{"id":1055,"date":"2015-06-08T23:23:09","date_gmt":"2015-06-08T23:23:09","guid":{"rendered":"https:\/\/www.microsoft.com\/industry\/blog\/uncategorized\/the-microsoft-approach-to-cjis-compliance\/"},"modified":"2023-05-31T16:31:08","modified_gmt":"2023-05-31T23:31:08","slug":"the-microsoft-approach-to-cjis-compliance","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/industry\/blog\/government\/2015\/06\/08\/the-microsoft-approach-to-cjis-compliance\/","title":{"rendered":"The Microsoft approach to CJIS compliance"},"content":{"rendered":"
From criminal histories to fingerprint records to sexual offender registrations, U.S. law enforcement agencies rely on a wide range of FBI data to solve crime. And to access this data, they need to comply with the FBI\u2019s Criminal Justice Information Services (CJIS) security policy, which includes strict requirements for how this data is protected.<\/p>\n
A major reason why law enforcement agencies have been slow to move to the cloud is the need to comply with the CJIS security policy in the cloud just like they do within their own datacenters. The good news is that the Microsoft Cloud for Government<\/a> breaks down this barrier. We take a rigorous approach to CJIS compliance in the cloud\u2014much more rigorous, in fact, than any other enterprise cloud services provider on the market. Because of these commitments, law enforcement agencies at the local, state, and federal levels can now take advantage of the many benefits that the cloud provides.<\/p>\n Microsoft\u2019s approach to CJIS compliance differs in three important ways from other leading cloud providers. First, Microsoft is the only major cloud platform that\u2019s contractually committed to meeting CJIS requirements for federal, state, and local governments<\/b>. While other cloud providers have simply stated that they\u2019ve read and met the requirements of the CJIS security addendum, there\u2019s been no third-party validation of these statements. In contrast, Microsoft has been continually working on-the-ground with federal and state regulators to address CJIS compliance, signing contractual agreements<\/a> that legally commit the company to meeting these requirements.<\/p>\n By signing these agreements, we\u2019re entering into dedicated, ongoing partnerships with our customers. We\u2019re contractually committed to conduct background checks on all Microsoft employees who work in government datacenters. We\u2019re required to provide datacenter audit information. And we\u2019re dedicated to working together with our partners on an ongoing basis to improve law enforcement security as requirements change. In short, we\u2019re sitting together at the same table with our customers, sharing both the risk and the responsibility.<\/p>\n Second, we\u2019re the only cloud vendor to develop a completely separate cloud platform dedicated to our US federal, state, and local government clients<\/b>. Unlike other cloud providers that rope off a corner of their commercial cloud platform and declare it their government cloud, Microsoft delivers completely separate datacenters that aren\u2019t in any way connected to our commercial datacenters. Government information is kept only within these separate datacenters, which are built with the most stringent security controls that meet the CJIS security policy and other government security requirements. By developing a separate government cloud, we\u2019ve provided an important layer of protection for law enforcement agencies.<\/p>\n Another way in which our approach differs from our competitors is that Microsoft is transparent about how it\u2019s meeting CJIS security policy requirements<\/b>. At Microsoft, we openly share our security strategy<\/a> so that government leaders and security experts can evaluate the strength of our commitments. This isn\u2019t the case with some of the other cloud providers on the market. For example, Amazon requires customers to sign a non-disclosure agreement to start a CJIS compliance discussion. This doesn\u2019t do much to increase government confidence in the cloud. We believe security commitments should be transparent.<\/p>\n Law enforcement agencies recognize Microsoft\u2019s commitment to security, and they\u2019ve been responding. Roughly 3 million entities now use the Microsoft Cloud for Government, many of which are law enforcement agencies. Moreover, third-party vendors\u2014from VIEVU to NC4 to PublicEye\u2014have been building new solutions on the Microsoft Azure government platform<\/a> in large part because of our industry-leading commitment to security.<\/p>\n At Microsoft, we understand that compliance with the CJIS security policy is a crucial priority for law enforcement agencies across the US. It\u2019s not just a check box, but an ongoing commitment\u2014one that we take very seriously.<\/p>\n