M365EXO-050: DLP restricts sharing of SSN, ITIN, and credit-card numbers (MS.EXO.8.4)
- Plataforma
- Entra ID / M365
- Categoría
- Advanced Threat Protection
- Severidad
- High
- Pilar de Zero Trust
- Data (peso 2)
- Fixtures de referencia
- 5
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA MS.EXO.8.4 requires that the Data Loss Prevention solution, at a minimum, restrict sharing of credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security Numbers (SSN) via email. This check inspects the DLP compliance rules collected from the tenant and confirms at least one enabled rule references each of those three sensitive information types. It reads DLP rules (not just policies); because Get-DlpComplianceRule cannot distinguish an unconfigured DLP solution from one that could not be read, an absent or empty rule set is reported as Not Assessed rather than a failure or a pass. A FAIL is only returned when rules are present but demonstrably do not cover one of the three required types.
Valor recomendado
At least one enabled DLP rule each for U.S. SSN, U.S. ITIN, and Credit Card Number sensitive information types, scoped to Exchange email
Remediación
In the Microsoft Purview compliance portal under Data loss prevention > Policies, create or extend a policy scoped to the Exchange email location with rules that detect the Credit Card Number, U.S. Social Security Number (SSN), and U.S. Individual Taxpayer Identification Number (ITIN) sensitive information types, and set the action to block or restrict external sharing. Enable the policy (not test mode) so the rules are enforced.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| empty | Not Assessed |
| no-data | Not Assessed |
| not-assessed | Not Assessed |
| partial | FAIL |
Mapeos a marcos de referencia
- NIST SP 800-53
- SC-7, SI-4, AC-4