Module 5cb - Identity, Governance, Privacy and Compliance - Privacy, Azure Government Flashcards
How does Azure address security and compliance wrt Azure Government?
Physical isolation from non-US Government (Public) cloud, which addresses all security and compliance needs for each level of Government
Hint: Six of them…
What regulations and requirements are Azure Government data-handling services subject to?
- FedRAMP (Federal Risk & Authorization Mgmt Program)
- NIST 800.171 Defense Industrial Base (Nat. Inst. of Standards and Tech)
- ITAR (Int. Traffic in Arms Reg)
- IRS 1075
- DoD L4
- CJIS (Criminal Justice Info Service)
What are three major differences between Azure and Azure Government?
- Az Gov is physically segregated from public Azure
- Az Gov has different endpoints for services (.us vs .com)
- The following are NOT AVAILABLE in Az Gov:
Cognitive/AI:
- Bot Service
- Cognitive: Content Moderator
- Cognitive: Language Understanding (LUIS)
- Cognitive: Translator
Open Source-based:
- Azure K8s
- Azure MySql
Recommendation Features in Azure Advisor, Cost Management, Azure Lighthouse, Azure Monitor, Azure Migrate, and a host of others
What’s the process and calculation for right-sizing VMs in Azure Government?
- Advisor monitors VM usage for 7 days to identify low-utilization machines
- Low Utilization == CPU <= 5% + Network Utilization < 2%, OR if the workload can be accommodated by a smaller VM size
Hint: There are eight (DoD, Gov, Sec)
What are the eight (8) Azure Government Regions?
- US DoD Central
- US DoD East
- US Gov AZ
- US Gov TX
- US Gov VA
- US Sec East
- US Sec West
- US Sec West Central
Azure Government is PCI DSS compliant (i.e. are certified to process and store payment information and related data) (T/F)?
True
What are two (2) personnel security requirements for using Azure Government?
- Screened US Personnel only
- Level 5 DoD approval
What is Azure China 21Vianet?
All data transactions involving Chinese private data, corporate data, financial data, etc. are required to go through China’s state controlled ISP 21Vianet (Shanghai Blue Cloud Technology Co., Ltd).
What are cloud service providers required to have from Azure China 21Vianet and China Telecom Regulations?
According to the China Telecom Regulation, all providers of cloud services, IaaS, PaaS must have Value-Added Telecom Permits
Azure China requires all providers of Cloud Services to have Value-Added Telecom Permits. What is the minimum qualification for those permits?
Must be a *locally registered* company with LESS than 50% foreign investment
All Azure services are available in Azure China 21Vianet (T/F)?
What’s required from Customers who use those Services?
True.
Customers are required to sign agreements/contracts with 21Vianet.
To host your applications in China you need only deploy the same services and such in Azure China 21Vianet (via ARM Templates) (T/F)? Why? (Two things)
False.
- Even if you already use Azure services, you may need to actually REHOST IN THEIR REGIONS or even refactor some or all your applications
- Your customers may need to sign additional contracts with 21Vianet