When evaluating Microsoft cloud services for alignment with US government regulatory compliance, it’s useful to have an online reference to understand how Microsoft categorizes the services it audits & what the opportunity for compliance is that Microsoft offers on a per-regulatory & per-service category level.
For example, for State & Local Government, Microsoft 365 GCC offers the opportunity for compliance with regulations such as:
- FBI CJIS – Law Enforcement, Justice
- IRS Tax 1075 – Finance, Tax
- FedRAMP Mod/High- Public Utilities (Power, Water)
- NERC/CIP – Public Utilities (Power)
Richard Wakeman, US Public Sector Specialist (Federal & Defense Industry Base) maintains online documentation year after year on Microsoft’s aggregate cloud services alignment with State & Local Government compliance requirements:
This article is the second of a series in the Microsoft Tech Community Public Sector Blog and touches on several key principles for compliance, including data residency versus data sovereignty. For the first article in the series, please refer to History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government. To keep this article concise, I will refrain from repeating content from the first. I recommend that you review the first article if you are unfamiliar with the architectural relationships between Azure, Microsoft 365 and Dynamics 365.In this article, we will focus on each of the US-based cloud offerings from Microsoft and compare the differences in compliance, including the compendium of common factors customers may use to decide which of our offerings align with current and future requirements in demonstrating compliance with US Government regulations and underlying cybersecurity frameworks.
Read the article in its entirety at:
- Understanding Compliance Between Commercial, Government, DoD & Secret Offerings
https://aka.ms/MSGovCompliance


You must be logged in to post a comment.