Protecting and governing sensitive data is the biggest concern in complying with regulations. Many businesses cannot say with confidence they can detect sensitive data loss or protect against it. More troubling is that that a lot of corporate data is not classified, protected, or governed.
Deploying tools and policies is small part of the work needed to Implement a governance and compliance strategy. Most of the work starts with a deep dive into the business and its data. BMIT’s experts will help you identify all your sources of data – on-premises or in hybrid clouds – and using Microsoft’s governance capabilities create a map of your data across your business.
Create policies to protect that data
Set rules on what data should be retained or deleted
Classify or label your data to make it easier to apply policies and protect data.
Data policies are a way of ensuring that your business's data is protected, compliant, and managed throughout its lifecycle. Data policies help control who can access your data, where your data is stored, how long your data is retained, and how your data is used.
Common types of sensitive data, include credit card numbers, social security numbers, or health records. You can use sensitive information types to detect and protect your data in various scenarios and define policies.
These specify how long data should be kept or when it should be deleted.
These how data should be protected or handled. You can use information protection labels to enforce encryption, access control, visual marking, or DLP policies.
These specify your data’s business value or risk level.
Data retention can help you comply with legal, regulatory, or business requirements, as well as reduce storage costs and risks.
Several solutions can address such a requirement, some better than others. For example, data retention in Microsoft 365 can help you to manage how long your content is stored and when it is deleted.
You can use retention policies and retention labels. Retention policies apply to entire locations or specific instances, such as mailboxes, sites, groups, or teams. Retention labels apply to individual items or folders, such as emails, documents, or chats. You can use both retention policies and retention labels together to achieve your data retention goals.
Retention policies and retention labels have common settings that let you specify how long to retain content and what to do with it after the retention period expires. You can choose to retain content for a fixed period or based on an event, such as the last modified date or the end of a contract. You can also choose to delete content automatically or review it before deletion.
Visually marking your data is a key step in your data governance journey. Using the capabilities of Microsoft 365 and Microsoft Purview, you can use built-in or custom regular expressions or functions to identify sensitive data. This can be based on keywords, confidence levels and proximity.
Once you have identified the types of sensitive data you want to identify and have created a sensitive information type or used a template you can then use that sensitive information type as a base for policies when deploying other features such as eDiscovery, auto-labelling to protect the data.
get in touch
What distinguishes BMIT from other service providers is our ability to offer a personalised and customised service to each of our customers.
Discover how our services could transform your business’ online efficiency and security