3.4 Ensure DLP policies are enabled

Information

Enabling Data Loss Prevention (DLP) policies allows Exchange Online and SharePoint Online content to be scanned for specific types of data like social security numbers, credit card numbers, or passwords.

Rationale:

Enabling DLP policies alerts users and administrators that specific types of data should not be exposed, helping to protect the data from accidental exposure.

Impact:

Enabling a Teams DLP policy will allow sensitive data in Exchange Online and SharePoint Online to be detected or blocked. Always ensure to follow appropriate procedures in regards to testing and implementation of DLP policies based on your organizational standards.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable DLP policies, use the Microsoft 365 Admin Center:

Under Admin centers Select Compliance.

From the Microsoft 365 compliance center expand Data loss prevention then choose Policies.

Click Create a policy.

See Also

https://workbench.cisecurity.org/files/3433