30 on thursday - data loss prevention in sharepoint 2016 - protect your sensitive information -...

33
Data Loss Prevention in SharePoint 2016: Protect Your Sensitive Information Thank you for joining our webinar!

Upload: antoniomaio2

Post on 15-Apr-2017

1.161 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Data Loss Prevention in SharePoint 2016: Protect Your Sensitive Information

Thank you for joining our webinar!

Page 2: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Who We Are

3,300 professionals

Over 20 countriesin the Americas, Europe, the Middle East and Asia-Pacific

70+offices

IT Consulting► Enterprise Content

Management Solutions

Protiviti is a global consulting firm that helps companies solve problems in finance, technology, operations, governance, risk and internal audit, and has served more than 40 percent of FORTUNE 1000® and FORTUNE Global 500® companies. Protiviti serve clients through a network of more than 70 locations in over 20 countries. Protiviti is a wholly owned subsidiary of Robert Half (NYSE: RHI). Founded in 1948, Robert Half is a member of the S&P 500 index.

Page 3: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Introduction• ‘30 on Thursday’ Webinar Series

• 30 minute webinar series• All things SharePoint & Enterprise Content Management!

• Upcoming Webinars:• June 9: “SharePoint 2016 and PowerApps Revealed!”• July 14: “Capacity Planning: An Introduction on How to Size and

Architect a SharePoint Farm”• Full Schedule: ECM.Protiviti.com/Webinars

Page 4: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Upcoming Roundtables: SharePoint Security

Register Now at: ECM.Protiviti.com/Events!

Date Time LocationTuesday, May 17 8:30-10:30 am Edina, MNTuesday, May 17 12:00-2:00 pm McLean, VATuesday, May 17 12:00-2:00 pm Atlanta, GAWednesday, May 25 8:30-10:30 am Chicago, ILWednesday, May 25 12:00-2:00 pm Houston, TX

Page 5: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Live Tweeting!

Tweet us your questions & feedback during the webinar!

Tweet @ProtivitiECM and use #30TDLP

Page 6: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Today’s Webinar• Today’s session is being recorded• Archive of past sessions

• YouTube.com/ProtivitiSP• Questions: Use the Question Window or tweet us

your questions @ProtivitiECM using #30TDLP

Page 7: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Today’s Presenter

Antonio MaioMicrosoft SharePoint MVP (5x)Senior Manager & Senior SharePoint ArchitectProtiviti

Page 8: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

LET’S GET STARTED!

Page 9: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Data Loss Prevention (DLP)Goals• Protect the business (legal action, sanctions, loss of reputation)• Comply with regulations and business standards

DLP is about Finding and Protecting sensitive information• Personally Identifiable Information (PII)• Payment Credit Industry Data (PCI, PCI DSS)• Financial Data• Health Insurance Data

etc…

Page 10: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Data Loss Prevention in Office 365Available through…

• Exchange Admin Center• Compliance Center (Protection

Center)

Page 11: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Data Loss Prevention in SharePoint 2016Available through…

• Improved eDiscovery Site Collection• New Compliance Policy Center Site

Collection

Page 12: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

SharePoint 2016DLP Policies for eDiscovery

eDiscovery Center• Create & run DLP Queries to identity sensitive data

• Save Queries• Export Data

• Highly dependent on SharePoint Search Index!

Page 13: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

SharePoint 2016DLP Policies for Compliance

Compliance Center• Create DLP Policies to monitor and enforce protection

of sensitive information• Provide administrator notification (via email)• Provide policy tips to users and owners• Block access to files containing sensitive content

• Assign policies to existing site collections• Highly dependent on SharePoint Search Index!

Page 14: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

SharePoint 2016 DLP Prerequisites• Create a Search Service Application (mandatory)

• Start the search service, Define a crawl schedule, Perform a full crawl• Must have a healthy search index and crawl

• Configure out-going email (recommended)• Turn on Usage reports (recommended)• Create the eDiscovery or Compliance Center site collections (mandatory– both

not needed)• eDiscovery – for DLP Queries to identify where sensitive data exists• Compliance Policy Center – for DLP Policies to monitor or enforce policies

• Assign permissions to Compliance team through the Site Collection Members group (recommended)

Page 15: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Creating the Compliance Center• Create a new Site Collection• Site Template - Select the Enterprise tab• Select Compliance Policy Center template

• Only One Compliance Center Site Collection per Web Application

• Compliance Center cannot cross Web Application boundary(eDiscovery Center can query across Web Applications)

Page 16: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types • U.S. / U.K. Passport Number

• U.S. Individual Taxpayer Identification Number (ITIN)• U.S. Social Security Number (SSN)

• No health related data• Cannot customize policy templates or data types

Page 17: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types • Credit Card Number

• U.S. Bank Account Number• U.S. Individual Taxpayer Identification Number (ITIN)• U.S. Social Security Number (SSN)

• No health related data• Cannot customize policy templates or data types

Page 18: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• Credit Card Number

• No health related data• Cannot customize policy templates or data types

Page 19: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• Credit Card Number• EU Debit Card Number• SWIFT Code

• No health related data• Cannot customize policy templates or data types

Page 20: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• ABA Routing Number• Credit Card Number• U.S. Bank Account Number

• No health related data• Cannot customize policy templates or data types

Page 21: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• U.K. National Insurance Number (NINO)• U.S. / U.K. Passport Number

• No health related data• Cannot customize policy templates or data types

Page 22: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• SWIFT Code• U.K. National Insurance Number (NINO)• U.S. / U.K. Passport Number

• No health related data• Cannot customize policy templates or data types

Page 23: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• SWIFT Code

• No health related data• Cannot customize policy templates or data types

Page 24: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• U.S. Social Security Number (SSN)

• No health related data• Cannot customize policy templates or data types

Page 25: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create DLP Policies using Policy Templates

• 10 policy templates available• Looking for 10 sensitive data types

• Credit Card Number• U.S. Bank Account Number• U.S. Driver's License Number• U.S. Social Security Number (SSN)

• No health related data• Cannot customize policy templates or data types

Page 26: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Create DLP Policies• Create New Policies

• Provide Name• Select 1 of 10 templates (no customization)• Select # of instances of sensitive data• Email address to send incident reports• Select to Notify with Policy Tip• Select to Block Access

• Assign Policies to site collections(one at time)

Page 27: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Avoiding False PositivesLooking for More Than Regular Expressions

Finding Credit Card Numbers• Format• Pattern• Checksum (Luhn Algorithm)• 191 related keywords• Confidence Definition

• 85% confident if all found within 300 chars• 65% confidence if number found & checksum

passes

Full Definitions found here:https://support.office.com/en-ie/article/What-the-sensitive-information-types-in-SharePoint-Server-2016-look-for-ec9fdbe2-bb77-455f-a2f6-407a4f54fca5

Page 28: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Finding US Driver’s License Numbers• Format – State Dependent• Pattern• 16 related abbreviations & 75 keywords• State name & State Abbreviation• Confidence Definition

• 75% confident if all found within 300 chars• 65% confidence if all found (except keywords) within

300 chars

Avoiding False PositivesLooking for More Than Regular Expressions

Full Definitions found here:https://support.office.com/en-ie/article/What-the-sensitive-information-types-in-SharePoint-Server-2016-look-for-ec9fdbe2-bb77-455f-a2f6-407a4f54fca5

Page 29: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

DEMONSTRATION

Page 30: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Important Technical Notes• If its not in the search index DLP policies will not be enforced

• Consider your crawl schedule• 4 Timer Jobs used to enforce policies

• Policies not enforced on new documents until search crawl and timer jobs complete• Timeliness of policy enforcement depends on priority of policy template• Can take up to 24 hours

• Cannot enforce policies on list items – only documents (not yet proven)

Page 31: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Final Thoughts• Data Loss Prevention just one critical part of

securing sensitive data• Identifying sensitive data, monitoring its usage and enforcing policies• DLP requires regular management of policies – refine to avoid noise of false

positives

• SharePoint 2016 DLP is a great start!• Start learning and testing SharePoint 2016 DLP

Today• Critical to have healthy search index• Test policies in Staging before deploying to Prod

Page 32: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Questions?Antonio [email protected] @AntonioMaio2

ECM.Protiviti.com

Julia [email protected] @ProtivitiECM

Page 33: 30 on Thursday - data loss prevention in SharePoint 2016 - protect your sensitive information - published

Thank You!