ASD's Blueprint for Secure Cloud

PROTECTED CABINET Personal Privacy sensitivity label

This section describes the configuration of sensitivity labels within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

Label details

Provide basic details for this label

ItemValue
Parent labelPROTECTED CABINET (group)
NameP C PP
Display NamePersonal Privacy
Label Priority24 in label group
Description for UsersHigh business impact. Damage to the national interest, organisations or individuals.
Description for adminsNone
Label colorNone selected

Scope

Define the scope for this label

ItemValue
- Files & other data assetsChecked
- EmailsChecked
- MeetingsChecked
Groups & sitesChecked
Schematized data assets (preview)Not checked

Items

Choose protection settings for the types of items you selected

ItemValue
Control accessChecked
Apply content markingChecked
Protect Teams meetings and chatsNot checked

Access control

ItemValue
Configure access control settingsSelected
Assign permissions now or let users decide?Assign permissions now
User access to content expiresNever
Allow offline accessOnly for a number of days
Users have offline access to content for this many days3
Assign permissions to specific users and groupsAdd users or groups
- Permissions assigned to<PROTECTED users group>
<PROTECTED guests group>
<external organisation's domains used for email>
- Choose permissionsOwner
Use dynamic watermarkingNot checked
Use Double Key EncryptionNot checked

Content marking

ItemValue
Content markingEnabled
Add a watermarkNot checked
Add a headerChecked
- Header textPROTECTED//CABINET//Personal Privacy
- Font size12
- Font colorRed
- Align textCenter
Add a footerChecked
- Header textPROTECTED//CABINET//Personal Privacy
- Font size12
- Font colorRed
- Align textCenter

Auto-labeling for files and emails

ItemValue
Auto-labeling for files and emailsNot enabled

Groups & sites

Define protection settings for groups and sites

ItemValue
Privacy and external user accessChecked
External sharing and Conditional AccessChecked
Private teams discoverability and shared channel settingsNot checked
Apply a label to channel meetingsPROTECTED CABINET (group)/Personal Privacy1

1: This setting may only be available when editing the label after creation.

Define privacy and external user access settings

ItemValue
PrivacyPrivate
Let Microsoft 365 Group owners add people outside your organization as guestsNot checked

Define external sharing and conditional access settings

ItemValue
Control external sharing from labeled SharePoint sitesChecked
- Content can be shared withOnly people in your organisation
Use Microsoft Entra Conditional Access to protect labeled SharePoint siteChecked
- Choose and existing authentication contextPROTECTED information -

Security & Governance

  • None identified

Design

Configuration

  • None identified

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra