by

Office 365 DLP protection cool again

Thank you everyone who came to see me talking about Office 365 DLP, Privacy, Data Leakage Protection. Office 365 User group at Microsoft Brisbane offices.

I love doing these things for the community! Feel free to reach out if you need anything or want to talk more about it.

by

BYOD Guidelines and Office 365 DLP


Let's talk about "Bring Your Own Device"(BYOD) again. We all know how often people have devices which are more capable than what their current organizations/employers offer. Rightly so, to keep all devices and all systems updated across the enterprise it is still a huge, and expensive, task. BYOD has a security framework that allows the regular folks to being their own laptops or mobiles to use at work.

The issue starts when company data is exposed in a risky way. Would your manager be OK with you having an spreadsheet with people's contacts details, addresses and sometimes financial values? hint: the answer should be NO; otherwise you guys needs to have the "data protection talk" :)

The key here to make sure the risks do not outweight the benefits of BYOD is to make sure reasonable steps were taken to mitigate data leakage and exposure to the wild web.

office-365-byod-guide

And that brings us to the point I wanted to discuss. Canada is one of the first nations to move in this direction with a comprehensive set of guidelines for mitigation polices. More precisely, the Office of the Privacy Commissioner of Canada released a guide (Is a Bring Your Own Device (BYOD) Program the Right Choice for Your Organization?) highlighting several key privacy and security risks that you and your organization should take into consideration for a BYOD program.

This is a Canadian perspective but some of the points are excellent for your own discussions. It is a long document but if we can summarize the main points they recommend are...

office-365-byod-guide-2

Perform an Impact and Threat Risk Assessment

Privacy Impact Assessment (PIA) and a Threat Risk Assessment (TRA) needs to be done to identify and address risks associated with the acquisition, handling, storage and period retention of personal identifiable information (PII). If you've been to any of my presentations, you see how much focus and stress I put on the demos with personal data. They are extremely valuable and can do real damage to everyone involved, people and companies.

Create specific BYOD policies

Dedicated BYOD policies needs to be developed, consolidates and established for all devices covered in the program. Training here is essential. All users part of the BYOD program must have a clear set of expectations about what they can and can't do with their devices, including training on privacy protection and defensive data handling (to mitigate security threats). The guide recommends for CTO offices engage directly with other departments. The objective here is to develop enforceable, easy-to-communicate BYOD policies. There is no point in having a hard to follow/hard to understand framework across the board. In short they should address at a minimum: user responsibilities, acceptable uses of BYOD devices, application management and access requests.

Containerization

Containerization means group and isolate corporate data that might be living offline in an employee's device. The goal here is to create a division between personal data (for example, family pictures in your mobile) and company data (for example, sales forecast documents, resumes etc).

Incident Management

Let's face it, doesn't matter how much effort and controls we put around a technology, at some point the data will likely be compromised. The question here is: What to do when this happens? Technology is a living thing. In 5 years from now, the technology landscape will be totally different from when we have today. So, when a a privacy or security breach happens, an mature and well-thought out incident management process needs to be in place. The goals here are to identify the root cause, report, analyse and correct the breach in a timely fashion...and then use the learnt lessons for the future.

Inventory

As part of the incident management, the guide recommends that companies should create an inventory of the connected devices. The goal here is to take appropriate steps during an incident response. Users must understand that personal devices which are not adequately secured might expose company information to malicious elements and this often leads to financial loss (for losing competitive advantage, reputation damage etc).

All these are great points and at first they seems very obvious. Tricky part here is that the obvious is hard to implement.

BYOD Program Seems Too Complex for Our Company

If you are reading this and think that your organization can't have a BYOD program because these guidelines might be too hard to implement, don't worry there are still steps you can do to make sure you meet them halfway. More and more the workforce is digital and users are demanding these programs. My 2 cents here is that the organization should aim to have a secure enough environment where the benefits of a smaller BYOD program can be leveraged. The main thing in any security program is still the same: User education. We are becoming so technologically connected, with machines so auto-sufficient yet the main component always was, still is (still will be?) people.

If you found this interesting, let me know what you think in the comments.

by

New Yammer Office 365 Features

If you're a current user of Yammer, you will be pleased to hear the great news Yammer team have done for you.
If you're not, I recommend for you to give it a try. In short, Yammer is like a "Facebook" for the enterprise.

edge-pereira-yammer-sample

It was acquired by Microsoft and soon later incorporated under the Office 365 umbrella.

It's great integration with document authoring tools and a very intuitive and responsive design are the coolest features of the product. This month, Microsoft made some announcements for the product that aim to raise its profile and increase adoption by the users across the board.

edge-pereira-yammer-sample-2

Immersive Experience

Files now can be previewed and edited straight out of Yammer. A unobtrusive window will appear on top of your browser session with the Office Online tool required to edit your document and then saved directly to the cloud. Changes made in the file are appropriately tracked with out-of-the-box versioning.

External Collaborators

Another cool feature from Yammer is the ability to share document with people outside your organization, if needed. Now Microsoft is taking this to the next step: External people can collaborate on the document together with your team is needed. This is not a paid feature, this is now available to everyone using Yammer.

Real-Time Co-Authoring

Document preview in Office Online is already available as of today. Real-Time Co-Authoring is in the roadmap for early 2016.

If you use Yammer, feel free to engage in the conversation in the comments. If not, what are you waiting for? :) join the fun. You can even create a Yammer network for your own family members, for example. Like your own family Facebook!

by

Office 365 Saturday Australia


Everyone is invited to this awesome event. Let’s talk about the digital workplace, office 365, SharePoint 2016 and BYOD !! Make sure to block your calendars, Brisbane.

visit: www.o365saturdayaustralia.com

edge-pereira-office365-dlp

by

Office 365 is now certified by the Australian Government DLM Documents

If you work in with government departments in Australia. Office 365 has great news for you. Office 365 is now certified by the Australian government to handle and store Federal documents.

Before we go a bit deeper in what this represents and ramifications, bear with me while we set the baseline for the discussion.

Let me introduce to you the Australian Signals Directorate (ASD). This is a Federal agency that collect and analyses intelligence sources  and provide services for data security and advice for the Australian government and Defence Force. We are talking here about highly capable and focused security IT people in the matters of data protection and data handling. Storing Australian government data in the cloud needs to be assessed by these folks. And they just certified Office 365 for that matter.

edge-pereira-DLP-office-365-Australian-signals-directorate

Quick comment: have a look at how cool is their logo: “Reveal their secrets…Protect Our Own”.

That's very cool. And there is more...The same certification is also extended to Windows Azure. If you’re keen to see how ASD assesses the Cloud providers for regulations suitability, here’s the guide. If you work with data compliance and regulation in the cloud this *is important* !

What it means?

it means they have certified the Office 365 existing document controls as qualified for storing Government data. Which means, they just gave their OK that "Office 365 Controls are good for our Government. If you have documents and you plan to store them in the cloud, Microsoft is OK with us."

Now that does not apply to *all* kinds of documents. Which takes us to the next point.

Unclassified DLM Documents

Let's talk now about a document type called "Dissemination Limiting Markers", or DLM. Every time you go to a governmental agency and fill up forms (such as driver's licence or REGO renewal forms) you see that they have a section called 'for official use only'. These type of documents are deemed *not highly classified* but require controls over sharing capabilities or fully prohibited by legislation or require special handling are classified as DLM. These are the ones you can use with Office 365 in Australia.

Now...Something needs to be said about Data Classification, which is a bit of a grey area and up for discussion (I am not a lawyer so take this with a grain of salt).

The catch with data classification is that each agency is responsible for classifying their own documents, including what is and what's not DLM. There is not a blanket rule addressing that.

If you are an IT professional

This matters for you. While the competition is using "blanket solutions" (one size fits all) to address cloud data regulation, privacy and protection, Microsoft is actually taking the time to sit down with legislators, policy makers and so on and is addressing each one of their concerns in their legislation. By doing this Microsoft solutions aims to offer a much better granularity, item by item. An Office 365 solution will likely fit perfectly the requirements because it will address each one of them individually. We should expect to see more progress and more classification types arising very soon.

If you are a Business Executive

This matters for you. I know how busy and how focused you are trying to close the deals and selling the solution to the customer. So here's a quick list of things that are sellable projects:

  • Archiving in the cloud: This certification from the Australian authorities now offers a possibility for you to engage (sell a project) directly with agencies with a pre-approved template. Show them how to move their forms to the cloud.
  • Document classification transformation: Help them with document classification to match the cloud approved regulations.
  • Electronic forms: Help agencies to convert their documents to eFormat, so people can fill them BYOD-style.
  • Codeword Discovery: Deliver a codeword discovery and implementation on metadata to ensure automatic Office 365 data leakage protection controls and compliance to the Australian standards. An stretched goal on this can be and to implement a document classification rule suah as FYEO ("for your eyes only"), where only a group of people can open certain document types. Even in the case of forward this document or it's link to someone else they will not be able to read it.
  • Accountable Material: Setup an "accountable material", where restrictions are applied across the dissemination and distribution of a document and to make the forward originators accountable and identifiable following the new Australian metadata retention laws. (eDiscovery)
  • Electronic Seal: Deliver a solution that allows sealing electronically emails in Exchange following the Australian ISM requirements.

One more thing before you go

Now, all this is a great deal of Legal/IT/Cloud stuff. I mean, this is touchy subject. I really do! So before anyone starts saying "we can't do this!" or "such ideas are not possible because XYS" I just to make it clear that this landscape clearly needs engagement from a Legal representative across the board. This is not an IT  project, this is likely a business transformation project where IT plays a great role offering the right controls.
I dare to say that, soon in the Government-focused cloud projects:
- We will see more and more cross-discipline collaboration involving Legal, Business and IT departments...a type of the Avengers Assemble for delivery :)
- Also the expectation that things will move slow. Government regulations are massive engines and its advances are really done at their own pace and liking. Their ramifications affect nations and the way markets operate.

And these were my 2 cents.

If you're involved in data protection, regulation, compliance cloud projects feel free to share your experiences.

by

How to Use OCR in OneNote. Awesome Feature.

This is an interesting one. Every time we do meetings with customers and I need to convert image to text, I use the OCR capabilities from OneNote. And every time I hear "WOW!" from the people.

It led me to conclude: This is a fantastic not-well-known feature, it must be promoted more. In this video I do a quick demo on how it works. If you knew this, great!! If not, I hope you use it more now and also share the news.



by

Stop Talking About Yourself to a Customer

DSC_1318In consulting, one thing I've learned is that one of the things customers hate most is when you spend time talking about yourself. Ok, maybe they don't literally hate, but they couldn't care less about your company of what you do. So, don't talk about yourself or how awesome your company is for a customer, specially if it is one of your first contacts with them.

So, Here's the Golden Tip...

They want to hear about *their* company, about *their* needs. Start talking about their company, their needs, their challenges and how you can be the glue to connect problem and solution.

You know, these 60 PowerPoint slides you want to show to them? forget about it. Pay attention at their body language. Around the slide #10 they will be checking their emails, their Yammer network and...god forbid... they may even be checking their Facebook!!

Get Them Engaged

It's nothing against you. They are basically waiting for you to finish what you have to say so they can see afterwards how can you help them solve their problems. If they are patient, they will wait...that's normally a BAD sign. If not, they will start asking questions and skip jump your presentation script...that's is normally a  GOOD sign.

In the new marketplace, they already know your company, they already know what you do. They Googled you, your company.

Also get rid of those slides about your prizes, your offices in Tokyo or London. OK so you do need to show them, at least don't spend too much time talking about them. It is OK to show at some point but don't spend precious time promoting yourself during their time. I like this point: When you have a customer presentation think this way, they are giving you THEIR time to you so what do you do: talk about yourself or how awesome your company is? Stop that, please! :-) Cut to the chase, talk about real solutions for their real problems.

Be Careful With Your Perception

Don't oversell. They already expect you to be a good company, they already expect you to offer a quality service, they already expect you to offer a fair price (regardless if it is a premium service). If you tell them your differential are these things they will put you on the hook for it.

You Don't Need to Say Anything

You're there to listen. You're there to make open questions about their needs, problems. And maybe some one of your slides address that, so just jump to that slide. Don't need to go one by one until you get there.

You're There to Help Them, Not to “Sell”

Eliminate the sales jargon from your pitch. Be authentic, be passionate about your intentions which are "I am here to help you with problem X". in my opinion, is should be your/our messaging.
by

What Defines Personal Information/Data in the Cloud ?

 

The cloud technology is great. It allows people and systems to deliver applications to a global scale, with ease and great management power. Data can be stored and retrieved from anywhere in the world. This is a huge benefit, and equally huge challenge.

cloud

If you deal with legal documents, store personal information, then independent of your preferred cloud provider (Microsoft, Amazon AWS, Google, IBM, HP etc.) there are challenges you need to consider to manage privacy issues.

The Case for Personal Identifiable Information

Many countries have laws that regulates how personal information data (PI) should be handled. For example, I live in Queensland, Australia and here we have the Information Policy Act 2009 also known as PI Act. This law defines what is PI data here:

"...information or an opinion, including information or an opinion forming part of a database, whether true or not, and whether recorded in material form or not, about an individual whose identify is apparent or can be ascertained".

This is definition is already a great start to help identifying PI data for cloud projects. If you're curious on what's and what's not PI data, the Office of the Information Commissioner (OIC) has a checklist that address this question.

Not All Bytes are Born the Same

It is important to say that laws like the PI Act are applied to personal identifiable data, not only this law can be applied. Any other laws may come on top of that, for example laws that regulates insider trading, or identity theft, for example.

Now that we know the scope of the regulations, the next thing to be aware is that not all data is the same. It means that the type of information and its sensitivity levels have a direct impact on how the data needs to be handled.

Privacy Impact Assessment

Generally speaking, it is common for cloud migration projects handling such data to have them identified in the assessment phase. In these cases, if any personal information is found (for example, a database table that has names and street addresses or an Excel file that contains telephone numbers) a privacy impact assessment (PIA) is conducted. This PIA will generate a report that cross-check the data identified, the impact in the cloud project delivery and how to minimize or avoid any privacy risks involved.

And we are talking here only about data. The next item to check in your cloud migration project is the data flow. Data flow is equally important because what it is "legal" in a place might not be in another. For example, let's assume that Company X applied all measures required by law to protect personal data for a company, however this company has headquarters in another country. Could an email between offices of these 2 countries be shared with the same content?

So as you see, data flow can be as complex as data controls, but we will talk about this on another time.

Images from @MSAU

by

SharePoint Paris 2015 Office 365 DLP

parisIn May 2015 I was both lucky and honoured with an invitation to present at the inaugural SharePoint Paris 2015. Fantastic event! lots of Microsoft people and MVPs from across the world.
If you came to my session, my wholeheartedly thank you and I hope you enjoyed watching it as much as I did presenting it.
Here are the slides of the session.

by

How to Add Simple Authentication to Azure Website

During my last Azure Website project, we had to setup a staging environment in order to test the website being deployed. By nature, all Azure Websites are opened to everyone to see, however the need to protect the content being tested came up for several reasons. We were running on a tight deadline and we did not want to spend too much on configuring this authentication. The solution we found was to leverage from the provided IIS and .NET capabilities already provided by Azure and setup a simple authentication mechanism using a static username and password.

Blueprint


For this case we needed 3 things:
  1. a web.config file with the authentication configuration
  2. a Login.aspx page that comes up for the visitors to enter the credentials
  3. a javascript hookup binding the page and the web.config

Once you have all these elements, what you do is to upload these files (via FTP) to your Azure Website. The IIS hosting will automatically recognize them and the changes will take effect immediately.

Solution


The solution took about 10 minutes to build and to save you this valuable time here is the code for both web.config and login.aspx (included with the javascript) you need:
<?xml version="1.0"?>
<configuration>
<system.web>
<compilation debug="false" />
<authentication mode="Forms">
<forms>
<credentials passwordFormat="Clear">
<user name="AddYourUserNameHere" password="AddYourPasswordHere" />
</credentials>
</forms>
</authentication>
<authorization>
<!-- Allow access to all who can match the username and password -->
<allow users="*" />
<!-- Denies access to anonymous users -->
<deny users="?" />
</authorization>
</system.web>

<system.webServer>
<modules>
<remove name="FormsAuthenticationModule" />
<add name="FormsAuthenticationModule" type="System.Web.Security.FormsAuthenticationModule" />
<remove name="UrlAuthorization" />
<add name="UrlAuthorization" type="System.Web.Security.UrlAuthorizationModule" />
</modules>
</system.webServer>
</configuration>



And here’s the code for the login.aspx file you will need.

<%@ Page Language="C#" %>
<%@ Import Namespace="System.Web.Security" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<script runat='server'>
public void Login_OnClick(object sender, EventArgs args)
{
if (FormsAuthentication.Authenticate(UsernameTextbox.Text, PasswordTextbox.Text))
{
FormsAuthentication.RedirectFromLoginPage(UsernameTextbox.Text, NotPublicCheckBox.Checked);
}
else
{
Msg.Text = "Login failed.";
}
}
</script>
<html xmlns="http://www.w3.org/1999/xhtml" >
<head><title>Simple Login Authentication</title></head>
<body>
<form id="form1" runat="server">
<h3>Simple Login Authentication</h3>
<asp:Label id="Msg" ForeColor="maroon" runat="server" /><br />
Enter the user name: <asp:Textbox id="UsernameTextbox" runat="server" /><br />
Enter the password : <asp:Textbox id="PasswordTextbox" runat="server" TextMode="Password" /><br />
<asp:Button id="LoginButton" Text="Login" OnClick="Login_OnClick" runat="server" />
<asp:CheckBox id="NotPublicCheckBox" runat="server" />
</form>
</body>
</html>


Well, that’s it. I hope you liked and it saved you some Google searches and time Smile

by
by

Office 365: Privacy, Compliance and Data Leakage Protection

Thank you everyone who attended my presentation at Infrastructure Saturday #infrasat on Office 365 : Privacy, Compliance and Data Leakage Protection. Fantastic crowd. Great engagement and questions. Feel free to reach out if needed anything. 

Here are the slides: http://1drv.ms/1v767mF


by
by

How to host json file on Azure Website

Recently our project team developed an application and we intended to host it using an Azure Website, due to its convenience, price and easy of use. It worked well in the local drive and in the local web server..so if we just copy the site to another place it should work, right?

Wrong, if the other site is an Azure Website. If you do, you will note that all accesses to the JSON file will result in a 404 error.

The Problem

To make short a long story, that's because Azure Websites have a few MIME file types blocked by default and .json is one of them. And for the record, .svg is another one. 

The Fix

Luckily all Azure Websites are really IIS servers running on .Net. If you have some basic knowledge of IIS and .Net you know that we can control these security things via web.config. And that is what you need to do: Place a web.config file that tells IIS to allow the file extension.

To save you the trouble, here's the code to allow json and .svg to be served on Azure Website:

<?xml version="1.0"?>
<configuration>
    <system.webServer>
        <staticContent>
            <mimeMap fileExtension=".json" mimeType="application/json" />
     </staticContent>
    </system.webServer>
</configuration>

Just save this as a web.config and copy to the root folder of your application.

I hope this little trick saved you lots of time!

Cheers,
by