Forum Discussion
Shivani_ra
Dec 20, 2018Copper Contributor
Need more details regarding "Compare Your Score" section
Hello Team, I have recently started analyzing secure score. I read in one of MS link that under "Compare your score" section, we can compare our score to the average score of all the O365 tenants...
- Dec 20, 2018Hi Shivani,
100% Agree with Jethro here in terms of the score and what it represents. There is an element of gamification in the Secure Score which I often find makes organisations think that if they outscore the industry average by 20-30 points then it means they are ok. It reality it only hides the fact that many Office 365 tenants do not utilise the security controls or best practices within their environments and your organisation becomes only marginally less insecure than the others.
As Jethro said, a lot has to do with mapping your own security requirements and I would add this includes actively managing these on an ongoing basis not just lighting up things like MFA and thinking that will do. Part of that is using secure score over time. There is a great article here about managing security with secure score over time - the first 30 days, then 90, then beyond
https://docs.microsoft.com/en-us/office365/securitycompliance/security-roadmap
And Microsoft have just released a series on best practice here on the TC
https://techcommunity.microsoft.com/t5/Security-Privacy-Compliance/How-to-help-maintain-security-compliance/m-p/298467#M1748
This should be used in conjunction with other tools and guides such as Intune, Cloud App Security and Advanced Threat Intelligence. For things outside Microsoft, if you are a UK based organisation then I would consider Cyber Essentials here
https://www.gov.uk/government/publications/cyber-essentials-scheme-overview
And looking into ISO27001
https://www.iso.org/isoiec-27001-information-security.html
Security improvement is also a lot about training as much as the tools so I would consider how to improve staff behaviours. If you do Cyber Essentials and ISO then there are trading elements. Having a few staff ITIL trained will help too.
Hope that helps.
Best, Chris
Shivani_ra
Copper Contributor
Thank you Jethro and Christopher for sharing your feedback.
So, this "Compare your score" will not help much. This is indeed confusing.
I understand that we need to be more focus on the actions suggested as part of secure score and make sure other security features are being used.
Dec 24, 2018
Thanks Shivani,
I think Microsoft intended the secure score compare to help spur organisations on to improve their score, however in the real world this is probably proving to be counterproductive. I wouldn’t be surprised if the compare is removed down the road.
My advice is to use secure score as part of your tool kit for security along with other things such as Cyber Essentials and ISO. Use the recommendations to apply and raise your score to as high as possible where it aligns to your needs and not be too restrictive to users.
I hope we have answered your initial question! If we have, please like the posts and mark on of them as the solution. Look forward to helping you again in the future!
Best, Chris
I think Microsoft intended the secure score compare to help spur organisations on to improve their score, however in the real world this is probably proving to be counterproductive. I wouldn’t be surprised if the compare is removed down the road.
My advice is to use secure score as part of your tool kit for security along with other things such as Cyber Essentials and ISO. Use the recommendations to apply and raise your score to as high as possible where it aligns to your needs and not be too restrictive to users.
I hope we have answered your initial question! If we have, please like the posts and mark on of them as the solution. Look forward to helping you again in the future!
Best, Chris