Accessible content is available upon request.
Initiation à la conformité dans O365
Hassen Boumaraf, Senior Technical Account Manager
Hassen.Boumaraf@avepoint.com
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Définitions
Quelques chiffres
Roadmap
Office 365 et conformité : Démo
La conformité au coeur de l’organisation
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Définitions
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Métiers Personnelles
Finance : N° de carte
bancaire
Visa, Amex, MasterCard
RH / Médicales
N° de Sécurité Sociale
Denmark Personal
Identification Number
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Métiers Personnelles
PCI – DSS
SOX (Sarbanes-Oxley)
HIPAA
loi Informatique et
Libertés et la Directive
Européenne 95/46/EC
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• “A data breach is a security incident in which sensitive,
protected or confidential data is copied, transmitted,
viewed, stolen or used by an individual unauthorized to
do so”
[U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES Administration for Children and Families]
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• “Compliance means conforming to a rule, such as a
specification, policy, standard or law …”
[Wikipedia]
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Une information ne doit être que là où elle devrait être
• Une information ne doit être visible que par ceux qui
devraient la voir
[Hassen Boumaraf]
Malheureusement, ce n’est pas toujours le cas
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Quelques chiffres
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Recordsbreached(known)Databreaches (known)
3,525 605,742,928Security
breaches
April20, 2005 to
December20, 2012
RepresentsUnitedStates
Source:http://www.privacyrights.org
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
System glitches
Malicious intent Oops!
39%
24%
37%
OnlineTrustAlliance:2013DataProtectionandBreachReadinessGuide
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• 29 entreprises ont participé à l’étude en France
• Coût moyen d’un enregistrement compromis : 134€
• Augmentation de 3.3% par rapport à l’année dernière
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Comment mettre ces solutions en place dans O365 ?
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
O365 et conformité
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• France Driver's License Number
• France National ID Card (CNI)
• France Passport Number
• France Social Security Number (INSEE)SWIFT Code
• Taiwan National ID
• Taiwan Passport Number
• Taiwan Resident Certificate (ARC/TARC) Number
• U.K. Driver's License Number
• U.K. Electoral Roll Number
• U.K. National Health Service Number
• U.K. National Insurance Number (NINO)
• U.S. / U.K. Passport Number
• U.S. Bank Account Number
• U.S. Driver's License Number
• U.S. Individual Taxpayer Identification Number (ITIN)
• U.S. Social Security Number (SSN)
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Titre/Corps/Pièces
jointes
• Policy Tips
• Justification
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• eDiscovery
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Audit
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Equipe conformité
• Intégration de DLP aux solutions MS
• Centralisation des outils de conformité
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Communément : Double authentification
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Azure Right Management
• Chiffrement de contenu, d’e-mail
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• Mobile Device Management
• Mobilité
• Policy
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
La conformité au coeur de l’organisation
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• CISO / RSSI
• CPO / CIL / DPO
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Roadmap
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
• SharePoint 2016- Intégration de la recherche
des données sensibles
O365 roadmap : http://success.office.com/en-
us/roadmap
©AvePoint, Inc. All rights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a
retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
Q / A

Initiation à la conformité dans Office365

  • 1.
    Accessible content isavailable upon request. Initiation à la conformité dans O365 Hassen Boumaraf, Senior Technical Account Manager Hassen.Boumaraf@avepoint.com
  • 2.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Définitions Quelques chiffres Roadmap Office 365 et conformité : Démo La conformité au coeur de l’organisation
  • 3.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Définitions
  • 4.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Métiers Personnelles Finance : N° de carte bancaire Visa, Amex, MasterCard RH / Médicales N° de Sécurité Sociale Denmark Personal Identification Number
  • 5.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Métiers Personnelles PCI – DSS SOX (Sarbanes-Oxley) HIPAA loi Informatique et Libertés et la Directive Européenne 95/46/EC
  • 6.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • “A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so” [U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES Administration for Children and Families]
  • 7.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • “Compliance means conforming to a rule, such as a specification, policy, standard or law …” [Wikipedia]
  • 8.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Une information ne doit être que là où elle devrait être • Une information ne doit être visible que par ceux qui devraient la voir [Hassen Boumaraf] Malheureusement, ce n’est pas toujours le cas
  • 9.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Quelques chiffres
  • 10.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Recordsbreached(known)Databreaches (known) 3,525 605,742,928Security breaches April20, 2005 to December20, 2012 RepresentsUnitedStates Source:http://www.privacyrights.org
  • 11.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. System glitches Malicious intent Oops! 39% 24% 37% OnlineTrustAlliance:2013DataProtectionandBreachReadinessGuide
  • 12.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • 29 entreprises ont participé à l’étude en France • Coût moyen d’un enregistrement compromis : 134€ • Augmentation de 3.3% par rapport à l’année dernière
  • 13.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
  • 14.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Comment mettre ces solutions en place dans O365 ?
  • 15.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. O365 et conformité
  • 16.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • France Driver's License Number • France National ID Card (CNI) • France Passport Number • France Social Security Number (INSEE)SWIFT Code • Taiwan National ID • Taiwan Passport Number • Taiwan Resident Certificate (ARC/TARC) Number • U.K. Driver's License Number • U.K. Electoral Roll Number • U.K. National Health Service Number • U.K. National Insurance Number (NINO) • U.S. / U.K. Passport Number • U.S. Bank Account Number • U.S. Driver's License Number • U.S. Individual Taxpayer Identification Number (ITIN) • U.S. Social Security Number (SSN)
  • 17.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Titre/Corps/Pièces jointes • Policy Tips • Justification
  • 18.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • eDiscovery
  • 19.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Audit
  • 20.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
  • 21.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Equipe conformité • Intégration de DLP aux solutions MS • Centralisation des outils de conformité
  • 22.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
  • 23.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Communément : Double authentification
  • 24.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Azure Right Management • Chiffrement de contenu, d’e-mail
  • 25.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • Mobile Device Management • Mobilité • Policy
  • 26.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. La conformité au coeur de l’organisation
  • 27.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • CISO / RSSI • CPO / CIL / DPO
  • 28.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc.
  • 29.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Roadmap
  • 30.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. • SharePoint 2016- Intégration de la recherche des données sensibles O365 roadmap : http://success.office.com/en- us/roadmap
  • 31.
    ©AvePoint, Inc. Allrights reserved. Confidential and proprietary information of AvePoint, Inc. No part of this may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written consent of AvePoint, Inc. Q / A

Editor's Notes

  • #5 PCI : Payment Card Industry  (Standard PCI - Payment Card Industry Data Security Standard ) PII : Personally identifiable information ou Données personnelles : Information pour identifier une personne PHI : Protected health information
  • #6 US : FinServ / HealthCare / Oil&Gas / Public Sector Standard PCI - Payment Card Industry Data Security Standard  HIPAA : The Health Insurance Portability and Accountability Act : Loi concernant la protection des données médicales . Dans le cadre dune étude pour la validation d’un médicament SOX : Loi imposant de nouvelles règles sur la comptabilité et la transparence financière
  • #7 Voici la définition de fuite de données /violation donnée par le ministère de la santé américain,
  • #9  Comme vous le voyez, cette définition est de « Moi », de ce que je rencontre sur le terrain Cette obligation vous incombe, que vous soyez On premises ou Online. Donc, une bonne partie des contraintes est valable aussi bien On premise qu’online Dans un monde parfait, on dirait que c’est du bon sens, sauf que dans la réalité, il en est autrement. Dans ce qui suit, nous allons évoquer les situations critiques
  • #14 Toujours selon l’étude IBM/Ponemon, les mesures les plus populaires suite à un incident sont classées dans ce tableau. Ce que l’on remarque aussi c’est que le recours aux procédures manuelles décroit au fil du temps
  • #24 Ce qui est intéressant c’est qu’elle est sélective, je peux l’activer pour mes utilisateurs nomades : Sales
  • #26 Principe d’authetification forte
  • #27 Comment faire du business
  • #28 CISO : Chieh Information Security Officer / US (Secteurs réglementés) RSSI : responsable de la sécurité des systèmes d'information CPO : Chief Privacy Officer CIL : Correspondant Informatique et Liberté / CPO : Chief Policy Officer DPO : Data Protection Officer
  • #29 Le cout d’un enregistrement compromis  Sensibilité à la fuite de données
  • #31 CISO : US (Secteurs réglementés) RSSI : FinServ Depuis 2005, plus de 250 personnes : CIL : Correspondant Informatique et Liberté / CPO : Chief Policy Officer DPO : Data Protection Officer