2.1.13 Ensure all security threats in the Threat protection status report are reviewed at least weekly

Information

The Threat protection status report shows specific instances of Microsoft blocking a malware attachment from reaching users, phishing being blocked, impersonation attempts, etc. The Threat protection status report should be reviewed at least weekly.

Rationale:

While this report isn't strictly actionable, reviewing it will give a sense of the overall volume of various security threats targeting users, which may prompt adoption of more aggressive threat mitigations.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the Threat protection status report:

Navigate to Microsoft 365 Defender https://security.microsoft.com.

Click to expand Email & collaboration select Review.

Select Malware trends.

On the Threat Explorer page, select All email and review statistics.

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-6, 800-53|AU-6(1), 800-53|AU-7(1), CSCv7|6.2

Plugin: microsoft_azure

Control ID: 5fb6cb29bb91a449d350cb86f93ef4205db70ab8f4bd2142644db0b118f73014