Compliance Manager
Compliance Manager is a risk assessment tool that allows an organization to track and record the activities they undertake to achieve compliance with specific certification standards. An assessment of an organization’s compliance posture is based on the capabilities of the Microsoft cloud services and the ways that the organization makes use of them, as compared to an existing standard, regulation, or law.
The home page for the Compliance Manager tool contains a dashboard that displays tiles representing the assessments of the selected components against different standards, as shown in Figure 1-59. Each tile specifies a cloud service and the specific standard to which it is being compared. The results of the comparison are stated as a numerical score.
FIGURE 1-59 A Compliance Manager tile
Selecting a tile displays a list of the cloud services being tested for the assessment, as shown in Figure 1-60, along with the results for each individual control. The controls are broken down into those for which Microsoft is responsible and those for which the customer is responsible. Each control entry contains a reference to a section or article in the standard that corresponds to the control; information about who tested the control and when; and the results of the test, expressed as an individual Compliance Score value.
FIGURE 1-60 A cloud service assessment in Compliance Manager
Auditing
Power Platform also supports auditing, which is another way of monitoring compliance with data access regulations. Auditing captures instances of specific activities and saves them to a log file, which administrators can review to monitor data access by specific users, modifications of security roles, changes made to entities and fields, changes made to sharing privileges, and the time and place of updates.
To allow auditing and access auditing logs, an administrator expands the Audit and logs heading on an environment’s Settings page in the Power Platform admin center. Selecting Audit settings opens the Auditing tab on the System Settings page of the Dynamics 365 admin center, as shown in Figure 1-61.
FIGURE 1-61 The Auditing tab of the System Settings page in the Dynamic 365 admin center
Other controls on the environment’s Settings page allow administrators to manage the logs and view individual entries, as shown in Figure 1-62.
FIGURE 1-62 Audit log detail