author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/27/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
## Supported certifications
Global Secure Access is included in several Azure compliance audits. The supported certifications are:
| Certification | Details | Inherited from | Status |
| --- | --- | --- | --- |
| Canadian Privacy Laws | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canada privacy laws](/azure/compliance/offerings/offering-canada-privacy-laws). | ISO 27001:2013 | |
| CDSA | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [CDSA](/azure/compliance/offerings/offering-cdsa). | ISO 27001:2013 | Certification available |
| CSA STAR | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [Cloud Security Alliance (CSA) STAR Certification](/azure/compliance/offerings/offering-csa-star-certification). | ISO 27001:2013 | |
| DoD DISA SRG Level 2 | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [Department of Defense (DoD) Impact Level 2 (IL2)](/azure/compliance/offerings/offering-dod-il2). | FedRAMP High | |
| EAR | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [Export Administration Regulations (EAR)](/azure/compliance/offerings/offering-ear). | FedRAMP High | |
| FedRAMP High | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [Federal Risk and Authorization Management Program (FedRAMP)](/azure/compliance/offerings/offering-fedramp). | NA | |
| FIPS 140-2 | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [Federal Information Processing Standard (FIPS) 140](/azure/compliance/offerings/offering-fips-140-2). | FedRAMP High | |
| GDPR | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [General Data Protection Regulation summary](/compliance/regulatory/gdpr). | ISO 27001:2013 | |
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/29/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
## Supported certifications
Global Secure Access is included in several Azure compliance audits. The supported certifications are:
| Certification | Details | Inherited from |
| --- | --- | --- |
| Canadian Privacy Laws | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canada privacy laws](/azure/compliance/offerings/offering-canada-privacy-laws). | ISO 27001:2013 |
| CDSA | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [CDSA](/azure/compliance/offerings/offering-cdsa). | ISO 27001:2013 |
| CSA STAR | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [Cloud Security Alliance (CSA) STAR Certification](/azure/compliance/offerings/offering-csa-star-certification). | ISO 27001:2013 |
| DoD DISA SRG Level 2 | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [Department of Defense (DoD) Impact Level 2 (IL2)](/azure/compliance/offerings/offering-dod-il2). | FedRAMP High |
| EAR | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [Export Administration Regulations (EAR)](/azure/compliance/offerings/offering-ear). | FedRAMP High |
| FedRAMP High | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [Federal Risk and Authorization Management Program (FedRAMP)](/azure/compliance/offerings/offering-fedramp). | NA |
| FIPS 140-2 | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [Federal Information Processing Standard (FIPS) 140](/azure/compliance/offerings/offering-fips-140-2). | FedRAMP High |
| GDPR | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [General Data Protection Regulation summary](/compliance/regulatory/gdpr). | ISO 27001:2013 |