To help with your assessment needs, Microsoft has released the Office 365 Service Trust Portal (STP). STP is a service feature in Office 365 designed to provide deeper information on how Microsoft manages security, compliance and privacy.
Through the STP you can get direct access to a wide variety of compliance reports and trust resources, including:
- Office 365 SOC 1 / SSAE 16 / ISAE 3402 Independent Audit Reports
- Office 365 SOC 2 / AT 101 Independent Audit Report
- Office 365 ISO 27001 (including 27018 controls) Independent Audit Report
- Various compliance reports, such as Office 365 Information Security Management System (ISMS)
- Various GRC and Trust resources, such as whitepapers, FAQs, security assessment, risk assessment and other reports that will help you perform your own risk assessment
Access office blogs for more information