Microsoft Purview Information Protection & Data Loss Prevention (DLP)
with Corporate Information Governance & Data Classification

Executive Summary
This engagement delivers a two-phase implementation designed to establish Microsoft Purview Information Protection and Data Loss Prevention capabilities while building an enterprise Information Governance program aligned with NeoCurrency's SOC 2 certification objectives.
Phase 1 – Microsoft Purview Information Protection & DLP
PhaseHoursDeliverables
Discovery & Planning Requirements, compliance objectives, licensing review
Purview Foundation Configure Purview, roles, readiness
Information Protection Up to 5 sensitivity labels, publishing policies, manual/container labeling
Data Loss Prevention Exchange, SharePoint, OneDrive, Teams DLP, policy tips, notifications
Endpoint DLP USB, copy/paste, browser, print controls
Testing & Optimization Pilot, tuning, reporting
Documentation & KT Runbooks, policy matrix, knowledge transfer
Phase 2 – Corporate Information Governance & Data Classification
PhaseHoursDeliverables
Information Governance Assessment Governance workshop, SOC 2 objectives, data owners
Corporate Classification Framework Classification matrix, handling standards, ownership
Enterprise Data Discovery Assess SharePoint, OneDrive, Exchange, Teams
Automatic Classification & Labeling Auto-labeling, classifiers, policy tuning
Corporate Data Tagging & Validation Validation, reporting, bulk tagging strategy
Governance Documentation & Handover Governance framework, standards, executive handover
SOC 2 Alignment
  • Security – Microsoft Purview, DLP, Endpoint DLP
  • Confidentiality – Sensitivity Labels and encryption
  • Privacy – Data classification and governance
  • Processing Integrity – Policy validation and auditing
  • Availability – Operational documentation and runbooks