Metadata, Sensitivity Labels and DLP: A Practical Guide to SharePoint Information Governance

For many New Zealand organisations, good SharePoint permissions and a clear metadata structure provide the foundation to organise and protect data. But for enterprise businesses holding large volumes of sensitive or regulated information, more advanced controls such as DLP policies can be beneficial.

The main controls that can be adopted – depending on information risk and compliance requirements – are:

  • Metadata
  • Sensitivity Labels
  • Retention Labels
  • DLP Policies
  • Endpoint DLP Policies

Metadata

Identifying and organising information in SharePoint.

What it is and why it matters:
Metadata is descriptive information attached to a document, such as document type, business function, customer, supplier, project, owner, status or review date.

It helps users search, filter and report on documents without relying entirely on folders and filenames. It also gives the business a clearer view of what information it holds and how that information relates to its operations.

An example use-case for metadata:

A business could apply metadata to supplier contracts to record:

  • Supplier name.
  • Contract owner.
  • Contract type.
  • Start and expiry dates.
  • Renewal status.
  • Business function.

Staff could then identify contracts due to expire or confirm who is responsible for each supplier contract.

How it is implemented:

It’s important to understand that Metadata does not provide security by itself. A metadata column marked “Confidential” will not automatically protect a document. A security policy or automated process must be applied to act on the classification for it to become a control. Metadata is implemented through SharePoint columns, content types and managed term sets.

Sensitivity Labels

Labelling sensitive information and applying protection.

What they are and why they matter:
Sensitivity labels can be applied to documents and emails, and can also be used to classify and control SharePoint sites and Microsoft Teams environments. They can be used to classify sensitive information or they can apply controls that tell Microsoft how the document should be handled. Label classifications should be business-defined to meet specific information risks and legal requirements.

A simple classification structure might include:

  • Public.
  • Internal.
  • Confidential.
  • Highly Confidential.

An example use-case for sensitivity labels:
An HR manager uploads a new employee’s signed employment agreement to the Employee Records library in SharePoint. The library automatically applies a Highly Confidential – HR sensitivity label which encrypts the document and limits access to approved HR staff.

If the document is downloaded or sent as an attachment, the label and its protection can remain attached to prevent unauthorised people from opening it.

How they are implemented:
Sensitivity labels are managed through Microsoft Purview. The business decides each classification and the controls associated with it.

Labels can then be applied in several ways:

  • An auto-labelling policy applies the label automatically.
  • Staff select a label manually.
  • A SharePoint library applies a default label.
  • Purview recommends a label when sensitive information is detected.

Retention Labels

Managing how long information is kept for.

What they are and why they matter:
Retention labels control how long documents and emails must be retained and what happens when the retention period ends. They can keep information, delete information or send information for review. A retention period can begin when a document is created, modified or when a business event occurs.

A retention label can also declare a document as a record, placing tighter controls on editing and deletion.

An example use-case:
An HR manager uploads a new employee’s signed employment agreement to the Employee Records library. The document receives a retention label that keeps it for the organisation’s required period after the employee leaves.

How they are implemented:
Retention labels are managed through Microsoft Purview. They can be selected by staff, applied automatically based on defined conditions, or set as defaults on document libraries or folders.

Data Loss Prevention (DLP) Policies

Monitoring and controlling how sensitive information is shared.

What it is and why it matters:
Data Loss Prevention (DLP) monitors how sensitive information is accessed and shared across Microsoft 365.

A SharePoint DLP policy can act on sensitivity labels, document properties or sensitive information detected inside a document. The process is simple:

  • When a defined condition occurs, take a specific action.

Depending on the policy, it can:

  • Record the activity.
  • Warn the user.
  • Require a business justification.
  • Notify the document or site owner.
  • Generate an alert for IT.
  • Block external access.
  • Restrict access to the document.

An example use-case for a DLP rule:
A DLP rule could be configured as follows:

Condition: A document has the Highly Confidential sensitivity label.
And: A user attempts to give an external recipient access through a SharePoint sharing link.
Action: Block the external recipient, notify the document owner and generate an IT alert.

How it is implemented:
DLP policies are configured in Microsoft Purview by defining:

  • The locations to monitor, such as SharePoint, OneDrive or Exchange.
  • The labels, metadata or sensitive information to detect.
  • The users or recipients covered by the rule.
  • The action to take.
  • Whether users can override the warning.
  • Who should receive alerts.


Endpoint DLP

Controlling sensitive information on managed computers.

What it is and why it matters:
Endpoint DLP extends Microsoft Purview controls beyond SharePoint and out across managed computers. It helps control what a user can do after downloading a sensitive document from SharePoint.

Endpoint DLP can monitor or restrict:

  • Copying files to USB storage.
  • Copying files to network locations.
  • Copying information to the clipboard.
  • Printing.
  • Uploading files to restricted websites.
  • Opening sensitive information through unapproved applications or browsers.

An example use-case:
A staff member may have a legitimate reason to access a Confidential customer report in SharePoint. The business may allow them to open and edit the document, but an endpoint DLP rule prevents them from:

  • Copying it to a personal USB drive.
  • Uploading it to personal cloud storage.
  • Printing or sending it to an unapproved printer.
  • Copying customer information into an unapproved application.

How it is implemented:
Endpoint DLP is managed through Microsoft Purview and applied to supported devices that have been onboarded into the business’s relevant Microsoft security services.


Where should a business start?

Where should a business start? Do you need every layer now?

A business should not switch on every available restriction across every SharePoint site. A SharePoint document security strategy should be manageable in terms of the business’s compliance requirements and Microsoft licensing. Every organisation will have different requirements.

Start by understanding where the greatest risks exist.

1. Identify high-risk information.
Focus first on SharePoint sites containing:

  • Employee and payroll records.
  • Customer personal information.
  • Financial documents.
  • Contracts and commercial information.
  • Legal documents.
  • Board and management information.
  • Cyber security and system information.

2. Review access and sharing.
Confirm who can access each site, whether access is still required, whether external sharing is enabled and whether users can download information.

3. Define a simple, risk-based classification model.

  • Public
  • Internal
  • Confidential
  • Highly Confidential

4. Define useful metadata.
Choose metadata that supports a search or reporting requirement, such as document type, business function, customer, project, owner, status or review date.

5. Introduce DLP gradually.
Early DLP policies might focus on documents labelled Highly Confidential and monitor the following activity:

  • External sharing or uploading to unapproved websites.
  • Copying to USB storage.

6. Review classifications and controls when the use of the information or business risk changes.


A layered approach.

Each tool performs a different job but layered together they provide protection across the document’s lifecycle.

Metadata identifies the document, sensitivity and retention labels classify it, DLP controls inappropriate sharing, and Endpoint DLP controls selected activity outside of SharePoint on managed devices.

How Podcom can help.

Podcom helps New Zealand businesses manage their SharePoint and Microsoft 365 environments through our vCISO Services. We can assess existing document structures and sharing controls, then develop a practical approach to information governance that supports security without making every day work difficult.