Microsoft adheres to a defense-in-depth principle to ensure protection of its cloud services, such as Microsoft Office 365. Built-in security features include threat protection to reduce malware infections, phishing attacks, distributed denial of service (DDoS) attacks, and other types of security threats.

Would an organization need to apply security controls to allow safe use of those applications? Why or why not?

Communication is a key part of a successful incident response plan. Assume you are the CSIRT team lead of a large corporation that just experienced a significant security breach.

Answer the following question(s): Should you inform the chief executive officer (CEO) immediately when the breach is discovered? Why or why not?

                     2. Should customers be informed immediately? Why or why not?

