From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Design DLP policies based on an organization’s requirements - Microsoft 365 Tutorial
From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Design DLP policies based on an organization’s requirements
Before you create DLP policies, you first have to determine what data must be protected and why. So we already touched on this when we were talking about sensitive information. So really, realistically, you would probably do all of these things together. So you would start reviewing all the compliance regulations your organization falls under, So maybe GDPR for personal data, PCI DSS for credit card data. And those laws and rules are going to define the specific categories of sensitive information that you have to include in your DLP coverage. In parallel, you should be talking to your internal stakeholders. Talk to legal about confidentiality requirements. You can talk to HR about employee data, finance about your financial records. They can tell you which information is considered sensitive, and how is it used? As you gather this information, you can create an inventory of sensitive data types and locations. And then you can map out where that data's stored or transmitted. And for…
Contents
-
-
-
-
-
-
(Locked)
Module introduction1m 9s
-
(Locked)
Learning objectives1m 12s
-
(Locked)
Design DLP policies based on an organization’s requirements3m 30s
-
(Locked)
Implement roles and permissions for DLP3m 16s
-
(Locked)
Create and manage DLP policies5m 40s
-
(Locked)
Configure DLP policies for Adaptive Protection5m 31s
-
(Locked)
Interpret policy and rule precedence in DLP5m 26s
-
(Locked)
Create file policies in Microsoft Defender for Cloud Apps by using a DLP policy5m 6s
-
(Locked)
-
-
-
-
-
-