Managed Cloud security overview

Version:

The security model for Sitecore Managed Cloud provides control over information and resources. Sitecore customers on Managed Cloud own the data and can apply changes to the Managed Cloud environment. This also means that customers are responsible for the confidentiality, integrity, and availability of Sitecore Managed Cloud resources and data.

The Sitecore Managed Cloud security model

The following tables indicate the roles and responsibilities associated with the various security functions in Sitecore Managed Cloud using the key responsibility roles of the RACI model. In the Production environment and Nonproduction environment columns, the value Sitecore can also refer to a Service provider and the value Customer can also refer to a Partner.

Production environmentNonproduction environment
SitecoreCustomerSitecoreCustomer
AKSR, AIR, AI
Default Network ControlsR, AIR, AI
Define Custom Network Controls Requirements in AzureR, ARR, AR
Implement Custom Network Controls in AzureR, ARR, AR
Sitecore Application ProductR, ACR, AC
Sitecore Application CodeRR, ARR, A
Identity and Directory Infrastructure including account administrationRR, ARR, A
CloudflareR, ARR, AR
Basic Firewall RequirementsR, ACR, AC
Firewall Monitoring and AlertingR, ARRR, A
Notification of security events related to the Azure platformR, ACR, AC
Notification of security events related to the Azure platform (When Sitecore is made aware by MSFT)R, AIR, AI
Define Environment access permissions and security configurationR, ARR,AR
Implement customer defined environment access and security configurationR, ARR, AR
Initial deployment security hardening of Sitecore productR, ACR, AC
Ongoing security hardening of Sitecore applicationRR, ARR, A
Patching of base images for Sitecore roles and made available in container registryCR, ACR, A
Deployment of Sitecore hotfixes, patches, and upgradesRR, ARR, A
Security monitoring of Azure environmentR, ARR, AR
Obtain Public SSL certificates from Trusted Root AuthorityCR, ACR, A
SSL certificate DeploymentRARA

Privacy and data protections laws

In Sitecore Managed Cloud, we process the data that we receive from our customers. In GDPR terminology, we are a Data Processor. Under the CCPA, we are a Service Provider. Accordingly, we have Data Processor Agreements with the relevant clauses in place with our customers to ensure compliance.

For more information, please visit our Trust Center.

Cloud operations procedures

Sitecore’s Cloud operations procedures include formal standards for the following:

  • Customer onboarding, including the creation of user accounts.
  • Infrastructure resource creation and set up.
  • Data creation and set up.
  • Disposal standards to securely delete infrastructure resources.
  • Data disposal standards.
  • Capacity management to identify capacity and availability-related issues.
  • Issues and event management.
If you have suggestions for improving this article, let us know!