How Purview supports an ISMS

Organizations that use Microsoft 365 have access to a wide range of security and compliance services that are highly relevant for an ISO 27001–based Information Security Management System (ISMS). Let’s explore how organizations can use Microsoft Purview to implement security controls defined in the standard.

ISO 27001 Requirements

ISO/IEC 27001:2022 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Organizations seeking certification must comply with all requirements in the standard.

One of the requirements in ISO 27001 is clause 9.1 – Monitoring, measurement, analysis, and evaluation. Under this requirement, the organization must determine what needs to be monitored and measured in order to analyze and evaluate the performance and effectiveness of the ISMS. This is often implemented through KPIs (Key Performance Indicators), which are presented in an ISMS dashboard or measurement register.

A relevant KPI in this context is Compliance Score. You can read more about Compliance Score in a separate article. Below is an example from an ISMS dashboard that includes several KPIs from Microsoft 365, including Compliance Score.

ISO 27001:2022 requirementRelevant Purview solution
9.1 Monitoring, measurement, analyses and evaluationCompliance Manager
– ISO 27001:2022 regulation (premium template)
– Compliance Score
– Improvement actions

Security Controls in ISO 27001 Annex A

Organizations must also assess the 93 security controls listed in Annex A of ISO 27001. The guidance for these controls is provided in ISO 27002. Each organization must evaluate whether a control is relevant, and if so, implement it. The result must be documented in the Statement of Applicability (SoA), which is a core part of the ISMS.

Below is an overview of how Microsoft Purview can support selected controls from Annex A.

ISO 27001 Annex A controlRelevant Purview solution
5.9 Inventory of information and other associated assetsInformation Protection
– Content Explorer
– Data Explorer

eDiscovery
– Search for stale data
– Search for sensitive data
5.12 Classification of informationInformation Protection
– Create custom sensitive information types (SIT) to classify data in M365
5.13 Labelling of informationInformation Protection
– Create sensitivity labels and ensure users apply them to e-mails and documents
– Configure automatic labelling based on SIT
5.36 Compliance with policies, rules and standards for information securityCompliance Manager
– Use regulations (ISO 27001, GDPR, NIS2 etc)
– Run assessments to document compliance with the regulations
– Use Compliance Score to demonstrate overall compliance
5.33 Protection of recordsData Lifecycle Management
– Create retention policies to prevent accidental deletion of information
8.12 Data leakage preventionData Loss Prevention (DLP)
– Create DLP policies to prevent users from sharing internal or confidentail information with external recipients
8.15 LoggingAudit
– Enable auditing and search activity logs to support monitoring and investigations
8.24 Use of cryptographyInformation Protection
– Configure sensitivity labels with access control, thus ensuring that information is automatically encrypted

As we can see, Microsoft Purview supports a significant number of security controls defined in ISO 27001. Microsoft 365 E3 licenses provide access to core functionality, but to fully leverage Purview, organizations typically need E5 Compliance (or full E5) licenses. With E5 Compliance, ISO 27001 is available as a premium regulatory template. You can read more about premium templates in a separate article.

The ISO 27001 Template in Compliance Manager

ISO/IEC 27001:2022 is available as a regulatory template in Microsoft Purview Compliance Manager. This means Microsoft has analyzed the standard and broken down its requirements and controls into concrete improvement actions.

By enabling this template, organizations gain a structured set of improvement actions directly mapped to ISO 27001 requirements and Annex A controls. This provides a practical overview of which configurations and controls can be implemented in Microsoft 365 to support compliance with the standard.