Veri-Tech Recommended Controls
Recommended controls developed by Veri-Tech to fill compliance and operational hygiene gaps not addressed by other frameworks.
44
Controls
3
Auto-Remediable
4
Domains
Purview(27)
VT-COPILOT-009Microsoft Purview Data Security Posture Management for AI activated
VT-PURVIEW-001SharePoint Online DLP coverage configured
VT-PURVIEW-002OneDrive for Business DLP coverage configured
VT-PURVIEW-003Endpoint DLP coverage configured for managed devices
VT-PURVIEW-004DLP rules block external sharing of credit card data
VT-PURVIEW-005DLP rules block external sharing of US Social Security numbers
VT-PURVIEW-006DLP policies promoted out of Test mode
VT-PURVIEW-007Sensitivity label policy published to users
VT-PURVIEW-008At least one sensitivity label enforces encryption
VT-PURVIEW-009Auto-labeling policies configured for sensitive content
VT-PURVIEW-010Container labels configured for Teams and Microsoft 365 Groups
VT-PURVIEW-011Mandatory sensitivity labeling enforced via label policy
VT-PURVIEW-012Retention policy enabled with at least one workload location
VT-PURVIEW-013Retention policy covers Exchange Online mailboxes
VT-PURVIEW-014Retention policy covers SharePoint Online sites
VT-PURVIEW-015Retention policy covers OneDrive for Business accounts
VT-PURVIEW-016Retention policy covers Teams chats and channel messages
VT-PURVIEW-017Microsoft Purview DSPM for Data baseline established
VT-PURVIEW-018Microsoft Compliance Manager assessment tracked
VT-PURVIEW-019Custom audit log retention policy extends to at least 1 year
VT-PURVIEW-020Audit retention coverage spans Exchange, SharePoint, and Entra ID
VT-PURVIEW-021Insider Risk Management policy active
VT-PURVIEW-022Insider Risk policy covers departing-user data theft
VT-PURVIEW-023Insider Risk reviewer roles populated
VT-PURVIEW-024Communication Compliance policy active
VT-PURVIEW-025Communication Compliance policy reviewers assigned
VT-PURVIEW-026Information Barriers configured if regulatory segregation applies
Intune(10)
VT-CP.001Should have at least one Windows compliance policy
VT-CP.002Should have at least one iOS compliance policy
VT-CP.003Should have at least one Android compliance policy
VT-CP.004Should have at least one macOS compliance policy
VT-CP.005All compliance policies should have assignments
VT-CP.006All compliance policies should have descriptions
VT-CP.007No compliance policies should be named with default or copy patterns
VT-CP.008Windows policies should require BitLocker encryption
VT-CP.009Windows policies should require minimum OS version
VT-CP.010Windows policies should require password
SharePoint(6)
VT-COPILOT-002Everyone Except External Users (EEEU) hidden at SharePoint tenant level
VT-COPILOT-004Restricted SharePoint Search enabled during Copilot deployment window
VT-COPILOT-005Restricted Content Discovery configured on high-risk SharePoint sites
VT-COPILOT-006SAM site access reviews initiated for sites flagged by oversharing reports
VT-COPILOT-007SAM Inactive Site Policy in Active mode
VT-COPILOT-008SAM Site Ownership policy active and ownerless sites at zero
Copilot(1)
VT-COPILOT-015Copilot agents governed by an explicit allow-list
