unstructured data risk assessment - varonis · unstructured data risk assessment file system...
TRANSCRIPT
Unstructured Data Risk Assessment
UnstructuredData RiskAssessment
Unstructured Data Risk Assessment
UNSTRUCTURED DATA RISK ASSESSMENT
EXECUTIVE OVERVIEW
Many organizations struggle with understanding the risk associated
with one of their largest assets – their unstructured data. After the
installation of DatAdvantage has been completed, the Varonis
Professional Services team may be contracted to provide an
assessment of your unstructured data and directory services
environments, quickly identifying areas of potential exposure and
opportunities for improvement. In accordance with Varonis best
practices and industry standards, Varonis Professional Services
will assess the environment’s controls and processes, and provide
a detailed report of their strengths and weaknesses, as well as
recommendations for improvement. A typical assessment takes
between one to two weeks, depending on the size and complexity
of the environment.
HOW DOES IT WORK?
Working in concert with your IT staff, Varonis Professional Services personnel will collect and analyze metadata from key infrastructure components, and return a detailed, written analysis, which will be reviewed with your staff. The scope of the assessment may be customized, and typically includes access controls and authorization processes, privileged and end user access monitoring, Active Directory structure, NTFS and sharing permissions structure, data retention proficiency, and compliance with applicable regulations.
Unstructured Data Risk Assessment
WORlDWIDE HEaDquaRTERS
1250 Broadway, 31st Floor, New York, NY 10001 T 877-292-8767 E [email protected] W www.varonis.com
unITED KIngDOm anD IRElanD
Varonis UK Ltd., Warnford Court, 29 Throgmorton Street, London, UK EC2N 2AT T +44 0207 947 4160 E [email protected] W www.varonis.com
WESTERn EuROpE
Varonis France, 13-15 rue Jean Jaures (1er Etage) 92800 Puteaux T +33 184 88 56 00 E [email protected] W sites.varonis.com/fr
gERmany, auSTRIa anD SWITzERlanD
Varonis Deutschland GmbH, Welserstrasse 88, 90489 Nürnberg T +49(0) 911 8937 1111 E [email protected] W sites.varonis.com/de
Unstructured Data Risk Assessment
FILE SYSTEMFolders with Stale Data
Amount of Stale Data
RESULTS4,827,640
34,128 GB
IMpAcTMedium
Medium
WHAT DoES An AnALYSIS LooK LIKE?
Unstructured Data Risk Assessment
FILE SYSTEMFolders with global group access
Server: Server A
Server: Server B
RESULTS179,829
11,988
10,041
IMpAcTHigh
High
High
Unstructured Data Risk Assessment
RISK LEVELHigh
High
High
High
High
Medium
Medium
Medium
Medium
Low
Low
Low
Low
Low
RESULTS179,009
4,998
8,034
22,571
19,800
2,340
3,465
6,847,640
13
1,613,080
551,655
147,072
1,973
12,210
DEScRIpTIonFolders with Global Group access
Sensitive files with Global Group access
Users with Varonis removal recommendations
Stale but enabled users AD accounts
Folders with Inconsistent (Broken) Permissions
Stale sensitive files
Users with passwords that don’t expire
Folders with stale data
Looped nested groups within AD
Folders with unique permissions
Folders that are protected from inheritance
Folders that have unresolved SIDs
Security groups with no users in AD
Folders where a user is assigned directly
SERVERS
http://sharepoint
Server A
Server B
Server C
Server D
Server E
DoMAInS
Domain1.com
Domain2.com
WHaT DOES an analySIS lOOK lIKE?
The Varonis Unstructured Data Risk Assessment Report will summarize key findings, stack rank identified weaknesses in order of risk, and provide a detailed explanation of each finding. The assessment is often used to scope and prioritize remediation efforts that, once completed, will significantly reduce the threat of data loss, theft, or misuse. Examples of Key Performance indicators include:
• Data exposed to inappropriate employees and contractors
• Widely accessible business, employee and customer data
• Broken Data Permissions
• IT Administrators with too much access
• Idle User Accounts that compromise security
• Recommendations about how to safely reduce risk
• Many more…
HOW DO I gET STaRTED
Visit www.varonis.com/assessment for more details.
pREREquISITES
A working installation of Varonis DatAdvantage 5.9 or later. IDU Data Classification Framework is also recommended.