M365EXO-050: DLP restricts sharing of SSN, ITIN, and credit-card numbers (MS.EXO.8.4)

Plataforma
Entra ID / M365
Categoría
Advanced Threat Protection
Severidad
High
Pilar de Zero Trust
Data (peso 2)
Fixtures de referencia
5
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

SCuBA MS.EXO.8.4 requires that the Data Loss Prevention solution, at a minimum, restrict sharing of credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security Numbers (SSN) via email. This check inspects the DLP compliance rules collected from the tenant and confirms at least one enabled rule references each of those three sensitive information types. It reads DLP rules (not just policies); because Get-DlpComplianceRule cannot distinguish an unconfigured DLP solution from one that could not be read, an absent or empty rule set is reported as Not Assessed rather than a failure or a pass. A FAIL is only returned when rules are present but demonstrably do not cover one of the three required types.

Valor recomendado

At least one enabled DLP rule each for U.S. SSN, U.S. ITIN, and Credit Card Number sensitive information types, scoped to Exchange email

Remediación

In the Microsoft Purview compliance portal under Data loss prevention > Policies, create or extend a policy scoped to the Exchange email location with rules that detect the Credit Card Number, U.S. Social Security Number (SSN), and U.S. Individual Taxpayer Identification Number (ITIN) sensitive information types, and set the action to block or restrict external sharing. Enable the policy (not test mode) so the rules are enforced.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de M365EXO-050
EscenarioVeredicto esperado
cleanPASS
emptyNot Assessed
no-dataNot Assessed
not-assessedNot Assessed
partialFAIL

Mapeos a marcos de referencia

NIST SP 800-53
SC-7, SI-4, AC-4