Read more
From our Security & Infrastructure experts
A key pillar in Microsoft's Zero Trust Framework is protecting (sensitive) data, as described in our first Security Blog on the Zero Trust Framework. The components of Confidentiality, Integrity and Availability - also known as the CIA triangle - apply to the data that lives within Microsoft 365 and Azure. This blog explains how the various products within Microsoft 365 ensure that the components of the CIA triangle are met, data is protected and your organization can comply with laws and regulations.
Data must be confidential (Confidentiality) so that only the right people can access it. Integrity of data is also an important aspect, in which respect the data remains consistent and is not modified at the source location or at the time of 'transport'. Availability is the third aspect of the CIA triangle, which is to ensure that data is available to the right people at all times.
In order to have data read and/or edited correctly both internally and externally, it is important to have insight into which employee, groups of employees and/or external parties are allowed access to certain information. For example, sensitive information such as strategies or product developments should only be viewed by management and not by the rest of the organization or external parties. Other types of information can be shared freely within the organization but must not leave the organization. In such cases, it is necessary to apply Sensitivity Labeling.
Through Sensitivity Labeling, it is possible to secure documents, emails and Microsoft Teams, allowing only the right people to access documentation. A sensitivity label can be set up for each hierarchical layer in the organization, in which it is possible to apply specific settings. One such setting is when a document or email is given a specific sensitivity label, for example, it can be encrypted (scrambled), preventing unauthorized persons from easily opening it.
Sensitive information can leave the organization in different ways. A document can be shared from Microsoft Teams, email or a Microsoft chat. Data Loss Prevention (DLP) within Microsoft 365 ensures that sensitive data cannot be shared with external parties. Microsoft 365 then automatically ensures that documents, emails or chats containing GDPR-sensitive information are not shared with external parties, for example. DLP can be used in conjunction with Sensitivity Labeling, which makes it a priori impossible to share labeled files with externals and/or specific internals.
To properly protect and handle personal data, more than 70% of countries worldwide have implemented privacy laws in recent years. One example is the GDPR within the European Union. Sensitivity Labeling and applying DLP help organizations within Microsoft 365 be GDPR-compliant. As an addition, managing and retaining information for a certain period of time - according to laws and regulations - also deserves an important place.
Among other things, the GDPR requires personal information to be deleted after a certain period of time. Retention labeling in Microsoft 365 enables management and (automatic) deletion of data in selected applications, such as Microsoft Teams, SharePoint and Exchange.
The aforementioned Microsoft Information Protection products and their capabilities can be applied in numerous ways. Step by step, these products ensure that organizations are compliant, keeping data protected and manageable as desired on the basis of the Confidentiality, Integrity and Availability (CIA) triangle
Read more
From our Security & Infrastructure experts


Want to know how Information Protection is applied and your organization can stay compliant?
Of course, there is much more to discover about Sensitivity Labeling, DLP and the GDPR. Want to know how your organization is taking an active stance on IT security? Our Infrastructure & Security experts are ready to help
We, and third parties, use cookies on our website. We use cookies to keep statistics, to save your preferences, but also for marketing purposes (for example, tailoring advertisements). By clicking on 'Settings' you can read more about our cookies and adjust your preferences. By clicking 'Accept all', you agree to the use of all cookies as described in our privacy and cookie policy.
Purpose
This cookie is used to store your preferences regarding cookies. The history is stored in your local storage.
Cookies
Location of Processing
European Union
Technologies Used
Cookies
Expiration date
1 year
Why required?
Required web technologies and cookies make our website technically accessible to and usable for you. This applies to essential base functionalities such as navigation on the website, correct display in your internet browser or requesting your consent. Without these web technologies and cookies our website does not work.
Purpose
These cookies are stored to keep you logged into the website.
Cookies
Location of Processing
European Union
Technologies Used
Cookies
Expiration date
1 year
Why required?
Required web technologies and cookies make our website technically accessible to and usable for you. This applies to essential base functionalities such as navigation on the website, correct display in your internet browser or requesting your consent. Without these web technologies and cookies our website does not work.
Purpose
This cookie is used to submit forms to us in a safe way.
Cookies
Location of Processing
European Union
Technologies Used
Cookies
Expiration date
1 year
Why required?
Required web technologies and cookies make our website technically accessible to and usable for you. This applies to essential base functionalities such as navigation on the website, correct display in your internet browser or requesting your consent. Without these web technologies and cookies our website does not work.
Purpose
This service provided by Google is used to load specific tags (or trackers) based on your preferences and location.
Why required?
This web technology enables us to insert tags based on your preferences. It is required but adheres to your settings and will not load any tags if you do not consent to them.
Purpose
This cookie is used to store your preferences regarding language.
Cookies
Why required?
We use your browser language to determine which language to show on our website. When you change the default language, this cookie makes sure your language preference is persistent.
Purpose
This service is used to track anonymized analytics on the HSO.com application. We find it very important that your privacy is protected. Therefore, we collect and store this data anonymously on our own servers. This cookie helps us collect data from HSO.com so that we can improve the website. Examples of this are: it allows us to track engagement by page, measuring various events like scroll-depth, time on page and clicks.
Cookie
Purpose
With your consent, this website will load Google Analytics to track behavior across the site.
Cookies
Purpose
With your consent, this website will load the Google Advertising tag which enables HSO to report user activity from HSO.com to Google. This enables HSO to track conversions and create remarketing lists based on user activity on HSO.com.
Possible cookies
Please refer to the below page for an updated view of all possible cookies that the Google Ads tag may set.
Cookie information for Google's ad products (safety.google)
Technologies Used
Cookies
Purpose
With your consent, we use IPGeoLocation to retrieve a country code based on your IP address. We use this service to be able to trigger the right web technologies for the right people.
Purpose
With your consent, we use Leadfeeder to identify companies by their IP-addresses. Leadfeeder automatically filters out all users visiting from residential IP addresses and ISPs. All visit data is aggregated on the company level.
Cookies
Purpose
With your consent, this website will load the LinkedIn Insights tag which enables us to see analytical data on website performance, allows us to build audiences, and use retargeting as an advertising technique. Learn more about LinkedIn cookies here.
Cookies
Purpose
With your consent, this website will load the Microsoft Advertising Universal Event Tracking tag which enables HSO to report user activity from HSO.com to Microsoft Advertising. HSO can then create conversion goals to specify which subset of user actions on the website qualify to be counted as conversions. Similarly, HSO can create remarketing lists based on user activity on HSO.com and Microsoft Advertising matches the list definitions with UET logged user activity to put users into those lists.
Cookies
Technologies Used
Cookies
Purpose
With your consent, this website will load the Microsoft Dynamics 365 Marketing tag which enables HSO to score leads based on your level of interaction with the website. The cookie contains no personal information, but does uniquely identify a specific browser on a specific machine. Learn more about Microsoft Dynamics 365 Marketing cookies here.
Cookies
Technologies Used
Cookies
Purpose
With your consent, we use Spotler to measures more extensive recurring website visits based on IP address and draw up a profile of a visitor.
Cookies
Purpose
With your consent, this website will show videos embedded from Vimeo.
Technologies Used
Cookies
Purpose
With your consent, this website will show videos embedded from Youtube.
Cookies
Technologies Used
Cookies
Purpose
With your consent, this website will load the Meta-pixel tag which enables us to see analytical data on website performance, allows us to build audiences, and use retargeting as an advertising technique through platforms owned by Meta, like Facebook and Instagram. Learn more about Facebook cookies here. You can adjust how ads work for you on Facebook here.
Cookies
Purpose
With your consent, we use LeadInfo to identify companies by their IP-addresses. LeadInfo automatically filters out all users visiting from residential IP addresses and ISPs. These cookies are not shared with third parties under any circumstances.
Cookies
Purpose
With your consent, we use TechTarget to identify companies by their IP address(es).
Cookies
Purpose
With your consent, we use this service provided by uMarketingSuite to run A/B tests across the HSO.com application. A/B testing (also called split testing) is comparing two versions of a web page to learn how we can improve your experience.
Purpose
With your consent, we use this service provided by uMarketingSuite to personalize pages and content across the HSO.com application. Personalization helps us to tailor the website to your specific needs, aiming to improve your experience on HSO.com.
Purpose
With your consent, we use ZoomInfo to identify companies by their IP addresses. The data collected helps us understand which companies are visiting our website, enabling us to target sales and marketing efforts more effectively.
Cookies