75 lines
4.2 KiB
Markdown
75 lines
4.2 KiB
Markdown
---
|
||
title: "Module 4 — Data Governance & Compliance"
|
||
description: "Sensitivity label deployment, retention policies, DLP, eDiscovery readiness, Teams governance, and SharePoint external sharing controls. Regulatory evidence produced as a natural output."
|
||
eyebrow: "Consulting Module"
|
||
lead: "Data does not stay where you put it. It is copied, forwarded, synced, and shared — and in most tenants, nobody can enumerate where it went or pull it back. This module makes data flows visible, governable, and auditable."
|
||
actions:
|
||
- label: "Get in Touch"
|
||
url: "/about/#contact"
|
||
primary: true
|
||
- label: "View All Modules"
|
||
url: "/consulting/skills/"
|
||
---
|
||
|
||
## What It Delivers
|
||
|
||
<div class="feature-list">
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">🏷️</div>
|
||
<div class="feature-item-body">
|
||
<h4>Sensitivity Label Deployment</h4>
|
||
<p>A practical label taxonomy deployed across M365 — not the six-tier compliance architecture that nobody uses, but a scheme your organisation will actually apply. Labels flow through email, Teams, SharePoint, and Office applications. Classification becomes a signal every downstream control can act on.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">📅</div>
|
||
<div class="feature-item-body">
|
||
<h4>Retention Policies for All M365 Workloads</h4>
|
||
<p>Retention configured for Exchange, SharePoint, OneDrive, Teams messages, and Teams meeting recordings. Regulatory minimums met. Over-retained data that creates unnecessary eDiscovery scope identified and scheduled for deletion. Retention gaps that expose you to "we don't have it" responses closed.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">🚫</div>
|
||
<div class="feature-item-body">
|
||
<h4>DLP Policies</h4>
|
||
<p>Data Loss Prevention policies targeting your actual regulated data — payment card numbers, national IDs, health data, or proprietary classifications — with alert-before-block staged deployment. Auto-forward to external addresses blocked. "Anyone with the link" sharing scoped or removed.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">⚖️</div>
|
||
<div class="feature-item-body">
|
||
<h4>eDiscovery Readiness</h4>
|
||
<p>Content search scope validated, custodian identification process documented, legal hold workflow tested. If you receive a regulatory request or litigation hold tomorrow, you can respond without improvising under pressure.</p>
|
||
</div>
|
||
</div>
|
||
<div class="feature-item">
|
||
<div class="feature-item-icon">👥</div>
|
||
<div class="feature-item-body">
|
||
<h4>Teams Governance and Guest Access Controls</h4>
|
||
<p>Teams lifecycle policy deployed so abandoned Teams do not accumulate as forgotten data stores. Guest access permissions tightened. External sharing settings reconciled across tenant, site, and Teams channel levels — the three layers that routinely disagree and produce unexpected exposure.</p>
|
||
</div>
|
||
</div>
|
||
</div>
|
||
|
||
## Standards Alignment
|
||
|
||
This module produces direct compliance evidence for NIS2 Article 21 (data security, access control), DORA Article 9 (ICT security policies — data classification and handling), GDPR Articles 5 and 25 (data minimisation, privacy by design), and ISO 27001 A.5.12–A.5.13 (classification, labelling). External auditors receive the retention logs, sensitivity label reports, and DLP policy documentation as artefacts — not manual screenshots.
|
||
|
||
## Scope and Prerequisites
|
||
|
||
| | |
|
||
|---|---|
|
||
| **Duration** | 45–90 days |
|
||
| **Environment** | M365 E3+ |
|
||
| **Prerequisites** | Module 2 (Identity) completed — guest access and external sharing controls depend on a clean identity baseline |
|
||
| **Natural follow-on** | Module 7 (Recovery) to ensure retained data is backed up independently of Microsoft's native retention |
|
||
|
||
<div class="cta-strip">
|
||
<h2>Make your data flows visible</h2>
|
||
<p>Every share is a copy of your blast radius handed to a party you do not fully control. Module 4 makes that visible and governable.</p>
|
||
<div class="actions">
|
||
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
|
||
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
|
||
</div>
|
||
</div>
|