2.1.13 Ensure all security threats in the Threat protection status report are reviewed at least weekly

Information

The Threat protection status report shows specific instances of Microsoft blocking a malware attachment from reaching users, phishing being blocked, impersonation attempts, etc. The Threat protection status report should be reviewed at least weekly.

Rationale:

While this report isn't strictly actionable, reviewing it will give a sense of the overall volume of various security threats targeting users, which may prompt adoption of more aggressive threat mitigations.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the Threat protection status report:

Navigate to Microsoft 365 Defender https://security.microsoft.com.

Click to expand Email & collaboration select Review.

Select Malware trends.

On the Threat Explorer page, select All email and review statistics.

See Also

https://workbench.cisecurity.org/benchmarks/12934