The purpose of the ISO/IEC 27XXX family is to standardise the use of information technology. The ISO 27018 – that Microsoft claims to be the first one with certification on its Azure platform – is dedicated to Cloud services. What are the new standards? What does that involve? What does it mean?
The standardisation of cloud storage seems to be almost impossible, yet, it is a question of methodology. One objective of the ISO 27018 is to improve the trust of clients storing data to the cloud. The protection of personal data is considered a key component. In February 2015, Brad Smith, executive vice-president of Microsoft in juridical field, explained what was necessary to complete the ISO/IEC 27018 certification on the Azure platform, Office 365 and the Dynamics CRM.
There are six fundamental principles which define the way to protect personal data and a cloud platform to the ISO 27018 standards.
We will talk more about technical requirements which are necessary for the compliance with these standards in the next blog and we will focus more deeply on the quality of the cloud services and give examples of what exists and the way it specifically works. The key word of the ISO/IEC 27018:2014 standard is “trust” – a principle that both clients and providers have to keep in mind.
More information about ISO standards can be found here:
https://www.iso.org/fr/standards.html
https://en.wikipedia.org/wiki/International_Organization_for_Standardization
More information on Microsoft's certification:
or