unstructured data risk assessment - varonis · unstructured data risk assessment file system...

3
Unstructured Data Risk Assessment Unstructured Data Risk Assessment

Upload: others

Post on 19-Jul-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Unstructured Data Risk Assessment - Varonis · Unstructured Data Risk Assessment FILE SYSTEM Folders with global group access Server: Server A Server: Server B RESULTS 179,829 11,988

Unstructured Data Risk Assessment

UnstructuredData RiskAssessment

Page 2: Unstructured Data Risk Assessment - Varonis · Unstructured Data Risk Assessment FILE SYSTEM Folders with global group access Server: Server A Server: Server B RESULTS 179,829 11,988

Unstructured Data Risk Assessment

UNSTRUCTURED DATA RISK ASSESSMENT

EXECUTIVE OVERVIEW

Many organizations struggle with understanding the risk associated

with one of their largest assets – their unstructured data. After the

installation of DatAdvantage has been completed, the Varonis

Professional Services team may be contracted to provide an

assessment of your unstructured data and directory services

environments, quickly identifying areas of potential exposure and

opportunities for improvement. In accordance with Varonis best

practices and industry standards, Varonis Professional Services

will assess the environment’s controls and processes, and provide

a detailed report of their strengths and weaknesses, as well as

recommendations for improvement. A typical assessment takes

between one to two weeks, depending on the size and complexity

of the environment.

HOW DOES IT WORK?

Working in concert with your IT staff, Varonis Professional Services personnel will collect and analyze metadata from key infrastructure components, and return a detailed, written analysis, which will be reviewed with your staff. The scope of the assessment may be customized, and typically includes access controls and authorization processes, privileged and end user access monitoring, Active Directory structure, NTFS and sharing permissions structure, data retention proficiency, and compliance with applicable regulations.

Page 3: Unstructured Data Risk Assessment - Varonis · Unstructured Data Risk Assessment FILE SYSTEM Folders with global group access Server: Server A Server: Server B RESULTS 179,829 11,988

Unstructured Data Risk Assessment

WORlDWIDE HEaDquaRTERS

1250 Broadway, 31st Floor, New York, NY 10001 T 877-292-8767 E [email protected] W www.varonis.com

unITED KIngDOm anD IRElanD

Varonis UK Ltd., Warnford Court, 29 Throgmorton Street, London, UK EC2N 2AT T +44 0207 947 4160 E [email protected] W www.varonis.com

WESTERn EuROpE

Varonis France, 13-15 rue Jean Jaures (1er Etage) 92800 Puteaux T +33 184 88 56 00 E [email protected] W sites.varonis.com/fr

gERmany, auSTRIa anD SWITzERlanD

Varonis Deutschland GmbH, Welserstrasse 88, 90489 Nürnberg T +49(0) 911 8937 1111 E [email protected] W sites.varonis.com/de

Unstructured Data Risk Assessment

FILE SYSTEMFolders with Stale Data

Amount of Stale Data

RESULTS4,827,640

34,128 GB

IMpAcTMedium

Medium

WHAT DoES An AnALYSIS LooK LIKE?

Unstructured Data Risk Assessment

FILE SYSTEMFolders with global group access

Server: Server A

Server: Server B

RESULTS179,829

11,988

10,041

IMpAcTHigh

High

High

Unstructured Data Risk Assessment

RISK LEVELHigh

High

High

High

High

Medium

Medium

Medium

Medium

Low

Low

Low

Low

Low

RESULTS179,009

4,998

8,034

22,571

19,800

2,340

3,465

6,847,640

13

1,613,080

551,655

147,072

1,973

12,210

DEScRIpTIonFolders with Global Group access

Sensitive files with Global Group access

Users with Varonis removal recommendations

Stale but enabled users AD accounts

Folders with Inconsistent (Broken) Permissions

Stale sensitive files

Users with passwords that don’t expire

Folders with stale data

Looped nested groups within AD

Folders with unique permissions

Folders that are protected from inheritance

Folders that have unresolved SIDs

Security groups with no users in AD

Folders where a user is assigned directly

SERVERS

http://sharepoint

Server A

Server B

Server C

Server D

Server E

DoMAInS

Domain1.com

Domain2.com

WHaT DOES an analySIS lOOK lIKE?

The Varonis Unstructured Data Risk Assessment Report will summarize key findings, stack rank identified weaknesses in order of risk, and provide a detailed explanation of each finding. The assessment is often used to scope and prioritize remediation efforts that, once completed, will significantly reduce the threat of data loss, theft, or misuse. Examples of Key Performance indicators include:

• Data exposed to inappropriate employees and contractors

• Widely accessible business, employee and customer data

• Broken Data Permissions

• IT Administrators with too much access

• Idle User Accounts that compromise security

• Recommendations about how to safely reduce risk

• Many more…

HOW DO I gET STaRTED

Visit www.varonis.com/assessment for more details.

pREREquISITES

A working installation of Varonis DatAdvantage 5.9 or later. IDU Data Classification Framework is also recommended.