{"id":1610,"date":"2018-03-23T01:00:00","date_gmt":"2018-03-23T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/office-365-data-loss-prevention-dlp-setup-for-a-simple-phrase\/"},"modified":"2018-03-23T01:00:00","modified_gmt":"2018-03-23T01:00:00","slug":"office-365-data-loss-prevention-dlp-setup-for-a-simple-phrase","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/secure-workplace\/office-365-data-loss-prevention-dlp-setup-for-a-simple-phrase\/","title":{"rendered":"Office 365 Data Loss Prevention (DLP) \u2013 Setup for a simple phrase"},"content":{"rendered":"<p style=\"text-align: justify;\">Data Loss Prevention (DLP) is a huge topic and with GDPR and privacy legislation in Australia, data breach notification is mandatory and leaks are newsworthy. People who leak are becoming martyrs \u2013 just think about Edward Snowden and Julian Assange.<\/p>\n<p style=\"text-align: justify;\">Implementing a custom DLP policy in Office 365 is a bit of a learning curve, it involves importing a custom XML, working with RegEx and A LOT of testing. We found that, even for a single word it can be tricky and not work as expected.<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>WHERE IT SHINES<\/span><\/h3>\n<p style=\"text-align: justify;\">DLP is extremely useful in cases where the word or phrase isn\u2019t common or is unique to your business such as a credit card number, unique employee ID or top-secret file naming convention.<\/p>\n<p style=\"text-align: justify;\">Here is a sample XML file for detecting a string \u201c#TOP-SECRET#\u201d. This should be unique enough that it won\u2019t trigger unnecessarily (its case sensitive) and you can put this classification in your top-secret documents. The string in the entity is a normal Regex expression which means it\u2019s extremely powerful. There are also ways to match data to other nearby data such as a Credit Card number and the expiry date but for this blog we are keeping it simple. I won\u2019t go into explaining the XML as there is a good guide<span>\u00a0<\/span><a rel=\"noopener nofollow\" href=\"https:\/\/support.office.com\/en-us\/article\/create-a-custom-sensitive-information-type-82c382a5-b6db-44fd-995d-b333b3c7fc30\" target=\"_blank\">here<\/a>.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 0px; height: 0px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/7a3de35a77ca4af58a514217760bda38\" \/><img decoding=\"async\" style=\"width: 773px; height: 408px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/7a3de35a77ca4af58a514217760bda38\" \/><\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Steps to use the new rule<\/span><\/h3>\n<h4>1. Import the rule to Office 365 DLP (Connect to Office 365 Security and Compliance PowerShell first)<\/h4>\n<p><img decoding=\"async\" style=\"width: 911px; height: 51px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_2.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/d92b623e46a24a96ba47fee57157f574\" \/><\/p>\n<h4>2. Logon to the Security and Compliance Centre and click on Policy -&gt; Create a Policy<\/h4>\n<p><img decoding=\"async\" style=\"width: 901px; height: 200px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_3.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/63fd02f3e7864a3187b1686baf49724c\" \/><\/p>\n<h4>3. Choose a Custom Policy and click Next<\/h4>\n<p><img decoding=\"async\" style=\"width: 859px; height: 359px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_4.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/9aa03849f6644609b925f412ae76d7d6\" \/><\/p>\n<h4>4. Name your policy and give it a description<\/h4>\n<p><img decoding=\"async\" style=\"width: 837px; height: 350px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_5.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/f057edb0d1214926ac501d20c11f8944\" \/><\/p>\n<h4>5. Choose where to protect your content, for this test we will protect all data (SharePoint, OneDrive and Exchange)<\/h4>\n<p><img decoding=\"async\" style=\"width: 763px; height: 319px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_6.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/5900ba78519a4bdca6bada636082cbac\" \/><\/p>\n<h4>6. On the policy settings screen \u2013 choose \u201cEdit\u201d<\/h4>\n<p><img decoding=\"async\" style=\"width: 784px; height: 328px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_7.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/8a8f106ca18f479a917f3ace1bf14fe7\" \/><\/p>\n<h4>7. Drop down the menu and choose \u201cSensitive Information Types\u201d<\/h4>\n<p><img decoding=\"async\" style=\"width: 723px; height: 302px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_8.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/4cf7c61aa08f4fe58fc439bc32a3fd19\" \/><\/p>\n<h4>8. Click on \u201cAdd\u201d then choose the sensitive information type you imported<\/h4>\n<p><img decoding=\"async\" style=\"width: 663px; height: 598px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_9.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/9d3368ff3e8f4333a226a113c72b964e\" \/><\/p>\n<h4>9. Leave the accuracy Min and Max at 100 as this is an exact match scenario and click \u201cSave\u201d<\/h4>\n<p><img decoding=\"async\" style=\"width: 832px; height: 351px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_10.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/cb29dbe527284904b42c4c35fe22f5cf\" \/><\/p>\n<h4>10. Customise the notification settings with your rule to match what you require \u2013 make sure you put the \u201cDetect when content that\u2019s being shared contains\u201d down to 1 instance \u2013 otherwise it will be hard to trigger this rule<\/h4>\n<p><img decoding=\"async\" style=\"width: 858px; height: 494px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_11.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/8e82e971c0e246dcb084640132e0e39e\" \/><\/p>\n<h4>11. Review the settings of the rule and click on \u201cCreate\u201d \u2013 Then wait at least 15-30 minutes before testing the rule.<\/h4>\n<h4>The rule will then block your email based on the conditions you set!<\/h4>\n<p><img decoding=\"async\" style=\"width: 863px; height: 409px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/dlp_img_12.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/43fc63e6239b45dcbb8ee03824d7cea0\" \/><\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>THINGS TO BE AWARE OF<\/span><\/h3>\n<ul>\n<li style=\"text-align: justify;\">DLP takes time to scan so, in a large email with an attachment of 30 pages, looking for a specific word could take a long time.<\/li>\n<li style=\"text-align: justify;\">Sometimes scans don\u2019t finish and an email is sent, triggering a bounce back once the scan finished.<\/li>\n<li style=\"text-align: justify;\">DLP, if not configured well it can trigger far too often.<\/li>\n<\/ul>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>OWN UP TO YOUR LEAKS OR FACE CONSEQUENCES!<\/span><\/h3>\n<p style=\"text-align: justify;\">Given the new legislation around the globe, every business needs to take note of DLP right now. The implications are significant:<\/p>\n<p style=\"text-align: justify;\"><em>\u201cIn a stark departure from previous privacy legislation in Europe or elsewhere, the GDPR authorizes regulators to levy remarkably steep fines in amounts exceeding 20 million euros or four percent of annual global turnover, whichever is higher.\u201d<\/em><\/p>\n<p style=\"text-align: justify;\">Recently we have been testing these scenarios as we are working towards compliance baselines and they have already made their mark. Don\u2019t worry \u2013 we don\u2019t name things top secret.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data Loss Prevention (DLP) is a huge topic and with GDPR and privacy legislation in Australia, data breach notification is mandatory and leaks are newsworthy. People who leak are becoming martyrs \u2013 just think about Edward Snowden and Julian Assange. Implementing a custom DLP policy in Office 365 is a bit of a learning curve,&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/secure-workplace\/office-365-data-loss-prevention-dlp-setup-for-a-simple-phrase\/\">Continue reading <span class=\"screen-reader-text\">Office 365 Data Loss Prevention (DLP) \u2013 Setup for a simple phrase<\/span><\/a><\/p>\n","protected":false},"author":57,"featured_media":1611,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[20],"tags":[],"class_list":["post-1610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=1610"}],"version-history":[{"count":0,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/1611"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=1610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=1610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=1610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}