3.2.1 Ensure DLP policies are enabled

Information

Data Loss Prevention (DLP) policies allow Exchange Online and SharePoint Online content to be scanned for specific types of data like social security numbers, credit card numbers, or passwords.

Rationale:

Enabling DLP policies alerts users and administrators that specific types of data should not be exposed, helping to protect the data from accidental exposure.

Impact:

Enabling a Teams DLP policy will allow sensitive data in Exchange Online and SharePoint Online to be detected or blocked. Always ensure to follow appropriate procedures in regard to testing and implementation of DLP policies based on organizational standards.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable DLP policies:

Navigate to Microsoft Purview https://compliance.microsoft.com.

Under Solutions select Data loss prevention then Policies.

Click Create policy.

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-11, 800-53|SI-12, CSCv7|13, CSCv7|14.7

Plugin: microsoft_azure

Control ID: 3cb440b5b96c5f04fd462fe453a85f3fbb91f7c048cacf461246dc64a2243312