Upload
2seeu
View
192
Download
0
Embed Size (px)
Citation preview
Accessible content is available upon request.
Initiation à la conformité dans O365Hassen Boumaraf, Senior Technical Account [email protected]
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Agenda Définitions
Quelques chiffres
Roadmap
Office 365 et conformité : Démo
La conformité au coeur de l’organisation
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Définitions
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Données sensibles
Métiers Personnelles
Finance : N° de carte bancaireVisa, Amex, MasterCard
RH / Médicales
N° de Sécurité Sociale
Denmark Personal Identification Number
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Règlementation
Métiers PersonnellesPCI – DSS
SOX (Sarbanes-Oxley)
HIPAA
loi Informatique et Libertés et la Directive Européenne 95/46/EC
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Data breach• “A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so”
[U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES Administration for Children and Families]
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Conformité
• “Compliance means conforming to a rule, such as a specification, policy, standard or law …”
[Wikipedia]
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Conformité des données• Une information ne doit être que là où elle devrait être• Une information ne doit être visible que par ceux qui devraient la voir
[Hassen Boumaraf]
Malheureusement, ce n’est pas toujours le cas
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Quelques chiffres
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Records breached (known)Data breaches (known)
Incident trends
3,525 605,742,928Security
breaches
April 20, 2005 toDecember 20, 2012
Represents United StatesSource: http://www.privacyrights.org
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Causes de “data breach”
System glitches
Malicious intent Oops!
39%
24%
37%
Online Trust Alliance: 2013 Data Protection and Breach Readiness Guide
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Etude IBM / Ponemon• 29 entreprises ont participé à l’étude en France
• Coût moyen d’un enregistrement compromis : 134€
• Augmentation de 3.3% par rapport à l’année dernière
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Actions correctives suite à un incident
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Solutions O365
Comment mettre ces solutions en place dans O365 ?
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
O365 et conformité
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Données sensibles• France Driver's License Number• France National ID Card (CNI)• France Passport Number• France Social Security Number (INSEE)SWIFT Code• Taiwan National ID• Taiwan Passport Number• Taiwan Resident Certificate (ARC/TARC) Number• U.K. Driver's License Number• U.K. Electoral Roll Number• U.K. National Health Service Number• U.K. National Insurance Number (NINO)• U.S. / U.K. Passport Number• U.S. Bank Account Number• U.S. Driver's License Number• U.S. Individual Taxpayer Identification Number (ITIN)• U.S. Social Security Number (SSN)
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Outlook• Titre/Corps/
Pièces jointes• Policy Tips• Justification
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
SharePoint• eDiscovery
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
SharePoint• Audit
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Yammer
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
O365 Compliance Center• Equipe conformité• Intégration de DLP aux solutions MS• Centralisation des outils de conformité
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
O365 : Partage vers l’exterieur
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
MFA• Communément : Double authentification
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
RMS• Azure Right Management
• Chiffrement de contenu, d’e-mail
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
MDM•Mobile Device Management
•Mobilité
• Policy
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
La conformité au coeur de l’organisation
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Responsables « Conformité »
• CISO / RSSI
• CPO / CIL / DPO
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Roadmap
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Roadmap• SharePoint 2016- Intégration de la recherche
des données sensibles
O365 roadmap : http://success.office.com/en-us/roadmap
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of
AvePoint, Inc.
Q / A