Now that you have remediated a whole slew of folders with Varonis DatAdvantage, how to protect your glorious handiwork. There are number of things that we can do. Here are some of the steps that we would take.
- Document your new standards and train the system administrators. Working with standard Windows tools is like exploring a cave with a flashlight. Possible but difficult. Teach them how to view permissions in DatAdvantage.
- Put in place detective controls (reports) to identify when changes are made that violate the new standards.
- Utilize an automated provisioning solution for the security groups that you have applied to the folders. Varonis has DataPrivilege, and there are other Identity and Access management solutions such as SailPoint and RSA Identity and Access Management.
- Monitored Share – Global groups in Use (4b) This lists all the folders where global groups are applied. It should be blank.
- Monitored Share – Individual Permissions (12d) This lists all the folders where Individual Users are applied directly to a folder. It should be blank.
- Monitored Share – Folder Changes (1a) This lists any permission changes or new folders created at the top-level of the monitored Share folder.
Good luck keeping the wolves at bay!
No comments:
Post a Comment