{"id":283,"date":"2016-06-06T12:09:42","date_gmt":"2016-06-06T11:09:42","guid":{"rendered":"https:\/\/www.microsoft.com\/en-gb\/industry\/blog\/industry\/2016\/06\/06\/earning-public-trust-in-the-age-of-cyber-threats\/"},"modified":"2016-06-06T12:09:42","modified_gmt":"2016-06-06T11:09:42","slug":"earning-public-trust-in-the-age-of-cyber-threats","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-gb\/industry\/blog\/government\/2016\/06\/06\/earning-public-trust-in-the-age-of-cyber-threats\/","title":{"rendered":"Earning public trust in the age of cyber threats"},"content":{"rendered":"

Often we hear about the \u201cpublic trust.\u201d While its common-law roots refer to the air, rivers, and lands commons to be shared by all citizens, the term today also connotes an attribute of the relationship between citizens and governments who can meet their needs in a digital world. Personal and business security matters.\u00a0 There is no security without cybersecurity. In this age of growing cyber threats, this means that governments must demonstrate they can protect citizen and employee data while delivering the services their constituents expect.\u00a0 In short, governments must earn their trust.<\/p>\n

Cities are already using cloud services and Internet of Things (IoT) along with big data, mobility, and social media, to transform their operations so they can deliver services more efficiently and invent new ways to address age-old civic issues. But alongside their transformations are ever-increasing vulnerabilities to cyber-attacks. Keeping data secure is one of several important steps needed to assure citizens and earn trust in these transformational technologies. Are governments ready?<\/p>\n

Growing needs<\/h2>\n

Many cities have developed defence-in-depth plans for cyber threats, but many more must take the needed steps to boost their defences. For example, in a 2015 UK survey of 150 senior public sector IT executives, 40% said their organisations had experienced a significant data breach in the prior year, and 61% had lost important documents.[1]<\/p>\n

These findings echo what we hear from city officials worldwide. They face growing pressures to safeguard data security and privacy, but must do so with shrinking budgets and increasingly limited in-house skillsets. The risk is that any data security breach will undermine the public\u2019s trust in their governments\u2019 abilities to prevent intrusions. Without that trust, it can be far harder to win citizen approval of other projects, especially those related to IT infrastructure and management.<\/p>\n

Data stewardship<\/h2>\n

One way cities can address the growing need for cybersecurity is to adhere to the ISO\/IEC 27001 family of security standards.\u00a0 Another is to adhere to ISO\/IEC 27018, the first global code of practice for cloud privacy to protect personally identifiable information (PII). If doing so is beyond a city\u2019s resources, it should seek partners who can provide the reliable and certified data stewardship that\u2019s needed.<\/p>\n

Microsoft is committed to earning your trust as your partner in safeguarding your data. For decades, Microsoft has developed enterprise software and run some of the largest online services in the world. With this experience, we continuously improve security-aware software development, operational management, and threat mitigation practices that are essential to the strong protection of services and data in the cloud.<\/p>\n

In addition, Microsoft hires the British Standards Institution (BSI), an accredited, independent certification body, to annually audit our compliance with ISO\/IEC 27001 for our Azure cloud platform as well as Office 365 Government and Dynamics CRM Online Government, plus several other cloud offerings.<\/p>\n

This audit helps to ensure we continue to fulfill our four commitments to governments, enterprises, consumers, and people around the world: We will keep their data secure; we will ensure people\u2019s data is private and under their control; we will figure out the laws in each country and manage data accordingly; and we will be transparent so people know what we are doing.<\/p>\n

Start with these resources<\/h2>\n

The ISO\/IEC 27001 security standards <\/a>can serve as a great starting point for IT professionals in cities and other public-sector organisations seeking to learn more about best practices for cybersecurity. You can read more about Microsoft\u2019s compliance with these standards, including\u00a0 ISO\/IEC 27018 by visiting the Microsoft Trust Center<\/a>.<\/p>\n

We also invite you to download the Cyber Security Demystified eBook<\/a>, which offers valuable insights into safeguarding data privacy and security in your organisation.<\/p>\n

Download the Cyber Security Demystified eBook<\/a><\/p>\n

[1] \u201cSeeing Information Differently: The Public Sector \/ Managing Information Through the Challenge of Change.\u201d Iron Mountain UK. 2015.<\/em>
\n