Security & Data Governance
Security & Data Governance
Security architecture and data governance should reflect the organisation's risk, regulatory obligations, operating model and technology footprint — not apply the same control set everywhere.
The framework and control guidance on this page is educational and reference material, not compliance or legal advice. Confirm applicable obligations with qualified legal, risk and compliance advisors for your organisation.
Framework selection
An architecture decision, not a shopping list
Framework selection starts with the organisation, not the product catalogue. Microsoft controls implement a chosen framework — they are not themselves the governance framework.
Organisation profile
Step 1
Security baseline
A pragmatic minimum control set
Step 2
Regulatory / industry overlays
Obligations layered on top of the baseline
Step 3
Microsoft control implementation
Entra, Defender, Sentinel, Purview and policy
Step 4
Continuous assurance
Evidence that controls remain effective
Framework → Controls → Microsoft implementation → Evidence
Reference guidance by organisation type
The right baseline changes with the organisation
Each example distinguishes the framework (the governance baseline) from Microsoft platform controls (how it's implemented). Expand a profile for detail.
Small / medium business
A pragmatic control baseline without enterprise-scale governance overhead.
Small / medium business
A pragmatic control baseline without enterprise-scale governance overhead.
Framework / baseline
- Australian Essential Eight
- CIS Controls
Microsoft implementation examples
- Entra MFA
- Conditional Access
- Intune
- Defender
- Endpoint hardening
- Privileged access controls
- Backup / recovery
- Security monitoring
General enterprise
Risk-based governance, measurable controls and enterprise assurance.
General enterprise
Risk-based governance, measurable controls and enterprise assurance.
Framework / baseline
- NIST Cybersecurity Framework
- ISO/IEC 27001
- CIS Controls
Microsoft implementation examples
- Entra ID
- Privileged Identity Management
- Defender XDR
- Sentinel
- Azure Policy
- Purview
- Intune
- Azure logging
- Security operations
Australian government / high-assurance
Architecture built around identity assurance, segmentation and continuous monitoring.
Australian government / high-assurance
Architecture built around identity assurance, segmentation and continuous monitoring.
Framework / baseline
- ASD Information Security Manual
- Essential Eight
Microsoft implementation examples
- Identity assurance
- Administrative separation
- Privileged access
- Logging
- Network segmentation
- Information classification
- Data sovereignty
- Secure configuration
- Continuous monitoring
Financial / APRA-regulated
Operational resilience, third-party risk and audit-ready control evidence.
Financial / APRA-regulated
Operational resilience, third-party risk and audit-ready control evidence.
Framework / baseline
- APRA CPS 234
- APRA CPS 230
- ISO 27001
- NIST CSF (where appropriate)
Microsoft implementation examples
- Information security capability
- Operational resilience
- Third-party risk
- Incident response
- Control assurance
- Audit evidence
- Business continuity
Payment environments
Minimising and segmenting cardholder data scope before adding controls.
Payment environments
Minimising and segmenting cardholder data scope before adding controls.
Framework / baseline
- PCI DSS
Microsoft implementation examples
- Scope minimisation
- Segmentation
- Identity
- Logging
- Encryption
- Vulnerability management
- Access control
Software / digital product organisations
Securing the software supply chain from commit to runtime.
Software / digital product organisations
Securing the software supply chain from commit to runtime.
Framework / baseline
- NIST SSDF
- OWASP
- CIS
- NIST CSF
Microsoft implementation examples
- Secure SDLC
- Dependency management
- Secrets
- CI/CD security
- Code scanning
- Workload identity
- Software supply chain
- Runtime monitoring
Security architecture
A cross-cutting capability, not a perimeter
Identity through Governance is designed as a stack that applies consistently across every domain — AI, applications, integration, data, the Azure platform and Microsoft 365 — rather than a box sitting at the edge of the architecture.
Applies across every domain below — not a perimeter at the edge
Identity
Device
Network
Application
Workload
Data
Monitoring
Response
Governance
Identity through Governance — a cross-cutting capability stack, applied consistently across AI, Applications, Integration, Data, the Azure Platform and Microsoft 365.
Data governance
Data has an architecture too
Data ownership, classification, discovery, access, protection, usage, retention and disposal — each stage has an accountable owner and a defensible answer.
Data ownership
Classification
Discovery & catalogue
Access
Protection
Usage
Retention
Disposal
Data ownership
Every data domain has a named business owner and steward accountable for its quality and use.
- Data domains
- Business data owners
- Data stewards
Classification
Data is classified by sensitivity so downstream controls can scale to the risk it carries.
- Sensitivity labels
- Classification schema
Discovery & catalogue
What data exists, where it lives, and how it flows is catalogued — not assumed.
- Data catalogue
- Lineage
Access
Access follows least privilege and is governed the same way as any other entitlement.
- Access governance
- Entitlement review
Protection
Sensitivity drives protection — encryption, labelling and loss-prevention controls.
- Information protection
- Data loss prevention
Usage
How data is used — including by AI systems — is governed by policy, not left implicit.
- Data sharing
- Acceptable use
- Privacy
Retention
Data is kept only as long as a business or regulatory reason requires.
- Retention schedules
- Records management
Disposal
End-of-life data is disposed of defensibly, with an auditable record that it happened.
- Defensible disposal
- Auditability
Microsoft implementation
Requirement first, product second
The model runs one direction only: business requirement defines the governance capability and control needed, which is then implemented with a Microsoft technology — never the reverse.
| Business requirement | Governance capability | Control | Technology |
|---|---|---|---|
| Know what sensitive data exists and where it lives | Data discovery & catalogue | Automated scanning, classification and lineage tracking | Microsoft Purview Data Map & Data Catalogue |
| Apply consistent sensitivity labelling across content | Classification & information protection | Sensitivity labels applied at creation and enforced on use | Microsoft Purview Information Protection |
| Prevent regulated data leaving an approved boundary | Data loss prevention | Policy-based content inspection, blocking and alerting | Microsoft Purview DLP |
| Keep data only as long as required, then dispose of it | Retention & records management | Retention labels, disposition review and defensible deletion | Microsoft Purview Data Lifecycle Management / Records Management |
| Ensure only authorised people and systems can access data | Identity & access governance | Conditional, least-privilege access with periodic certification | Microsoft Entra ID |
| Analyse data at scale without losing governance controls | Governed analytics & data platform | Access, lineage and classification carried into the data platform | Microsoft Fabric / Azure data services (where appropriate) |
| Detect and respond to anomalous data access or exfiltration | Security monitoring | Correlated detection across identity, data and endpoint signals | Microsoft Defender / Sentinel |
AI + data governance
AI cannot be governed without data governance
Before any AI system is trusted with enterprise data, the organisation needs to know what data exists, who owns it, its classification and sensitivity, who can access it, where it's stored, whether AI may consume it, and what retention and audit requirements apply.
User
Requests a task or answer
Identity
Authenticated and scoped to least privilege
AI application
Copilot, custom agent or Azure OpenAI app
Guardrail / policy
Checks classification, sensitivity and entitlement
Retrieval / MCP / tool
Allow-listed retrieval or tool invocation only
Authorised data
Only data the user is entitled to is returned
Audit + monitoring
Every step logged for traceability and review