A company uses Microsoft Purview Compliance Manager to improve their compliance posture. They are preparing for a SOC 2 audit and need to score compliance with SOC 2 controls, track improvement actions, and assign tasks to responsible teams. Which component of Compliance Manager should they use to assign and track specific actions to improve their compliance score?
Improvement actions are detailed tasks that can be assigned to groups or individuals, tracked, and documented to demonstrate compliance progress.
Why this answer
Improvement actions in Compliance Manager are the specific, actionable tasks that directly impact your compliance score. They represent the steps you need to take (e.g., configuring a policy, enabling logging) to satisfy a control. By assigning these actions to responsible teams and tracking their completion status, you can systematically improve your score and demonstrate progress during a SOC 2 audit.
Exam trap
The trap here is that candidates confuse 'Control' (the requirement) with 'Improvement action' (the task to meet the requirement), leading them to select B, even though controls are not directly assignable or trackable as individual tasks.
How to eliminate wrong answers
Option A is wrong because an Assessment is a container that groups controls from a specific regulation (like SOC 2) and tracks your overall compliance score, but it does not provide the granular, assignable tasks needed to drive improvement. Option B is wrong because a Control is a specific requirement from the regulation (e.g., 'Access must be logged'), but it is not the actionable item you assign to a team; the control is satisfied by completing one or more improvement actions. Option D is wrong because a Template is a reusable blueprint that defines the controls and improvement actions for a regulation (e.g., SOC 2 template), but it is not the mechanism for assigning and tracking individual tasks.