I just came across (yet another) good article by Kevin Beaver called
Tests for securing the internal windows network . Kevin is an independent security expert, so he can’t be blamed for being vendor biased. Interestingly enough, the 1st step out of 3 he lists is “Test for share, directory, and (if needed) file permissions”.
Some might be surprised by this, but almost whenever I do a remote audit of file servers or a NAS devices, I always seem to find data that’s Exposed. Now, I’m not talking about an environment that’s “just” overly permissive – we all know how things work in large organizations: as people change roles or departments, they somehow always retain their old access rights and assume the new ones needed for the new role. (Why this is taking place probably warrants it’s own post). I’m talking about sensitive data being exposed to the “everyone” group (think the ‘Finance’ folder holding your company’s most sensitive data), I’m talking about seeing the “Domain\users” group showing up in unexpected places, because it’s a nested group of a nested group in Active Directory etc… If I had hair on my head, they would stand up every time we do one of these remote audits!

Kevin even goes on to say “..I come across a lot of open shares and unprotected directories on Windows workstations that anyone and everyone on the network has free reign over…” . So, It’s good to know I'm not alone out there…What’s interesting is that it’s not only small shops or small networks that run into this issue. I work with companies that have dozens and hundreds of TBs, hundreds and thousands of users in their Active directory, the most advanced IT staff – and yet we always find data that’s exposed or an environment that’s overly permissive. Add to this the fact that IT pros are the data custodians but the data owners are the ones that get to set and change many of the access rights. Kevin does list a few free tools in his article that would help the sys admin running a small network, but these tools won’t cut it for the larger environments. It seems that with talking to many IT professionals out there, what they need to be able to do in order to protect their data from rogue users:
* Find Data Exposure Level- discover and highlight data that is accessible to the ‘Everyone’ group and other unrestricted and unwanted groups
* Discover Who Can Access Specific Data- See which users and groups have access to folders on your shares
* Fix Access Rights Policies– With visibility into who has access to your sensitive data, you can lock those access rights down
* Monitor Changes – Stay on top of the access rights on sensitive folders by tracking changes taking place
* Audit NAS And File Servers- Keep a history of user access rights and generate a point-in-time access rights audit trail
So what do you think is holding many IT environments back from being able to effectively secure their company’s data against rogue insiders? Is it because of the ever-changing data environment? Is it because existing solutions are too complex / expensive or just don’t provide the required functionality?
You need to be a member of The SysAdmin Network to add comments!
Join The SysAdmin Network