3.2 Ensure SharePoint Online Information Protection policies are set up and used

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

You should set up and use SharePoint Online data classification policies on data stored in your SharePoint Online sites.

Rationale:

The policies will help categorize your most important data so you can effectively protect it from illicit access, and will help make it easier to investigate discovered breaches.

Impact:

Creation of data classification policies will not cause a significant impact to an organization. However, ensuring long term adherence with policies can potentially be a significant training and ongoing compliance effort across an organization. Organizations should ensure that training and compliance planning is part of the classification policy creation process.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set up data classification policies, use the Microsoft 365 Admin Center:

Under Admin centers select Compliance to open the Microsoft 365 compliance center.

Under Solutions click Information protection

Select Labels tab

Click Create a label to create a label.

Select the label and click on the Publish label

Fill out the forms to create the policy.

See Also

https://workbench.cisecurity.org/files/3729