{"id":11169,"date":"2016-04-21T15:14:04","date_gmt":"2016-04-21T22:14:04","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=11169"},"modified":"2023-06-16T15:58:47","modified_gmt":"2023-06-16T22:58:47","slug":"monitoring-and-protecting-sensitive-data-in-office-365","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/monitoring-and-protecting-sensitive-data-in-office-365\/","title":{"rendered":"Monitoring and protecting sensitive data in Office 365"},"content":{"rendered":"
\n
\n
<\/div>\n

This content has been archived, and while it was correct at time of publication, it may no longer be accurate or reflect the current situation at Microsoft.<\/p>\n<\/div>\n<\/div>\n

Microsoft IT created a solution to manage the risk of sharing sensitive data, while still promoting collaboration in Office 365. Power BI dashboards give insight into how Microsoft corporate users share information. This solution detects sensitive data sharing and helps Microsoft IT proactively manage and respond to information security risks.<\/p>\n

With Office 365, Microsoft corporate users can access and share data from anywhere, on any device, and be more productive by using all of its collaboration features. On the other hand, it\u2019s easier to inadvertently share sensitive information with others both inside and outside of the company.<\/p>\n

To manage security risk, Microsoft IT created a solution that uses the Office 365 Management Activity API and the data loss prevention (DLP) features of Office 365. The solution gathers data about sharing from Microsoft Exchange Online, SharePoint Online, OneDrive for Business, and Azure Active Directory. It also includes a custom governance solution to help protect data. Microsoft Power BI dashboards visualize the data to show how Microsoft corporate users share information.<\/p>\n

The dashboards help answer four business questions that have direct business impact on risk, and the answers help leadership make decisions that reduce risk. Microsoft IT uses an agile process to answer these questions:<\/p>\n

    \n
  1. Which sites are capable of external sharing?<\/li>\n
  2. What is the classification of externally shared sites?<\/li>\n
  3. Which files are shared externally?<\/li>\n
  4. What operations are performed by external users on those externally shared files?<\/li>\n<\/ol>\n

    Microsoft IT tests hypotheses about how various policies and programs might improve users\u2019 sharing behavior and then check the dashboards to see if the behavior has changed. Besides dashboards, the solution improves sharing behavior by giving users visual cues about appropriate sharing. The solution automatically sends email to users who violate security policies by sharing too much, asking them to change their behavior. This helps manage and respond to information security risks.<\/p>\n

    Information security policies<\/h2>\n

    To protect valuable intellectual property, Microsoft has corporate policies for handling and sharing data. Using business rules based on these policies, the solution detects and reports when users share documents and if the sharing is in or out of compliance with the rules. For example, Microsoft data handling policy states that sensitive business information must be encrypted both at rest and in flight. And, when shared externally, users are accountable for who they share it with.<\/p>\n

    The solution audits the following types of sharing:<\/p>\n

    Regulated information<\/strong>. Regulated information includes government identification numbers such as social security numbers and passport numbers, financial data such as credit card numbers and financial records, or medical information. Regulated information must always be protected by encryption.<\/p>\n

    Business information<\/strong>. At Microsoft, sensitive business information is called High Business Impact (HBI) data. Users can store HBI data on SharePoint Online and OneDrive for Business if they comply with Microsoft policies for HBI data storage and transmission; however, to share HBI content externally, users must get a policy exception from the Microsoft IT security and privacy team.<\/p>\n

    Low Business Impact (LBI) and Medium Business Impact (MBI) data is permitted on SharePoint Online and OneDrive for Business with no special approval. Users must review all classifications to understand how to classify, protect, and handle data that they create, and ensure that it is properly categorized for use at Microsoft.<\/p>\n

    How users share too much<\/h3>\n

    Inappropriate sharing occurs when users make information accessible to others in a way that violates information security policies. There\u2019s rarely malicious intent behind inappropriate data sharing. Rather, the main reasons for it are:<\/p>\n