M365EXO-025: DLP protects PII and sensitive data types (MS.EXO.8.2)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
High
Zero Trust pillar
Data (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.8.2 requires that the DLP solution protect PII and sensitive information, restricting at minimum the sharing of credit card numbers, Taxpayer Identification Numbers, and Social Security numbers via email. A DLP solution that exists but does not detect these high-value identifiers fails to prevent the most damaging classes of inadvertent disclosure.

Recommended value

DLP policy includes sensitive information types covering credit card numbers, TIN, and SSN with a restrict/block action for email

Remediation

Configure the DLP policy that covers Exchange Online to detect the sensitive information types for credit card numbers, Taxpayer Identification Numbers, and Social Security numbers, plus any additional agency-defined PII. Set the rule action to block or restrict outbound mail containing these identifiers. Test with sample data to confirm detection and that user notifications and incident reports are generated.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-025
ScenarioExpected verdict
known-badFAIL
presentWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-4, SC-7, MP-6
MITRE ATT&CK
T1048