 important?

    Compliance with these standards, confirmed by an accredited auditor, demonstrates that Microsoft uses internationally recognized processes and best practices to manage the infrastructure and organization that support and deliver its services. The certificate validates that Microsoft has implemented the guidelines and general principles for initiating, implementing, maintaining, and improving the management of information security.

    Where can I get the ISO/IEC 27001 audit reports and scope statements for Microsoft services?

    The Service Trust Portal provides independently audited compliance reports. You can use the portal to request reports so that your auditors can compare Microsoft's cloud services results with your own legal and regulatory requirements.

    Which services are in scope for ISO/IEC 27001?

    Covered services include:

    • Microsoft Azure: API Management, App Service: Mobile Apps, App Service: Web Apps, Application Gateway, Automation, Azure Active Directory, Azure IoT Hub, Backup, Batch, BizTalk Services, Cloud Services, Data Catalog, Data Factory, Document DB, Event Hubs, ExpressRoute, HDInsight, Key Vault, Load Balancer, Log Analytics (formerly Operational Insights), Machine Learning, Media Services, Multi-Factor Authentication, Notification Hubs, Portal, Redis Cache, RemoteApp, Rights Management, Scheduler, Service Bus, Service Fabric, Site Recovery, SQL Database, Storage, Storage Premium, StorSimple, Stream Analytics, Traffic Manager, Virtual Machines, Virtual Network, and VPN Gateway.
    • Microsoft Commercial Support: Premier and On Premises for Azure, Dynamics 365, Intune, and for Medium Business and Enterprise customers of Office 365.
    • Microsoft Dynamics 365 and Dynamics 365 U.S. Government detailed list.
    • Microsoft Intune.
    • Microsoft Office 365 and Microsoft Office 365 U.S. Government detailed list.
    • Microsoft Power BI cloud service either as a standalone service or as included in an Office 365 branded plan or suite.
    • Visual Studio Team Services.

    Does Microsoft run annual tests for infrastructure failures?

    Yes. The annual ISO/IEC 27001 certification process for the Microsoft Cloud Infrastructure and Operations group includes an audit for operational resiliency. To preview the latest certificate, click ISO/IEC 27001:2013 certificate for Microsoft Cloud Infrastructure and Operations.

    Where do I start my organization’s own ISO/IEC 27001 compliance effort?

    Adopting ISO/IEC 27001 is a strategic commitment. As a starting point, consult the ISO/IEC 27000 Directory.

    Can I leverage the ISO/IEC 27001 compliance of Microsoft services in my organization’s certification?

    Yes. If your business requires ISO/IEC 27001 certification for implementations deployed on Microsoft services, you can use the applicable certification in your compliance assessment. You are responsible, however, for engaging an assessor to evaluate the controls and processes within your own organization and your implementation for ISO/IEC 27001 compliance.

    Dynamics 365
    Office 365 U.S. Government
    Office 365 U.S. Government Defense
    Commercial Support
    Dynamics 365 U.S. Government
    Office 365
    Power BI
    Visual Studio Team Services