Security and offshore Azure regions

Stowe, Jim 1 Reputation point
2022-07-01T13:45:09.943+00:00

I work for a financial institution. We've recently started engaging offshore contractors in India. Their round-trip-times to our Azure VDI instances in EastUS2 are between 400-600ms. I've proposed moving the VDI instances into one of the Azure regions located in India. However, our Information Security team is very reluctant to place any of our resources in an offshore data center (non-continental USA).

Can anyone direct me toward resources that would address (and hopefully alleviate) this concern for our Information Security folks?

Thank you.

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,841 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. kobulloc-MSFT 26,811 Reputation points Microsoft Employee Moderator
    2022-07-01T16:10:05.77+00:00

    Hello, @Stowe, Jim !

    It sounds like your Information Security team is primarily concerned about physical security in the data center as well as data residency and data protection. I'd be happy to provide some resources that will strengthen confidence in this decision (and please let me know if you need additional or more specific examples).

    Azure Compliance offerings
    Azure compliance offerings are a good place to start the conversation as they use well defined specifications to cover common concerns. These offerings provide assurance that your company will meet regulatory compliance standards, including various financial service standards around the world. Microsoft cloud is compliant with more certifications than any other cloud service provider.

    https://learn.microsoft.com/en-us/compliance/regulatory/offering-home

    Enabling Data Residency and Data Protection in Azure regions
    This page has a link to our Enabling Data Residency and Data Protection paper which covers data residency assurances, your control over data, how Microsoft protects data, and privacy regulations and standards. Section IV, "How Microsoft protects access to customer data" on page 23 may be a good place to start.

    https://azure.microsoft.com/en-us/resources/achieving-compliant-data-residency-and-security-with-azure/

    Azure Datacenter Security
    The documentation covers datacenter security in great detail which will provide assurance related to physical, environmental, and infrastructure security as well as other concerns. Datacenter facilities have strict access controls, perimeter fencing, security officers, locked server racks, alarms, video surveillance, and much more.

    Other options
    It may also be worth mentioning that there are networking options that may be able to bring your round trip time down to the low 200ms range by using the Azure network/Microsoft global network or looking at services like ExpressRoute.

    217005-image.png

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.