Configuring Data Security Policies in Microsoft Azure CONFIGURING - - PowerPoint PPT Presentation

configuring data security policies in microsoft azure
SMART_READER_LITE
LIVE PREVIEW

Configuring Data Security Policies in Microsoft Azure CONFIGURING - - PowerPoint PPT Presentation

Configuring Data Security Policies in Microsoft Azure CONFIGURING DATA CLASSIFICATION IN MICROSOFT AZURE Reza Salehi CLOUD CONSULTANT @zaalion linkedin.com/in/rezasalehi2008 t h s Understanding data risks, governance and compliance


slide-1
SLIDE 1

@zaalion linkedin.com/in/rezasalehi2008

CLOUD CONSULTANT

Reza Salehi

CONFIGURING DATA CLASSIFICATION IN MICROSOFT AZURE

Configuring Data Security Policies in Microsoft Azure

slide-2
SLIDE 2

t h s

Understanding data risks, governance and compliance What is data classification? Classifying resources and data in Azure

  • Resource Manager tags
  • Azure Information Protection labels
  • Service specific (Azure SQL Database)

Demo:

  • Working with ARM tags
  • Working with Azure SQL Database

Advanced Data Security (ADS)

Overview

slide-3
SLIDE 3

To achieve better ROI on security, the organization needs to first understand its security requirements & priorities

Understanding Security Requirements

Governance – How is the organization’s security going to be monitored, audited, and reported? Risk – What types of risks does the organization face while trying to protect information? Compliance – Are there specific industry, government, or regulatory requirements?

slide-4
SLIDE 4

Understand the security requirements first.

slide-5
SLIDE 5

Compliance Governance Risks

Understanding Security Requirements

slide-6
SLIDE 6

Addressing Disaster Recovery and Business Continuity Who may be interested or could leverage this information if stolen? Intellectual Property (IP), PII, financial information, etc. The risks you face while trying to protect identifiable information

Data Security Risks

slide-7
SLIDE 7

Are there industry, government, or regulatory requirements that dictate or provide recommendation

  • n your organization’s security controls?

Compliance

slide-8
SLIDE 8

Auditing the compliance Are there new security requirements? Is there any mandatory reporting? How do you know if your protection is working as expected? Monitoring, auditing, and reporting of security

Governance

slide-9
SLIDE 9

Understand your data by classifying it.

slide-10
SLIDE 10

To apply security rules, you need to classify your data You have identified the security priorities and ready to define security rules

Data Classification

slide-11
SLIDE 11

Public

Data Classification in Your Organization

Internal Confidential Top Secret

slide-12
SLIDE 12

Extremely important for cloud data Then, data can be managed to prevent theft or loss Categorizes data by sensitivity and business impact Is a common starting point for governance Allows you to assign metadata to your

  • rganization's data

Data Classification

slide-13
SLIDE 13

Is the process of associating a metadata to a digital asset, which identifies the type of data associated with that asset.

Data Classification

slide-14
SLIDE 14

Highly confidential

Business data that would cause extensive harm to Microsoft if overshared

Confidential

Business data that could cause harm to Microsoft if

  • vershared

General

Business data that is not meant for a public audience Public

Business data that is freely available and approved for public consumption

Non-business

Data from your personal life that does not belong to Microsoft

Example: Microsoft's Data Classification

slide-15
SLIDE 15

You know your data/industry better than anyone else. Classify the data following your own criteria.

slide-16
SLIDE 16

Microsoft suggests that any asset in the cloud should have documented metadata

Data Classification in Azure

The data classification (public, internal, etc.) Business criticality (non-critical, critical, etc.) Billing responsibility (department, branch name, etc.)

slide-17
SLIDE 17

Azure Information Protection labels

For Microsoft Office documents and emails

Resource type specific

e.g. Advanced Data Security for Azure SQL Database

Azure Resource Manager tags

Most resources in Azure support tags

Data Classification in Azure

slide-18
SLIDE 18

In the case of Azure, resource tags are the suggested approach for metadata storage

Azure Resource Manager Tags

These tags can be used to apply data classification information to deployed resources They provide a valuable tool for managing resources and applying policies Can be managed in the portal or programmatically

slide-19
SLIDE 19

You can apply tags to your Azure resources to logically organize them into a taxonomy

Azure Resource Manager Tags

Each tag consists of a name and a value pair (e.g. department = IT) After you apply tags, you can retrieve all the resources in your subscription with that tag name and value Tags enable you to retrieve related resources from different resource groups

slide-20
SLIDE 20

T ag can be applied manually or automatically.

slide-21
SLIDE 21

Helps to comply with the expected tags standards for your

  • rganization

You can create a policy that automatically applies tags during resource deployment You can use an Azure Policy to enforce tagging rules and conventions

Tags and Azure Policies

slide-22
SLIDE 22

Generalized VMs don't support tags

Resource group tags are not inherited by the children Tags can't be applied to classic resources such as Cloud Services

Tag names can't contain < > % & \ ? /

Tag name 512 characters (128 for storage), value 256 characters

Maximum of 50 tags

Resource Manager Tags Limitations

slide-23
SLIDE 23

Tag Support for Azure Resources

slide-24
SLIDE 24

Azure Information Protection

A cloud-based solution that helps an organization to classify and protect its documents and emails by applying labels Labels can be applied automatically by administrators who define rules and conditions Or manually by users, or a combination where users are given recommendations

slide-25
SLIDE 25

Azure Information Protection

slide-26
SLIDE 26

Labels can include visual markings (header, footer, or watermark)

Prevent data leakage or misuse Track access to documents Detect risky behavior and take corrective measures Analyze data flows to gain insight into your business

Azure Information Protection

slide-27
SLIDE 27

Azure Information Protection

slide-28
SLIDE 28

Install the Azure Information Protection client Provision Azure Information Protection in the portal

Provisioning Azure Information Protection

slide-29
SLIDE 29

Provisioning Azure Information Protection

slide-30
SLIDE 30

You must have either of the following:

  • Azure Information Protection Premium

P1 (included within Enterprise Mobility and

Security E3)

  • Azure Information Protection Premium

P2 (included within Enterprise Mobility and

Security E5)

  • Office 365 subscription that includes

Azure Rights Management

slide-31
SLIDE 31

Download the Client

slide-32
SLIDE 32

Data Classification for Azure SQL Databases

slide-33
SLIDE 33

Data discovery & classification provides advanced capabilities built into Azure SQL Databases.

slide-34
SLIDE 34

Provides discovering, classifying, labeling & protecting the sensitive data in your Azure SQL databases and data warehouse

Data Classification for Azure SQL Databases

Business, financial, healthcare, personally identifiable data (PII), and so on Data discovery & classification is part of the Advanced Data Security (ADS) offering Can be accessed and managed via the central SQL ADS in the Azure portal

slide-35
SLIDE 35

Enabling Advanced Data Security

slide-36
SLIDE 36

Enabling Advanced Data Security

slide-37
SLIDE 37

Enabling Advanced Data Security

slide-38
SLIDE 38

Demo

t h s

Classify Azure resources using ARM tags

  • Assign tags to different resources
  • Enforce tags using Azure Policy
slide-39
SLIDE 39

Demo

t h s

Classifying data in Azure SQL Database using Advanced Data Security (ADS)

slide-40
SLIDE 40

t h s

Understanding data risks and importance

  • f governance

Data classification Data classification in Azure

  • ARM tags
  • Azure Information Protection labels
  • Service specific (Azure SQL Database)

Demo: ARM tags Demo: Azure SQL Database ADS

Summary