Strengthening data security in Bahrain: leveraging Microsoft Purview to prevent leakage of sensitive information
Naser F. Aldoseri, Wael Mohamed Elmedany · IET conference proceedings. · 2024
Sensitive information is a category of classified data that must remain inaccessible to unauthorized users and devices. Traditionally, organizations maintained control over sensitive data within the confines of their corporate perimeters. However, COVID-19 has catalyzed a significant shift, compelling employees to transition from office settings to remote work environments. Thus, sensitive information could be potentially exposed to the internet. Notably, two key categories of sensitive information in Bahrain are Bahraini CPR (Central Population Register) and Bahraini passport numbers, whose unauthorized disclosure could have severe consequences for organizations. This paper explores the capabilities of Microsoft Purview in safeguarding these two critical types of sensitive information from unauthorized leakage outside an organization. Microsoft Purview is a cohesive governance unit that provides the capability to manage and govern your data landscape by mapping the sensitive information with discovery automation[1]. Microsoft Purview harnesses the power of two integral components. The first component is the deployment of Sensitive Information Types (SITs), which rely on regular expression (Regex) based patterns to identify the presence of Bahraini sensitive information. A regex-based pattern can be created to detect and prevent the malicious transfer of social security numbers (SSN) [2]. These SITs are further enhanced through a keyword list that assists in refining the framework's ability to locate sensitive data while minimizing false positives. The second component is the Microsoft Data Loss Prevention (DLP) service, designed to detect the sharing of sensitive data both internally and externally through the Microsoft 365 suite, including e-mails, documents, chats, and endpoints.