CollabDays Bletchley Park 2024 - Compliance Manager

appie1701 52 views 25 slides Sep 25, 2024
Slide 1
Slide 1 of 25
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25

About This Presentation

Did you know that with your Microsoft 365 enterprise license, you get a complete Information Security Management System or ISMS? Yes, you do and it's known as Microsoft Purview Compliance Manager.

But the Compliance Manager goes beyond this. As an ISMS you are able to use the Compliance Manager...


Slide Content

A hidden gem: Microsoft Purview Compliance Manager Albert Hoitingh

Thank you to our sponsors!

Albert Hoitingh Principal Consultant Data Security & Compliance @ InSpark The Hague – The Netherlands @alberthoitingh https://alberthoitingh.com https://www.linkedin.com/in/appieh/

Microsoft Purview Compliance Manager

Microsoft Purview Compliance Manager Take inventory Implement controls and report Multi-cloud Stay current with regulation

Licensing All subscriptions: Data Protection Baseline Microsoft 365 E5: Three premium regulations free Premium regulations https://learn.microsoft.com/en-us/purview/compliance-manager-templates-list

Permission levels Azure/Entra ID Read only Global Reader | Security Reader Edit data only Compliance Administrator Edit data and create assessments Compliance Administrator Manage all Compliance Administrator Compliance Data Administrator Security Administrator

Permission levels Microsoft Purview Read only Compliance Manager Reader Edit data only Compliance Manager Assessor Edit data and create assessments Compliance Manager Contribution Manage all Compliance Manager Administrator Compliance Administrator Specific permissions, per regulation for example

Key elements Controls Assessments Regulations Improvement actions Technical Operational Documentation

Copilot…. Oh wait….

Shared Responsibility

Compliance Score Improvement actions Mandatory Discretionary Preventive | Detective | Corrective

S coring Preventive Detective Corrective Mandatory Discretionary Points +27 Points +9 Points +1 Points +3 Points +1 Points +3

Testing Manual | Automatic Automatic based on settings in Purview (Compliance Administrator) – based on assessment and activated (Defender) services – takes 24 hours Turn on/off per improvement (Compliance Manager Administrator) Modify an improvement action -> automatic testing is turned off

Testing

Run through DEMO

Microsoft Defender for Cloud

Multicloud support - regulations Microsoft Azure CIS Microsoft Azure Foundations Benchmark v1.1.0 CIS Microsoft Azure Foundations Benchmark v1.3.0 CIS Microsoft Azure Foundations Benchmark v1.4.0 FedRAMP High FedRAMP Moderate ISO 27001 NIST SP 800-171 Rev.2 NIST SP 800-53 Rev.4 NIST SP 800 53 Rev.5 PCI DSS v4.0 SOC 2 Type 2 SWIFT CSP-CDCF v2022 AWS AWS Foundational Security Best Practices CIS 1.2.0 NIST SP 800 53 Rev.5 PCI DSS 3.2.1 GCP CIS 1.1.0 CIS 1.2.0 ISO 27001 NIST SP 800 53 Rev.5 PCI DSS 3.2.1

Multicloud support - connectors https://learn.microsoft.com/en-us/purview/compliance-manager-cloud-settings

Run through DEMO

Some thoughts To end this session Some regional regulations are not (yet) supported Custom assessments are coming back Automatic testing will take some time Some improvement actions will increase your score, but not your compliance stance

Enter the raffle to win prizes! Visit each sponsor Decrypt the Morse code! Provide feedback through the Run.Events app!

Thank you to our sponsors!

Thank you! Albert Hoitingh