Skip to content

Commit d7935b8

Browse files
authored
Merge pull request #53660 from ceperezb/CEPEREZB-sc100-design-regulatory-compliance
update module
2 parents f92bbad + eccd2ec commit d7935b8

15 files changed

Lines changed: 137 additions & 143 deletions

learn-pr/wwl-sci/design-solutions-regulatory-compliance/1-introduction-regulatory-compliance.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Introduction
44
metadata:
55
title: Introduction
66
description: "Introduction to: Design solutions for regulatory compliance."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/2-translate-compliance-requirements-security-solution.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Translate compliance requirements into security controls
44
metadata:
55
title: Translate compliance requirements into security controls
66
description: "SC-100 preparatory unit on the topic: Translate compliance requirements into security controls."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/2a-ai-compliance-considerations.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: AI compliance considerations
44
metadata:
55
title: AI compliance considerations
66
description: "SC-100 preparatory unit on the topic: compliance considerations for AI technologies including EU AI Act, ISO 42001, and NIST AI RMF."
7-
ms.date: 01/29/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/3-address-compliance-requirements-microsoft-purview.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Design a solution to address compliance requirements by using Microsoft P
44
metadata:
55
title: Design a solution to address compliance requirements by using Microsoft Purview
66
description: "SC-100 preparatory unit on the topic: Design a solution to address compliance requirements by using Microsoft Purview."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/4-address-privacy-requirements-microsoft-priva.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ title: Address privacy requirements with Microsoft Priva
44
metadata:
55
title: Address privacy requirements with Microsoft Priva
66
description: "SC-100 preparatory unit on topic: address privacy requirements with Microsoft Priva."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 9
11+
durationInMinutes: 8
1212
content: |
1313
[!include[](includes/4-address-privacy-requirements-microsoft-priva.md)]
Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
### YamlMime:ModuleUnit
22
uid: learn.wwl.design-solutions-regulatory-compliance.address-security-compliance-requirements-azure-policy
3-
title: Address security and compliance requirements with Azure policy
3+
title: Address security and compliance requirements with Azure Policy
44
metadata:
5-
title: Address security and compliance requirements with Azure policy
6-
description: "SC-100 preparatory unit on the topic: address security and compliance requirements with Azure policy."
7-
ms.date: 01/28/2026
5+
title: Address security and compliance requirements with Azure Policy
6+
description: "SC-100 preparatory unit on the topic: address security and compliance requirements with Azure Policy."
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 8
11+
durationInMinutes: 10
1212
content: |
1313
[!include[](includes/5-address-security-compliance-requirements-azure-policy.md)]

learn-pr/wwl-sci/design-solutions-regulatory-compliance/6-evaluate-infrastructure-compliance-defender-cloud.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Evaluate and validate alignment with regulatory standards and benchmarks
44
metadata:
55
title: Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud
66
description: "SC-100 preparatory unit on the topic: Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/7-knowledge-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Module assessment
44
metadata:
55
title: Module assessment
66
description: "Knowledge check for module on the topic: design solutions for regulatory requirements. Contains AI generated content."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/8-summary.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ title: Summary
44
metadata:
55
title: Summary
66
description: "Summary of module on topic: design solutions for regulatory requirements."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 3
11+
durationInMinutes: 2
1212
content: |
1313
[!include[](includes/8-summary.md)]

learn-pr/wwl-sci/design-solutions-regulatory-compliance/includes/3-address-compliance-requirements-microsoft-purview.md

Lines changed: 23 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,14 @@ Microsoft Purview provides a unified platform for data security, governance, and
22

33
## The Microsoft Purview portfolio
44

5+
<!-- Source: https://learn.microsoft.com/purview/purview -->
56
Microsoft Purview combines multiple solution areas to address compliance requirements across your organization's data estate:
67

78
| Solution Area | Purpose | Key Solutions |
89
|--------------|---------|---------------|
9-
| **Data security** | Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management |
10+
| **Data security** | Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management, Information Barriers, Privileged Access Management, Data Security Investigations |
1011
| **Data governance** | Manage and catalog data across your estate | Data Map, Unified Catalog |
11-
| **Data compliance** | Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, eDiscovery, Records Management |
12+
| **Data compliance** | Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, Communication Compliance, eDiscovery, Data Lifecycle Management, Records Management |
1213

1314
Understanding how these solutions map to specific compliance requirements helps you design an integrated architecture rather than deploying isolated tools.
1415

@@ -17,6 +18,7 @@ Understanding how these solutions map to specific compliance requirements helps
1718

1819
## Addressing data protection requirements
1920

21+
<!-- Source: https://learn.microsoft.com/purview/information-protection -->
2022
Most compliance frameworks require organizations to identify, classify, and protect sensitive data. Purview Information Protection provides the foundation for these requirements.
2123

2224
**Sensitive information types** identify regulated data like payment card numbers, health records, or personal identifiers using built-in patterns or custom definitions. **Trainable classifiers** extend this capability by learning to recognize sensitive content based on examples you provide—useful for organization-specific data like internal financial reports or proprietary designs.
@@ -36,12 +38,13 @@ When designing your labeling strategy, consider:
3638

3739
## Preventing unauthorized data sharing
3840

41+
<!-- Source: https://learn.microsoft.com/purview/dlp-learn-about-dlp -->
3942
Regulations often require controls to prevent unauthorized disclosure of sensitive information. **Microsoft Purview Data Loss Prevention (DLP)** monitors and controls how sensitive data is shared across Microsoft 365 services, endpoints, and cloud apps.
4043

4144
Design your DLP policies to address specific regulatory requirements:
4245

4346
- **Policy conditions** - Define what sensitive data to protect based on sensitive information types, labels, or content patterns
44-
- **Policy locations** - Specify where monitoring occurs (Exchange, SharePoint, OneDrive, Teams, endpoints, Defender for Cloud Apps)
47+
- **Policy locations** - Specify where monitoring occurs (Exchange, SharePoint, OneDrive, Teams, devices, non-Microsoft cloud apps, on-premises repositories, Fabric and Power BI, and Microsoft 365 Copilot)
4548
- **Policy actions** - Configure responses from audit-only monitoring to blocking with user override to complete restriction
4649

4750
DLP integrates with your sensitivity labels, so protection can follow content based on its classification. This integration is particularly valuable for requirements that mandate different handling based on data sensitivity levels.
@@ -50,22 +53,26 @@ DLP integrates with your sensitivity labels, so protection can follow content ba
5053

5154
Compliance frameworks require organizations to maintain audit trails and respond to legal or regulatory inquiries. Purview provides several solutions for these requirements:
5255

53-
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Design your audit strategy to:
56+
<!-- Source: https://learn.microsoft.com/purview/audit-solutions-overview -->
57+
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Audit is available in two tiers—Audit (Standard) provides 180-day retention with basic search and export, while Audit (Premium) adds custom retention policies (up to 10 years with an add-on license), intelligent insights for forensic investigations, and higher API bandwidth. Design your audit strategy to:
5458

55-
- Enable appropriate audit logging levels based on regulatory requirements
56-
- Configure retention periods that meet legal hold obligations
59+
- Select the appropriate audit tier based on regulatory retention and investigation requirements
60+
- Configure retention policies that meet legal hold obligations
5761
- Establish processes for searching and exporting audit data for investigations
5862

63+
<!-- Source: https://learn.microsoft.com/purview/ediscovery -->
5964
**Microsoft Purview eDiscovery** helps you identify, preserve, collect, and export content for legal matters. For compliance purposes, design workflows that:
6065

6166
- Create legal holds to preserve relevant content
6267
- Define search criteria that capture required data without over-collection
6368
- Export content in formats suitable for regulatory review
6469

70+
<!-- Source: https://learn.microsoft.com/purview/records-management -->
6571
**Microsoft Purview Records Management** applies retention and deletion policies to meet recordkeeping requirements. Consider how file plans, retention labels, and disposition reviews align with your regulatory obligations.
6672

6773
## Managing insider risk
6874

75+
<!-- Source: https://learn.microsoft.com/purview/insider-risk-management-solution-overview -->
6976
Some regulations require controls to detect and respond to insider threats. **Microsoft Purview Insider Risk Management** uses signals from across Microsoft 365 and third-party systems to identify risky user activities.
7077

7178
Design your insider risk program to:
@@ -76,24 +83,27 @@ Design your insider risk program to:
7683

7784
## Addressing AI compliance requirements
7885

79-
As discussed in the AI compliance considerations unit, organizations deploying AI face specific regulatory requirements around data protection, transparency, and governance. Purview provides capabilities specifically designed for AI scenarios:
86+
As discussed in the AI compliance considerations unit, organizations deploying AI face specific regulatory requirements around data protection, transparency, and governance. Multiple Purview solutions extend their capabilities to AI scenarios:
8087

81-
**Data Security Posture Management (DSPM)** provides visibility and control for both traditional applications and AI apps. Use DSPM to:
88+
<!-- Source: https://learn.microsoft.com/purview/data-security-posture-management-learn-about -->
89+
**Data Security Posture Management (DSPM) (preview)** provides visibility and control for both traditional applications and AI apps and agents. Use DSPM to:
8290

8391
- Discover sensitive data that may be exposed to AI applications
84-
- Monitor how AI apps access and process organizational data
92+
- Monitor how AI apps access and process organizational data through data security insights and trend analysis
8593
- Identify and remediate data security risks before they become compliance issues
8694

87-
**Microsoft Purview for AI** extends data security protections to generative AI experiences:
95+
<!-- Source: https://learn.microsoft.com/purview/ai-microsoft-purview -->
96+
Existing Purview data security capabilities extend to generative AI apps, including Microsoft 365 Copilot, Copilot Studio, and third-party AI applications:
8897

89-
- Protect data used by Copilot experiences and custom AI agents
90-
- Apply sensitivity labels to AI-generated content
91-
- Prevent sensitive data from being shared inappropriately through AI interactions
98+
- **Sensitivity labels** protect data referenced by AI apps—users must have appropriate usage rights (VIEW and EXTRACT) for AI apps to return encrypted content
99+
- **Data Loss Prevention** monitors AI interactions and can block sensitive data sharing with unmanaged AI apps through endpoint and inline web traffic policies
100+
- **Insider Risk Management** detects risky AI usage, including prompt injection attacks and unauthorized access to protected materials, through the Risky AI usage policy template
92101

93102
For organizations subject to AI-specific regulations like the EU AI Act or ISO 42001, **Compliance Manager** provides assessment templates that map Purview controls to these requirements.
94103

95104
## Multicloud compliance with Compliance Manager
96105

106+
<!-- Source: https://learn.microsoft.com/purview/compliance-manager -->
97107
Compliance Manager serves as the orchestration layer that brings together compliance data from across your environment. It integrates with Microsoft Defender for Cloud to assess compliance across Azure, AWS, and GCP.
98108

99109
When designing your Compliance Manager implementation:

0 commit comments

Comments
 (0)