Skip to content

Commit ef81f31

Browse files
committed
update module
1 parent b68de65 commit ef81f31

15 files changed

Lines changed: 131 additions & 139 deletions

learn-pr/wwl-sci/design-solutions-regulatory-compliance/1-introduction-regulatory-compliance.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Introduction
44
metadata:
55
title: Introduction
66
description: "Introduction to: Design solutions for regulatory compliance."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/2-translate-compliance-requirements-security-solution.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Translate compliance requirements into security controls
44
metadata:
55
title: Translate compliance requirements into security controls
66
description: "SC-100 preparatory unit on the topic: Translate compliance requirements into security controls."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/2a-ai-compliance-considerations.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: AI compliance considerations
44
metadata:
55
title: AI compliance considerations
66
description: "SC-100 preparatory unit on the topic: compliance considerations for AI technologies including EU AI Act, ISO 42001, and NIST AI RMF."
7-
ms.date: 01/29/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/3-address-compliance-requirements-microsoft-purview.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Design a solution to address compliance requirements by using Microsoft P
44
metadata:
55
title: Design a solution to address compliance requirements by using Microsoft Purview
66
description: "SC-100 preparatory unit on the topic: Design a solution to address compliance requirements by using Microsoft Purview."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/4-address-privacy-requirements-microsoft-priva.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ title: Address privacy requirements with Microsoft Priva
44
metadata:
55
title: Address privacy requirements with Microsoft Priva
66
description: "SC-100 preparatory unit on topic: address privacy requirements with Microsoft Priva."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 9
11+
durationInMinutes: 8
1212
content: |
1313
[!include[](includes/4-address-privacy-requirements-microsoft-priva.md)]
Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
### YamlMime:ModuleUnit
22
uid: learn.wwl.design-solutions-regulatory-compliance.address-security-compliance-requirements-azure-policy
3-
title: Address security and compliance requirements with Azure policy
3+
title: Address security and compliance requirements with Azure Policy
44
metadata:
5-
title: Address security and compliance requirements with Azure policy
6-
description: "SC-100 preparatory unit on the topic: address security and compliance requirements with Azure policy."
7-
ms.date: 01/28/2026
5+
title: Address security and compliance requirements with Azure Policy
6+
description: "SC-100 preparatory unit on the topic: address security and compliance requirements with Azure Policy."
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 8
11+
durationInMinutes: 10
1212
content: |
1313
[!include[](includes/5-address-security-compliance-requirements-azure-policy.md)]

learn-pr/wwl-sci/design-solutions-regulatory-compliance/6-evaluate-infrastructure-compliance-defender-cloud.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Evaluate and validate alignment with regulatory standards and benchmarks
44
metadata:
55
title: Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud
66
description: "SC-100 preparatory unit on the topic: Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/7-knowledge-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ title: Module assessment
44
metadata:
55
title: Module assessment
66
description: "Knowledge check for module on the topic: design solutions for regulatory requirements. Contains AI generated content."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit

learn-pr/wwl-sci/design-solutions-regulatory-compliance/8-summary.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ title: Summary
44
metadata:
55
title: Summary
66
description: "Summary of module on topic: design solutions for regulatory requirements."
7-
ms.date: 01/28/2026
7+
ms.date: 02/27/2026
88
author: ceperezb
99
ms.author: ceperezb
1010
ms.topic: unit
11-
durationInMinutes: 3
11+
durationInMinutes: 2
1212
content: |
1313
[!include[](includes/8-summary.md)]

learn-pr/wwl-sci/design-solutions-regulatory-compliance/includes/3-address-compliance-requirements-microsoft-purview.md

Lines changed: 17 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,14 @@ Microsoft Purview provides a unified platform for data security, governance, and
22

33
## The Microsoft Purview portfolio
44

5+
<!-- Source: https://learn.microsoft.com/purview/purview -->
56
Microsoft Purview combines multiple solution areas to address compliance requirements across your organization's data estate:
67

78
| Solution Area | Purpose | Key Solutions |
89
|--------------|---------|---------------|
9-
| **Data security** | Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management |
10+
| **Data security** | Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management, Information Barriers, Privileged Access Management |
1011
| **Data governance** | Manage and catalog data across your estate | Data Map, Unified Catalog |
11-
| **Data compliance** | Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, eDiscovery, Records Management |
12+
| **Data compliance** | Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, Communication Compliance, eDiscovery, Data Lifecycle Management, Records Management |
1213

1314
Understanding how these solutions map to specific compliance requirements helps you design an integrated architecture rather than deploying isolated tools.
1415

@@ -17,6 +18,7 @@ Understanding how these solutions map to specific compliance requirements helps
1718

1819
## Addressing data protection requirements
1920

21+
<!-- Source: https://learn.microsoft.com/purview/information-protection -->
2022
Most compliance frameworks require organizations to identify, classify, and protect sensitive data. Purview Information Protection provides the foundation for these requirements.
2123

2224
**Sensitive information types** identify regulated data like payment card numbers, health records, or personal identifiers using built-in patterns or custom definitions. **Trainable classifiers** extend this capability by learning to recognize sensitive content based on examples you provide—useful for organization-specific data like internal financial reports or proprietary designs.
@@ -36,6 +38,7 @@ When designing your labeling strategy, consider:
3638

3739
## Preventing unauthorized data sharing
3840

41+
<!-- Source: https://learn.microsoft.com/purview/dlp-learn-about-dlp -->
3942
Regulations often require controls to prevent unauthorized disclosure of sensitive information. **Microsoft Purview Data Loss Prevention (DLP)** monitors and controls how sensitive data is shared across Microsoft 365 services, endpoints, and cloud apps.
4043

4144
Design your DLP policies to address specific regulatory requirements:
@@ -50,6 +53,7 @@ DLP integrates with your sensitivity labels, so protection can follow content ba
5053

5154
Compliance frameworks require organizations to maintain audit trails and respond to legal or regulatory inquiries. Purview provides several solutions for these requirements:
5255

56+
<!-- Source: https://learn.microsoft.com/purview/audit-solutions-overview -->
5357
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Design your audit strategy to:
5458

5559
- Enable appropriate audit logging levels based on regulatory requirements
@@ -66,6 +70,7 @@ Compliance frameworks require organizations to maintain audit trails and respond
6670

6771
## Managing insider risk
6872

73+
<!-- Source: https://learn.microsoft.com/purview/insider-risk-management-solution-overview -->
6974
Some regulations require controls to detect and respond to insider threats. **Microsoft Purview Insider Risk Management** uses signals from across Microsoft 365 and third-party systems to identify risky user activities.
7075

7176
Design your insider risk program to:
@@ -76,24 +81,27 @@ Design your insider risk program to:
7681

7782
## Addressing AI compliance requirements
7883

79-
As discussed in the AI compliance considerations unit, organizations deploying AI face specific regulatory requirements around data protection, transparency, and governance. Purview provides capabilities specifically designed for AI scenarios:
84+
As discussed in the AI compliance considerations unit, organizations deploying AI face specific regulatory requirements around data protection, transparency, and governance. Multiple Purview solutions extend their capabilities to AI scenarios:
8085

81-
**Data Security Posture Management (DSPM)** provides visibility and control for both traditional applications and AI apps. Use DSPM to:
86+
<!-- Source: https://learn.microsoft.com/purview/data-security-posture-management-learn-about -->
87+
**Data Security Posture Management (DSPM) (preview)** provides visibility and control for both traditional applications and AI apps and agents. Use DSPM to:
8288

8389
- Discover sensitive data that may be exposed to AI applications
84-
- Monitor how AI apps access and process organizational data
90+
- Monitor how AI apps access and process organizational data through AI observability dashboards
8591
- Identify and remediate data security risks before they become compliance issues
8692

87-
**Microsoft Purview for AI** extends data security protections to generative AI experiences:
93+
<!-- Source: https://learn.microsoft.com/purview/ai-microsoft-purview -->
94+
Existing Purview data security capabilities extend to generative AI apps, including Microsoft 365 Copilot, Copilot Studio, and third-party AI applications:
8895

89-
- Protect data used by Copilot experiences and custom AI agents
90-
- Apply sensitivity labels to AI-generated content
91-
- Prevent sensitive data from being shared inappropriately through AI interactions
96+
- **Sensitivity labels** protect data referenced by AI apps—users must have appropriate usage rights (VIEW and EXTRACT) for AI apps to return encrypted content
97+
- **Data Loss Prevention** monitors AI interactions and can block sensitive data sharing with unmanaged AI apps through endpoint and inline web traffic policies
98+
- **Insider Risk Management** detects risky AI usage, including prompt injection attacks and unauthorized access to protected materials, through the Risky AI usage policy template
9299

93100
For organizations subject to AI-specific regulations like the EU AI Act or ISO 42001, **Compliance Manager** provides assessment templates that map Purview controls to these requirements.
94101

95102
## Multicloud compliance with Compliance Manager
96103

104+
<!-- Source: https://learn.microsoft.com/purview/compliance-manager -->
97105
Compliance Manager serves as the orchestration layer that brings together compliance data from across your environment. It integrates with Microsoft Defender for Cloud to assess compliance across Azure, AWS, and GCP.
98106

99107
When designing your Compliance Manager implementation:

0 commit comments

Comments
 (0)