Microsoft 365 data handling maturity levels 2-7-3 give you a practical way to score whether your organization handles information accidentally, consistently, measurably, or continuously improves it. For ECC 2-7-3, a useful assessment uses five levels—Initial, Repeatable, Defined, Managed, and Optimized—across data classification, sharing, access, retention, protection, and evidence. Your goal is not to enable every Microsoft 365 feature; it is to establish data-handling requirements that meet applicable NCA Data Cybersecurity Controls and can be demonstrated when someone asks how sensitive information is protected.
Why does maturity scoring beat a binary checklist for ECC 2-7-3?
A binary checklist can tell you whether a setting exists, but it cannot tell you whether that setting is reliable, applied to the right data, understood by users, or reviewed after it changes. A sole IT administrator can easily mark “DLP enabled” as complete while discovering later that the policy covers only Exchange, runs only in test mode, or generates alerts nobody reviews.
ECC 2:2024 practice 2-7-3 requires cybersecurity requirements for protecting and handling data and information to include applicable requirements from NCA Data Cybersecurity Controls. That is broader than a single technical configuration. It includes deciding what data needs protection, documenting the handling rules, applying controls in Microsoft 365, and retaining evidence that the controls operate.
Maturity scoring makes the work manageable because it separates “we have started” from “we can prove this works.” Instead of treating every gap as equally urgent, you can identify the one behavior preventing your next level of maturity. For a side-responsibility security owner, that creates a defensible improvement plan rather than an endless list of security portal recommendations.
What are the five Microsoft 365 data handling maturity levels 2-7-3?
Level 1: Initial
Data handling is mostly ad hoc. Users decide where to save files, whether to email attachments externally, and how long to keep information. You may have Microsoft 365 defaults enabled, such as mailbox encryption in transit and basic audit logging, but they were not deliberately selected as data-handling controls.
- No approved data classification scheme or written handling rules exist.
- SharePoint and OneDrive external sharing settings are inherited defaults or vary by site owner.
- Sensitive information may be stored in Teams chats, personal OneDrive folders, shared mailboxes, and unmanaged spreadsheets without visibility.
- Evidence is limited to screenshots taken when someone asks for them.
Level 2: Repeatable
You have begun applying the same response to common situations. For example, you know how to remove a risky anonymous sharing link, create a Microsoft Purview sensitivity label, or disable a departing employee’s OneDrive sharing. The work is repeatable because you have done it before, but it depends heavily on your memory and availability.
- A basic list identifies sensitive data types, such as national IDs, financial records, HR files, customer records, or regulated business information.
- External sharing has a documented baseline, such as disabling “Anyone” links tenant-wide or restricting them to approved sites.
- A small number of Purview sensitivity labels or DLP policies exist, often created after an incident or audit request.
- You retain selected exports or screenshots, but there is no scheduled control review.
Level 3: Defined
Data-handling requirements are written, approved, and consistently translated into Microsoft 365 settings. A user can understand what “Confidential” means and what they must do differently when handling it. You can also explain which NCA Data Cybersecurity Controls are applicable to your organization and how your Microsoft 365 controls support them.
- A data classification and handling standard defines categories, owners, approved storage locations, sharing rules, retention expectations, and escalation paths.
- Purview sensitivity labels use clear names and user-facing guidance, such as
Public,Internal,Confidential, andRestricted. - Label actions are purposeful: for example,
Confidentialadds a footer and restricts external sharing, whileRestrictedapplies encryption to named users or groups. - SharePoint, OneDrive, Teams, Exchange Online, and endpoint rules are aligned where licensing and technical capabilities allow.
- A simple evidence folder contains policy versions, configuration exports, review records, and exception approvals.
Level 4: Managed
At this level, you measure whether the defined requirements are working. You do not simply deploy policies; you review alerts, exceptions, label adoption, sharing activity, and policy changes. Managed does not mean zero incidents. It means incidents and findings produce measurable corrective action.
- Microsoft Purview DLP policies run in simulation first, then are tuned and enforced with documented exception handling.
- You review Purview Activity Explorer, DLP alerts, SharePoint sharing reports, and Microsoft 365 audit searches on a scheduled basis.
- Metrics track items such as unlabelled sensitive documents, external sharing links, DLP matches, overdue access reviews, and unresolved alerts.
- Privileged administrators use separate admin accounts, multifactor authentication, and Conditional Access protections.
- Control owners or business data owners review high-risk exceptions instead of leaving approval entirely with IT.
Level 5: Optimized
Data protection continuously improves based on measured outcomes, business changes, and lessons from incidents. Automation reduces manual effort, but it does not remove accountability. The organization can adapt policies when new collaboration patterns, regulatory obligations, or high-risk data types appear.
- Sensitivity labels, DLP rules, retention labels, and sharing restrictions are improved through documented quarterly reviews.
- Microsoft Purview auto-labeling, trainable classifiers, or data classification analytics are used where suitable and properly tested.
- High-risk sharing and data-loss events feed an incident process with root-cause analysis and trend reporting.
- Configuration drift is detected through recurring reviews, PowerShell exports, or approved configuration-management processes.
- Data owners participate in reviewing policy impact, false positives, and acceptable collaboration methods.
How can you score your Microsoft 365 data handling maturity?
Score each area from 1 to 5 using the descriptions below. Choose the score that reflects normal practice, not the best configuration in one department. Add the five scores and divide by five. Round down if one critical area—particularly access and external sharing—is two or more points below your average.
| Assessment area | 1: Initial | 2: Repeatable | 3: Defined | 4: Managed | 5: Optimized |
|---|---|---|---|---|---|
| Classification and handling rules | No classification or handling standard. | Informal list of sensitive information exists. | Approved categories, owner duties, storage and sharing rules are documented. | Label use and exceptions are reviewed monthly or quarterly. | Rules are improved using metrics, incidents, and business-owner feedback. |
| Purview labels and protection | Users freely name and share files. | One or two manual labels exist. | Published sensitivity labels apply markings, encryption, or sharing restrictions. | Label adoption and protection failures are measured and remediated. | Auto-labeling or advanced classification is tested and tuned. |
| External sharing and access | Site owners decide sharing without baseline controls. | Anonymous links are restricted after issues occur. | SharePoint and OneDrive sharing baselines, guest rules, and approval paths are documented. | External sharing, guest access, and privileged access are periodically reviewed. | High-risk sharing triggers automated investigation or approval workflows. |
| DLP, retention, and records | No deliberate DLP or retention configuration. | A policy exists in test mode or only covers email. | Purview DLP and retention policies reflect approved data-handling requirements. | Alerts, policy matches, false positives, and retention exceptions are reviewed. | Policies are tuned from trends and integrated with incident response. |
| Evidence and governance | No evidence beyond portal settings. | Occasional screenshots or exported reports are retained. | Policies, settings, approvals, and applicability decisions are stored centrally. | Scheduled reviews produce dated records, metrics, and corrective actions. | Control performance is reported to management and drives funded improvements. |
Interpret your average: 1.0–1.9 is Initial, 2.0–2.9 is Repeatable, 3.0–3.9 is Defined, 4.0–4.9 is Managed, and 5.0 is Optimized. For most small organizations, reaching Defined across all five areas is a strong and realistic short-term target.
What commonly keeps organizations stuck at each maturity level?
- Initial: The common blocker is assuming Microsoft 365 defaults equal a data-handling program. Defaults provide useful protection, but they do not define how your organization classifies, shares, retains, and proves handling of sensitive data.
- Repeatable: The blocker is undocumented tribal knowledge. If only you know which team may share externally or how to respond to a DLP alert, the control is fragile.
- Defined: The blocker is policy-to-configuration drift. A document may say “Confidential data must not be shared publicly,” while anonymous links remain available in selected SharePoint sites.
- Managed: The blocker is alert fatigue. DLP alerts and audit events become noise unless you define what gets reviewed, who investigates, expected response times, and when a policy needs tuning.
- Optimized: The blocker is automating before the process is stable. Auto-labeling and automated remediation can spread incorrect decisions quickly when labels, ownership, and exception rules are unclear.
What is a realistic 90-day plan to advance one maturity level?
Use this plan to move one level, not to transform every Microsoft 365 workload at once. If your score varies widely, improve the lowest-scoring area first because it limits the reliability of the overall control.
- Days 1–30: establish the baseline. Export current SharePoint and OneDrive sharing settings, review existing Purview labels and DLP policies, and identify where sensitive data is most likely stored. Write a one-page data-handling baseline covering classifications, approved locations, external sharing, and escalation. Record which NCA Data Cybersecurity Controls are applicable and why.
- Days 31–60: define and apply one enforceable standard. Publish a small sensitivity-label set and align it with a clear user rule. For example, make
Confidentialrequire a label, add visible markings, and prevent uncontrolled external sharing. Put one DLP policy into simulation mode for a high-risk data type before enforcing it. - Days 61–90: measure and retain evidence. Review DLP simulation results, external sharing activity, and label usage. Adjust false positives, document approved exceptions, and save dated exports, screenshots, policy approvals, and a short review note in one evidence location. Set a recurring calendar reminder for the next review.
Choose your lowest rubric score today, assign one 90-day owner action to it, and keep the evidence where you can find it during your next ECC 2-7-3 review.