Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A company is developing a new cloud-native application that will store sensitive customer data. To meet regulatory requirements, they need to implement continuous monitoring of all activities related to this data, including who accessed it, when, and what changes were made. This record must be immutable and legally defensible. Which compliance concept is most relevant here?
- AData Encryption
- BInformation Rights Management (IRM)
- CData Loss Prevention (DLP)
- DAuditing (Accountability)
Show answer & explanationAnswer & explanation
Correct answer: D. Auditing (Accountability)
Auditing (Accountability) involves maintaining detailed, immutable records of system and data access and activity. This allows for forensic analysis, proving compliance, and ensuring that actions can be traced back to individuals, which aligns with the requirement for continuous, legally defensible monitoring of data activities.
Why the other options are wrong
- A. Data Encryption protects data at rest or in transit, but doesn't log access or changes.
- B. IRM controls what users can do with sensitive information (e.g., print, forward), but doesn't provide a comprehensive log of all data activities.
- C. DLP prevents data from leaving the organization, not monitoring internal access and changes.
Auditing (Accountability)
The process of systematically examining and recording system activities, data access, and user actions to ensure compliance, detect anomalies, and establish accountability.
- Creates an immutable record of 'who, what, when, where'.
- Crucial for forensic investigations and compliance.
- Helps enforce non-repudiation.
Memory trick: Auditing: The security camera and logbook of data.