M365SPO-005: DLP policy configuration
- Plataforma
- Entra ID / M365
- Categoría
- SharePoint & OneDrive Security
- Severidad
- High
- Pilar de Zero Trust
- Data (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
Data Loss Prevention policies in SharePoint Online and OneDrive detect and protect sensitive information such as personally identifiable information, financial data, and health records from being shared inappropriately. Without DLP policies, users can inadvertently share documents containing sensitive data with external users or through unmonitored channels. DLP policies provide automated detection, user notification, and blocking of sensitive data exposure.
Valor recomendado
DLP policies configured for all regulated data types with user notifications and sharing blocks for external sharing of sensitive content
Remediación
Create DLP policies targeting SharePoint Online and OneDrive locations that detect sensitive information types relevant to your regulatory requirements such as PII, PCI, or HIPAA data. Configure policy rules to display user notifications with guidance on proper handling when sensitive content is detected, and block external sharing of documents containing high-sensitivity data. Enable incident reports to notify the compliance team of policy matches and review the DLP activity reports to tune policy accuracy and reduce false positives.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- MS.DEFENDER.4.1v1
- NIST SP 800-53
- AC-4, SC-7