2seeu - initiation à la conformité dans o365

31
Accessible content is available upon request. Initiation à la conformité dans O365 Hassen Boumaraf, Senior Technical Account Manager [email protected]

Upload: hassen-boumaraf

Post on 21-Jan-2018

148 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: 2SeeU - Initiation à la conformité dans o365

Accessible content is available upon request.

Initiation à la conformité dans O365Hassen Boumaraf, Senior Technical Account Manager

[email protected]

Page 2: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Définitions

Quelques chiffres

Roadmap

Office 365 et conformité : Démo

La conformité au coeur de l’organisation

Page 3: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Définitions

Page 4: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Métiers Personnelles

Finance : N° de carte bancaire

Visa, Amex, MasterCard

RH / Médicales

N° de Sécurité Sociale

Denmark PersonalIdentification Number

Page 5: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Métiers Personnelles

PCI – DSS

SOX (Sarbanes-Oxley)

HIPAA

loi Informatique et Libertés et la Directive Européenne 95/46/EC

Page 6: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• “A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so”

[U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES Administration for Children and Families]

Page 7: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• “Compliance means conforming to a rule, such as a specification, policy, standard or law …”

[Wikipedia]

Page 8: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Une information ne doit être que là où elle devrait être

• Une information ne doit être visible que par ceux qui devraient la voir

[Hassen Boumaraf]

Malheureusement, ce n’est pas toujours le cas

Page 9: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Quelques chiffres

Page 10: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Records breached (known)Data breaches (known)

3,525 605,742,928Securitybreaches

April 20, 2005 toDecember 20, 2012

Represents United StatesSource: http://www.privacyrights.org

Page 11: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

System glitches

Malicious intent Oops!

39%

24%

37%

Online Trust Alliance: 2013 Data Protection and Breach Readiness Guide

Page 12: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• 29 entreprises ont participé à l’étude en France

• Coût moyen d’un enregistrement compromis : 134€

• Augmentation de 3.3% par rapport à l’année dernière

Page 13: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Page 14: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Comment mettre ces solutions en place dans O365 ?

Page 15: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

O365 et conformité

Page 16: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• France Driver's License Number

• France National ID Card (CNI)

• France Passport Number

• France Social Security Number (INSEE)SWIFT Code

• Taiwan National ID

• Taiwan Passport Number

• Taiwan Resident Certificate (ARC/TARC) Number

• U.K. Driver's License Number

• U.K. Electoral Roll Number

• U.K. National Health Service Number

• U.K. National Insurance Number (NINO)

• U.S. / U.K. Passport Number

• U.S. Bank Account Number

• U.S. Driver's License Number

• U.S. Individual Taxpayer Identification Number (ITIN)

• U.S. Social Security Number (SSN)

Page 17: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Titre/Corps/Pièces jointes

• Policy Tips

• Justification

Page 18: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• eDiscovery

Page 19: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Audit

Page 20: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Page 21: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Equipe conformité

• Intégration de DLP aux solutions MS

• Centralisation des outils de conformité

Page 22: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Page 23: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Communément : Double authentification

Page 24: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Azure Right Management

• Chiffrement de contenu, d’e-mail

Page 25: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• Mobile Device Management

• Mobilité

• Policy

Page 26: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

La conformité au coeur de l’organisation

Page 27: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• CISO / RSSI

• CPO / CIL / DPO

Page 28: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Page 29: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Roadmap

Page 30: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

• SharePoint 2016- Intégration de la recherche

des données sensibles

O365 roadmap : http://success.office.com/en-us/roadmap

Page 31: 2SeeU - Initiation à la conformité dans o365

©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a

retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.

Q / A