Forum Discussion

Kalonji_ICS's avatar
Kalonji_ICS
Copper Contributor
Aug 25, 2020

What are the recommendation and procedures for flagging data as CUI and managing it?

In preparing for our CMMC Certification, as a company that is heavily uses SharePoint and Teams in the Office365 cloud environment -- what are the recommendations and procedures for flagging data as CUI and managing it?

1 Reply

  • Kalonji_ICS - Thank you for your question.  First, let me commend you on beginning this journey.  Data tagging and labeling is perhaps one of the most critical aspects of not just controlling CUI, but also managing your business IP.  

     

    There's a few places to get started:
    1) take a look at Data Loss Prevention (DLP):  https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide


    second,

     

    Take a look at Azure Information Protection (AIP): https://docs.microsoft.com/en-us/azure/information-protection/

    These are foundational offerings and approaches to managing your special data types.

    As you dig into these and have more questions, please do come back to this thread and ask more questions.

    V/R
    Anu Gupta

Resources