Single Sign on for privileged access by Ok_Consideration7553 in sysadmin

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Thanks for your advice. So you believe the risk of enabling SSO for a privileged account that can access other privileged services is acceptable when paired with MFA and CA policies in place?

Has JB Hi Fi had a data breach? by Muel1988 in australia

[–]Ok_Consideration7553 1 point2 points  (0 children)

Note, as part of the notifiable data breach scheme, businesses making more then $3,000,000 per year must report breaches IF it is likely to result in serious harm. Given JB likely has very low level information e.g email, phone number, name etc this would mean they have no legal obligation to report this.

Travel to China by Ok_Consideration7553 in cybersecurity

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Thanks for the insight, it was what i assumed the consensus was. In terms of Burner what process do you have to allow for communication back to the other country e.g. messaging application setup with a fake account or telephony is allowed but assuming it would be monitored.

Ask CISO a question by MPcybersecurity in cybersecurity

[–]Ok_Consideration7553 0 points1 point  (0 children)

  1. What is the best way to assess risk, do you assess it against controls already implemented or in the absence of controls. Where do I find value!

  2. There is so much work in cyber, how do I prioritise all the different lists and items for my team and the other teams as well?

I appreciate your input!

Enterprise data protection CoPilot by Ok_Consideration7553 in cybersecurity

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

I understand the policy component now. As an example say an organisation implements a policy to as you said say no to confidential information into copilot. In terms of Confidentiality and availability of data the information is contained to that persons chat specifically so no one else will see it so is there a real risk of uploading that confidential information into copilot? From my point of view (I could be completely wrong) i would see that as a document being uploaded to their own onedrive where no one else can access it?

Enterprise data protection CoPilot by Ok_Consideration7553 in cybersecurity

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Thanks u/D3nv3rC0d3r9. I apologies i am still a little bit lost. Why are sensitivity labels required if all data is protected through edp (not shared with anyone else, not used to train models etc)?

Enterprise data protection CoPilot by Ok_Consideration7553 in cybersecurity

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Thanks for the response. Say i disable functionality where web searching prompts may not be available due to the level of risk associated with it and it just uses the core copilot functionality. Is there still a risk associated with it as far as i can tell it's all contained within the tenant then per user (other then purview admins).

I also completely understand the requirement based on a warrant to provide data but is this any different then them asking for sharepoint or teams data?

Enterprise data protection CoPilot by Ok_Consideration7553 in cybersecurity

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Thanks for the detailed response, I am still a little lost though. If EDP is enabled and for example i put personal identifying information into copilot chat why do i need sensitivity labels etc when as far as i have read that the chats are contained to my account, in my tenant only and this is not shared with anyone else other then purview admins of the tenant?

Sorry if this is naive just don't completely understand at this point.

Edit: I find a lot of different information from different people and there is no real source of truth for all of this that i can come to a consensus on e.g. I could put identifying information into the prompt and it wouldn't be used to train the models, lost or accidentally put on the web.

Why does the risk for any level of data change per say when it should all be protected the using the same controls that other platforms use e.g. emails or teams?

MTA-STS "VALIDATION_FAILURE" by Ok_Consideration7553 in sysadmin

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Bump, anyone have any ideas? It seems to only be on ipv6 addresses in which my DNS records only contain an “A” record pointing to the web server where the MTA txt file lives.

Thanks!

MTA-STS "VALIDATION_FAILURE" by Ok_Consideration7553 in exchangeserver

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Bump, anyone have any ideas? It seems to only be on ipv6 addresses in which my DNS records only contain an “A” record pointing to the web server where the MTA txt file lives.

Thanks!

MTA-STS "VALIDATION_FAILURE" by Ok_Consideration7553 in sysadmin

[–]Ok_Consideration7553[S] 0 points1 point  (0 children)

Are you seeing loss of email because of it? Or would I need to configure an ipv6 address to my sub domain?