Centene Corporation

CNC Data Security Platform

SOW No. 3 Β· Engagement 2 β€” SIT Library Maturation Β· Exception Management Β· Quarantine Optimization Β· Reporting & Automation Β· DLP Expansion Β· End Date: November 30, 2026

CNC Data Security Platform Β· SOW No. 3 Β· Engagement 2
SOW No. 3 execution hub β€” five work streams driving SIT library maturation, exception management, quarantine optimization, reporting automation, and DLP channel expansion. AI-Assisted Engineering is an operating assumption across all work streams. SOW end date: November 30, 2026.
Use the topic cards below to navigate the knowledge base. Track work stream status in the Deliverable Status Tracker and manage tasks and decisions in the Platform Workbook. February 2026 Discovery Policies are the baseline β€” WS1 gates WS5.
SOW No. 3 β€” What's inside
πŸ”¬  WS1 β€” SIT Library Maturation & Validation
🚦  WS2 β€” Exception Management
πŸ”’  WS3 β€” Quarantine Optimization
πŸ“Š  WS4 β€” Reporting, Automation & AI Engineering
πŸ›‘οΈ  WS5 β€” DLP Expansion (Policy & Channels)
🏷️  4-label sensitivity taxonomy
πŸ“‘  DSPM operating model
βš™οΈ  Non-standard policy dev (SitPak)
βœ…  Deliverable tracker Β· πŸ“‹ Platform workbook
Export guide: Open any topic, then click πŸ“„ PDF to save a designed A4 infographic for that topic. Use πŸ“¦ ZIP (top right) to download the entire package for offline use.
β–Ά Start Here
Protection & Enforcement
πŸ›‘οΈ
Data Loss Prevention

DLP enforcement ladder, policy scope, and channel coverage. SOW3 WS5: expand net-new policies using WS1-validated SITs. February 2026 Discovery Policies are the evaluation baseline.

β†’
🏷️
Sensitivity Labeling

Four-label taxonomy β€” Public, Internal, Confidential, and Restricted β€” with automation matrix, protection controls, and rollout guidance. Classification integrity underpins all SOW3 DLP enforcement.

β†’
πŸ“‘
DSPM

Data Security Posture Management operating model β€” continuous visibility, risk scoring, and cross-platform signals. Feeds SOW3 WS3 quarantine baseline and WS4 reporting KPIs.

β†’
πŸ“Š
Splunk Reporting Architecture

Reporting architecture feeding SOW3 WS4. Dual-ingestion model: UAL audit + Defender XDR enrichment β†’ normalized KPI marts β†’ 5 dashboard tiers. Monthly cadence: 20th–25th rollup window. AI Builder β†’ Copilot Credits migration required by Nov 1, 2026.

β†’
πŸ†
Final Architecture Recommendation

Microsoft-core, Splunk-consumer hybrid model with SOW3 context. 7 reasoning points, platform ownership matrix, 8 implementation phases. SOW3 delivery closes November 30, 2026.

β†’
πŸ›‘οΈ
Sentinel / Microsoft-Native Architecture

Microsoft-native reporting path: Defender XDR β†’ Sentinel/Log Analytics β†’ KQL semantic functions β†’ Sentinel Workbooks + Power BI dashboards + Logic Apps automation. Supports SOW3 WS4 reporting automation build.

β†’
βš™οΈ
Non-Standard Policy Dev

AI-assisted SIT engineering β€” core methodology for SOW3 WS1 net-new SIT builds. Single-prompt pipeline with PowerShell automation, SitPak 2026 methodology, and Power Automate approval gates. WS1 SIT validation gates WS5 policy deployment.

β†’
Governance & Discovery
Reference & Build
βš™οΈ
SOW No. 3 is active β€” Engagement 2 Β· End date: November 30, 2026. WS1 SIT validation gates WS5 policy deployment. AI-Assisted Engineering is an operating assumption across all work streams β€” without it, timelines slip. Open Tracker β†’ Open Workbook β†’
Platform Flow at a Glance
πŸ—ΊοΈ
1. Discover

Data Map + DSPM scan all workloads

🏷️
2. Classify

Apply sensitivity labels per taxonomy

πŸ›‘οΈ
3. Protect

DLP rules enforce based on label + content

πŸ“Š
4. Monitor

Activity Explorer + DSPM posture + lifecycle