3.2 Ensure SharePoint Online data classification policies are set up and used

Information

You should set up and use SharePoint Online data classification policies on data stored in your SharePoint Online sites.

Rationale:

The policies will help categorize your most important data so you can effectively protect it from illicit access, and will help make it easier to investigate discovered breaches.

Impact:

Creation of data classification policies will not cause a significant impact to an organization. However, ensuring long term adherence with policies can potentially be a significant training and ongoing compliance effort across an organization. Organizations should ensure that training and compliance planning is part of the classification policy creation process.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set up data classification policies, use the Microsoft 365 Admin Center:

Under Admin centers select Security to open the Microsoft 365 Security Center.

Expand Classification then choose Sensitivity labels.

Click Create label to create a label.

See Also

https://workbench.cisecurity.org/files/3433