Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Easy
A small non-profit organization is adopting Microsoft 365. They need to ensure their data is protected from external threats and unauthorized access, but they have a very limited IT budget and no dedicated security staff. Which Microsoft 365 security principle best addresses their primary concern?
- AZero Trust Model
- BShared Responsibility Model
- CSecurity by Design
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: C. Security by Design
Security by Design ensures that security is built into the product from the ground up, reducing the need for extensive configuration or specialized staff for basic protection, which is ideal for organizations with limited resources.
Why the other options are wrong
- A. The Zero Trust Model requires extensive configuration and continuous monitoring, which would be challenging for a non-profit with limited IT staff.
- B. The Shared Responsibility Model clarifies roles but doesn't inherently reduce the need for security expertise or budget.
- D. Defense in Depth involves multiple layers of security, which typically requires more resources and expertise than a small non-profit can afford.
Security by Design
A foundational security principle where security is integrated into the entire development lifecycle of a product or service, rather than being added as an afterthought.
- Security features are inherent, not optional add-ons.
- Reduces vulnerabilities from the outset.
- Minimizes the need for extensive post-deployment configuration.
Memory trick: Build security in, don't bolt it on later.