Our risk team want to audit our email systems. At present around 25% of our mailboxes are in the cloud via exchange365, and 75% are stored on-premise 2013 servers.
When looking at internally hosted mail servers the risk team can look into areas such as security and cofniguration of exchange, backup procedures, AV policies, backup procedures, mailbox ACL's, run EXBPA to check for bad design configs etc etc.
But for the cloud based email infrastructure (exchange365), what can/should they look for in an audit/risk assessment?