Microsoft compliance solutions Flashcards
What are the three types of controls used in Microsoft Purview Compliance Manager?
Microsoft managed controls
Shared controls
customer managed controls
What does the compliance score in Compliance Manager measure?
an organization’s progress toward implementing controls
What is an assessment in Compliance Manager?
a grouping of controls from a specific regulation, standard or policy
Microsoft Service Trust Portal
official source for information on how Microsoft manages privacy, compliance, and security for its cloud services. It provides detailed documentation, whitepapers, certifications and risk assessments
Microsoft 365 Compliance Center
this is primarily for managing compliance within your organization using Microsoft 365 tools
Compliance Manager is deprecated
Content Explorer
shows a current snapshot of items that are either classified as a sensitive information type or have a sensitive label, or a retention label.
In order to view a snapshot of your organization’s scanned classified documents in SharePoint and OneDrive you need to be assigned which two role groups?
Content Explorer List Viewer (can only view the item and its location, not the contents)
Content Explorer Content Viewer (can view the sensitive information in plaintext)
You need both!
Microsoft Purview Compliance Portal
Easy access to the data and tools you need to manage your organization’s compliance needs
Compliance Manager
simplifies compliance and reduce risk by providing the following:
-prebuilt assessments based on common standards
-workflow capabilities to complete risk assessments
-step by step improvement actions
-compliance score, which shows the overal compliance posture
Compliance Manager is the first menu item in the Microsoft Purview compliance portal!
Microsoft Purview Audit (Standard)
Helps organizations respond effectively to security events, forensic investigations, internal investigation and compliance obligations
Standard
-log and search for audited activities
-enabled by default
-thousands of searchable audit events
90-day default retention period
-access by GUI, cmdlet, and API
Microsoft Purview Audit (Premium)
Helps organizations respond effectively to security events, forensic investigations, internal investigations and compliance obligations
Premium
-can be used to investigate possible security or compliance breaches and identify their scope based on records
-Builds on Standard with 1 year retention
-customized retention period
-customized retention policies
-intelligent insights
-higher bandwidth access to API
Microsoft Purview eDiscovery
The process of identifying and delivering electronic information that can be used as evidence in legal cases.
There is
Content Search
eDiscovery (Standard)
eDiscovery (Premium)
The cord eDiscovery workflow is…
1) Creating eDiscovery holds (to preserve content relevant to a case so nobody can delete them) HOLDS!
2) Search for content (related to an investigation) SEARCHES!
3) Export and download search results (so that people outside the investigation team can review) EXPORTS!
What is the workflow for Advanced eDiscovery?
1) Add custodians to a case
2) Search custodial sources for relevant data
3) Add data to a review set
4) Review and analyze data
5) Export and download the case data
eDiscovery Manager role group
Members of this role group can create and manage eDiscovery cases. They can also add and remove members, place an eDiscovery hold on users, create and edit searches, and export content from an eDiscovery case
eDiscovery Content Search
Used to search documents
Search for Content
Keyword queries and search conditions
Export search results
role-based permissions
Used to quickly find email in Exchance mailboxes, documents in SharePoint, OneDrive locations and messages in Teams
Microsoft Purview eDiscovery (Standard)
Allows you to create cases and assign managers, not auditing
Search and export
Case management
legal hold
eDiscovery (Premium)
all the things Standard does but allows you to assign custodians
allows you to collect and copy data into review sets, where you can filter, search and tag content so you can identify and focus on content that is most relevant
custodian management
legal hold notifications
advanced indexing
review set filtering
tagging
analytics
predictive coding models
Advanced Auditing
Advanced Auditing helps organizations to conduct forensic compliance investigations by providing acces to these crucial events
Crucial events include when mail items were accessed, when mail items were replied to and fowarded
You wont be able to access crucial events with Core Auditing
Microsoft Purview Data Map
able to capture metadata about enterprise data, to identify and classify sensitive data
Microsoft Purview Insider Risk Management
a solution that helps minimize internal risks by enabling an organization to detect, investigate and act on risky and malicious activities
Insider Risk Management Principles
Transparency
Configurable
Integrated
Actionable
Microsoft Purview Communcation Compliance
An Insider Risk solution that helps you detect, capture, and act on inappropriate messages that can lead to potential data security or compliance incidents within your organization
Auditing Solutions in Microsoft Purview
helps organizations effectively respond to security events, forensic investigations, internal investigations and compliance obligations
Audit (Standard)
Audit (Premium)