Back to Search Start Over

Is My Office 365 GDPR Compliant? : Security Issues in Authentication and Administration

Authors :
Tessa Viitanen
Nestori Syynimaa
Hammoudi, Slimane
Smialek, Michal
Camp, Olivier
Filipe, Joaquim
Source :
ICEIS (2)
Publication Year :
2018
Publisher :
SCITEPRESS Science And Technology Publications, 2018.

Abstract

The General Data Protection Regulation, commonly referred as GDPR, will be enforced in all European Union countries in May 2018. GDPR sets requirements for processing EU citizens’ personal data regardless of the physical location of the organisation processing the data. Over 40 percent of European organisations are using Office 365. Microsoft claims that Office 365 service is GDPR compliant, and has provided tools to help Office 365 customers to ensure their GDPR compliancy. In this paper, we present some security issues related to the very foundation of Office 365 service, namely Azure Active Directory and administrative tools, and assess their GDPR compliancy. Our findings reveal that personal data stored in Office 365 is subject to undetectable security breaches, preventing organisations to be GDPR compliant. We also propose actions to take to minimise the impact of the security issues. peerReviewed

Details

Language :
English
Database :
OpenAIRE
Journal :
ICEIS (2)
Accession number :
edsair.doi.dedup.....19531f7586c588c9e687a876c8b79336