Compliance Tools in Microsoft 365 Flashcards
(HIPAA) Act that imposes strict privacy regulations on protected health information.
Health Insurance Portability Act
(FISMA) Act that dictates how United States federal agencies protect information.
Federal Information Security Modernization Act
(GDPR) Regulation that gives rights to people to manage personal data collected by an organization.
General Data Protection Regulation
(FERPA) Act that covers the use or disclosure of student education records.
The Family Educational Rights and Privacy Act
(PIPEDA) Act that addresses how private sector organizations collect, use, and disclose personal information.
The Personal Information Protection and Electronic Documents Act
(GLBA) Act that protects nonpublic personal information.
The Gramm-Leach-Bliley Act
- Assess
- Protect
- Respond
Three Phases of Compliance Management
365 Feature that assists with security, privacy, and compliance and helps with understanding an organizations compliance regulations.
Service Trust Portal (STP)
Dashboard of organizational data standards, regulations, and assessments.
Compliance Manager
Audit reports, data protection info, and info on 365 features.
Trust Documents
The name for keeping documents when you need them and getting rid of them when you don’t.
Data Governance
Users don’t get default permissions to perform a privileged task.
Zero Standing Access
Search tool that allows you to review and redact content.
eDiscovery
Capabilities of ________________
- Ongoing Risk Assessment
- Actionable Insights
- Simplified Compliance
Compliance Manager (3)
Encrypting data at rest on a physical disk.
BitLocker
Encrypting data in transit at the Transportation layer on the network.
TLS
Before access to tenant data is granted to a Microsoft engineer, approval is required from the tenant admin.
Customer Lockbox
Oversight of access requests through logging and an approval process in Microsoft 365.
Privileged Access Management
A specialized 365 workspace for compliancy, privacy, and risk management helping you assess risks, protect and govern data with sensitivity and retention labels, respond to regulatory requests, and access compliance solutions.
Compliance Center
Which Azure AD service tier includes only the following:
- SSO
- MFA
- Basic Reports
- Business-to-business collaboration
Azure AD Free
Which Azure AD service tier includes all free features plus the following:
- Self-service password reset
- Device write-back
Microsoft 365
Which Azure AD service tier includes all 365 features plus the following:
- Conditional Access
- Microsoft Cloud App Discovery
- Advanced Reports
- Group access management
- Hybrid identities
Premium 1