M365EXO-025: DLP protects PII and sensitive data types (MS.EXO.8.2)

Plataforma
Entra ID / M365
Categoría
Advanced Threat Protection
Severidad
High
Pilar de Zero Trust
Data (peso 2)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

SCuBA MS.EXO.8.2 requires that the DLP solution protect PII and sensitive information, restricting at minimum the sharing of credit card numbers, Taxpayer Identification Numbers, and Social Security numbers via email. A DLP solution that exists but does not detect these high-value identifiers fails to prevent the most damaging classes of inadvertent disclosure.

Valor recomendado

DLP policy includes sensitive information types covering credit card numbers, TIN, and SSN with a restrict/block action for email

Remediación

Configure the DLP policy that covers Exchange Online to detect the sensitive information types for credit card numbers, Taxpayer Identification Numbers, and Social Security numbers, plus any additional agency-defined PII. Set the rule action to block or restrict outbound mail containing these identifiers. Test with sample data to confirm detection and that user notifications and incident reports are generated.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de M365EXO-025
EscenarioVeredicto esperado
known-badFAIL
presentWARN
throttledNot Assessed

Mapeos a marcos de referencia

NIST SP 800-53
SI-4, SC-7, MP-6
MITRE ATT&CK
T1048