Office 365 Setup
Budget: ₹1,250 – ₹2,500 INR
1. Introduction
1.1 Project Description
Company’s information security mission is to Ensure the Confidentiality, Integrity and Availability of Company’s information, information systems and the network infrastructure against unauthorized disclosure, modification and/or downtime.
Our high-level understanding of the expected project and engagement is there is need of a solution that caters to the company’s information security mission.
1.2 Problem Statement
Client needs to ensure the Confidentiality, Integrity and Availability of Company’s information, information systems and the network infrastructure against unauthorized
disclosure, modification and/or downtime.
1.3 Expected Business Benefits
While adherence to the regulatory mandates, company would like to ensure GCC compliant data loss prevention policies are put in place. Implement information security policies at the information technology systems level protecting the firm, its clients and employees from phishing attacks, securing data and managing the infrastructure seamlessly with simple solutions that are easy to use and administer.
1.4 Assumptions, Constraints, and Dependencies
1.4.1 Assumptions
A1 Network infrastructure • Availability of reliable internet connectivity at office and DC location
• Employees having reliable and secure devices i.e. laptops, desktops, tablets and mobile devices, to access data and communicate with their clients.
A2 Desktop and laptop • Local IT will ensure the local connectivity to access Azure cloud
A3 Testing • The business will have an opportunity to complete user acceptance testing.
A4 Systems • Currently client is using Zoho for Cloud data storage.
• Employees are using office 365 procured thru godaddy.com
• Acronis cyber protect is being used to encrypt data and emails
• Fortigate Firewall is in place as a layer of security.
1.4.2 Constraints
C-1 Onboarding time • The working group will setup Office 365 tenant.
• Advise on appropriate licenses that caters to clients requirements of their Information Security policy
• Solution should be able to cater to the vulnerability assessment and should be able to solve all the problems highlighted in the report.
In Scope
1. Setup tenant for Office 365 with appropriate licenses
2. Create users in the new tenant (Policy header under IS Policy)
3. Procedure for review of user access rights to be implemented. (Define frequency)
4. Password complexity policy to be defined and implemented.
5. Implement Role Based Access Management (4.1 of IS Policy).
6. Implement Multi-factor authentication for all users.
7. Remote access of the data to be secured and only allowed thru company approved devices.
8. Setup Data Loss Prevention policies
9. Migrate data from Zoho to SharePoint
10. Create folder structure in SharePoint to host the data migrated from Zoho
11. Create one SharePoint site for internal usage and sharing and one site for external usage and sharing.
12. Implement end-point protection
13. Implement mobile device management as part of proprietary information management.
14. Implement Anti-Phishing policies.
15. Implement URL filtering as part of acceptable use policy
16. Implement GDPR compliance policies for data in motion.
17. Screen lock policy to be implemented after 30 minutes of inactivity.
18. Physical security controls – Biometric entry, CCTV (cloud based)
19. Vulnerability scans on external environments to be implemented.
20. Intrusion detection and prevention systems required
21. End-point encryption and blocking of USB
22. Development of technical help guide documents
23. Half Yearly Cyber Security Awareness trainings on social engineering and phishing.
24. Mail Encryption for External Users
25. Company Branding on Desktops and Office 365 Apps
26. Alerts on - Receiving or Sending Mails outside Organization
27. Restrict data sharing from managed app (E.g. Outlook) to Non-Managed App (E.g. WhatsApp) in Phone.
1.1 Project Description
Company’s information security mission is to Ensure the Confidentiality, Integrity and Availability of Company’s information, information systems and the network infrastructure against unauthorized disclosure, modification and/or downtime.
Our high-level understanding of the expected project and engagement is there is need of a solution that caters to the company’s information security mission.
1.2 Problem Statement
Client needs to ensure the Confidentiality, Integrity and Availability of Company’s information, information systems and the network infrastructure against unauthorized
disclosure, modification and/or downtime.
1.3 Expected Business Benefits
While adherence to the regulatory mandates, company would like to ensure GCC compliant data loss prevention policies are put in place. Implement information security policies at the information technology systems level protecting the firm, its clients and employees from phishing attacks, securing data and managing the infrastructure seamlessly with simple solutions that are easy to use and administer.
1.4 Assumptions, Constraints, and Dependencies
1.4.1 Assumptions
A1 Network infrastructure • Availability of reliable internet connectivity at office and DC location
• Employees having reliable and secure devices i.e. laptops, desktops, tablets and mobile devices, to access data and communicate with their clients.
A2 Desktop and laptop • Local IT will ensure the local connectivity to access Azure cloud
A3 Testing • The business will have an opportunity to complete user acceptance testing.
A4 Systems • Currently client is using Zoho for Cloud data storage.
• Employees are using office 365 procured thru godaddy.com
• Acronis cyber protect is being used to encrypt data and emails
• Fortigate Firewall is in place as a layer of security.
1.4.2 Constraints
C-1 Onboarding time • The working group will setup Office 365 tenant.
• Advise on appropriate licenses that caters to clients requirements of their Information Security policy
• Solution should be able to cater to the vulnerability assessment and should be able to solve all the problems highlighted in the report.
In Scope
1. Setup tenant for Office 365 with appropriate licenses
2. Create users in the new tenant (Policy header under IS Policy)
3. Procedure for review of user access rights to be implemented. (Define frequency)
4. Password complexity policy to be defined and implemented.
5. Implement Role Based Access Management (4.1 of IS Policy).
6. Implement Multi-factor authentication for all users.
7. Remote access of the data to be secured and only allowed thru company approved devices.
8. Setup Data Loss Prevention policies
9. Migrate data from Zoho to SharePoint
10. Create folder structure in SharePoint to host the data migrated from Zoho
11. Create one SharePoint site for internal usage and sharing and one site for external usage and sharing.
12. Implement end-point protection
13. Implement mobile device management as part of proprietary information management.
14. Implement Anti-Phishing policies.
15. Implement URL filtering as part of acceptable use policy
16. Implement GDPR compliance policies for data in motion.
17. Screen lock policy to be implemented after 30 minutes of inactivity.
18. Physical security controls – Biometric entry, CCTV (cloud based)
19. Vulnerability scans on external environments to be implemented.
20. Intrusion detection and prevention systems required
21. End-point encryption and blocking of USB
22. Development of technical help guide documents
23. Half Yearly Cyber Security Awareness trainings on social engineering and phishing.
24. Mail Encryption for External Users
25. Company Branding on Desktops and Office 365 Apps
26. Alerts on - Receiving or Sending Mails outside Organization
27. Restrict data sharing from managed app (E.g. Outlook) to Non-Managed App (E.g. WhatsApp) in Phone.
Related categories:
Microsoft Exchange
Amazon Web Services
Windows Server
Office 365
Microsoft Azure