3.2 Ensure SharePoint Online data classification policies are set up and used

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

You should set up and use SharePoint Online data classification policies on data stored in your SharePoint Online sites.

Rationale:

The policies will help categorize your most important data so you can effectively protect it from illicit access, and will help make it easier to investigate discovered breaches.

Impact:

Creation of data classification policies will not cause a significant impact to an organization. However, ensuring long term adherence with policies can potentially be a significant training and ongoing compliance effort across an organization. Organizations should ensure that training and compliance planning is part of the classification policy creation process.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set up data classification policies, use the Microsoft 365 Admin Center:

Under Admin centers select Security to open the Microsoft 365 Security Center.

Expand Classification then choose Sensitivity labels.

Click Create label to create a label.

See Also

https://workbench.cisecurity.org/files/3433