3.2 Ensure SharePoint Online Information Protection policies are set up and used

Information

You should set up and use SharePoint Online data classification policies on data stored in your SharePoint Online sites.

Rationale:

The policies will help categorize your most important data so you can effectively protect it from illicit access, and will help make it easier to investigate discovered breaches.

Impact:

Creation of data classification policies will not cause a significant impact to an organization. However, ensuring long term adherence with policies can potentially be a significant training and ongoing compliance effort across an organization. Organizations should ensure that training and compliance planning is part of the classification policy creation process.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set up data classification policies, use the Microsoft 365 Admin Center:

Under Admin centers select Compliance to open the Microsoft Purview compliance portal.

Under Solutions click Information protection

Select Labels tab

Click Create a label to create a label.

Select the label and click on the Publish label

Fill out the forms to create the policy.

See Also

https://workbench.cisecurity.org/files/4073