Solving Four Primary Security Challenges of Microsoft SharePoint

Solving four primary security challenges of Microsoft SharePoint

Microsoft SharePoint has quickly become the enterprise standard for internal and external collaboration and content management much in the same way Microsoft Exchange has become the enterprise standard for email. However, along with SharePoint’s acceptance comes the same challenges that enveloped Exchange: The need to maximize ROI, guard against viruses and data leakage, and establish policies for governance and compliance. This white paper examines SharePoint’s benefits and risks and recommends best practices for protecting an organization’s digital assets.

1

Solving four primary security challenges of Microsoft SharePoint

Introduction to SharePoint

Microsoft Windows SharePoint enables information workers to collaborate on documents, exchange files, problem-solve, strategize, link to live web content and create tables and reports that are culled from an organization’s databases. SharePoint offers many benefits for organizations, especially those with 1,000 employees or more, because it:

»»Increases employee productivity by streamlining day-to-day business operations

»»Reduces project cycle time through collaboration

»»Empowers employees to make informed decisions by providing centralized access to information

»»Helps meet regulatory requirements through total content control

»»Simplifies access to structured and non-structured data across various systems

»»Offers a unique, integrated platform for managing business-wide intranet, extranet and internet applications

Microsoft SharePoint comprises two main components: Windows SharePoint Services 3.0 (WSS) and Microsoft Office SharePoint Server (MOSS).

Microsoft SharePoint sales broke the $1 billion revenue mark in 2008 with more than 100 million licenses sold, leading one market research analyst to proclaim that “SharePoint is the hottest-selling server-side product ever for the company.” Other analysts predict the growth of the popular content management and collaboration platform will remain steady and they expect to see it grow at a remarkable average annual rate of 25% over the next 4 years.

Today, a majority of organizations are using SharePoint to store and share their most vital electronic records such as strategic corporate planning documents, company financials, employee records, critical intellectual property records and personal health records.

Assessing reward versus risk

One of the key challenges IT managers and administrators face is finding a way to balance SharePoint’s rich functionality with the attendant risks that come from making interactive content more accessible beyond the organization’s walled garden. Even when SharePoint is used mainly by internal users (see shaded area in the figure on page 2) the threat of malware propagating across the network is remains significant.

As access to SharePoint is broadened to include outside partners and applications, the risks are magnified exponentially. What this means for IT managers and admins is that fully leveraging the organization’s investment in SharePoint also increases its vulnerability to malware, data leakage and many other concerns.

A secure deployment consists of layers of security backed with appropriate access controls so that the organization’s content is well protected while at the same time accessible beyond the walls of the organization.

What are the four primary risks?

SharePoint is susceptible to a variety of existing and emerging threats:

1. Viruses and other malware

2. Access to inappropriate content

3. Data leakage of the company’s competitive and bus iness intelligence

4. Data tampering by internal and external users

1. Viruses and other forms of malware

Windows SharePoint Services stores documents, lists, views and other information in a Microsoft SQL Server database.

Collaborative workspaces are an easy way to share files and content, which only increases the odds of contracting viruses and other forms of malware. This is a significant concern if content originates from outside the organization from unmanaged machines (for example, enabling customers to post attachments or links to untrustworthy sites in a SharePoint-based environment).

Recommendations

Deploy an anti-virus suite designed for scanning SQL Server database stores to find malware and suspicious files stored within the database — a capability that typical endpoint/server AV solutions lack. Other features to consider include:

»»On-access, on-demand, or on-schedule protection from malware, viruses, spyware, adware, suspicious files and potentially unwanted applications, which ensures maximum security while offering a completely transparent end-user experience.

»»Proactive zero-day detection of new malware using Behavioral Genotype technology.

»»Integrated quarantine manager for deleting, disinfecting or authorizing files.

2. Access to inappropriate content

Don’t let your SharePoint portal become a vast source of inappropriate, illegal or similar content that violates legal requirements for compliance and governance.

Recommendations

»»Simplify compliance with advanced content filtering.

»»Make sure the third-party solution you deploy includes a comprehensive content scanning and policy engine.

»»Control file types based on file name, size, or type using true-file-type technology to prevent file type masquerading.

»»Delivers centralized data security control across mixed IT environments.

»»Provides consistent implementation and enforcement of company-wide security policies.

»»Makes storage, exchange and recovery of keys simple and easy through centralized state-of-the-art key management

»»Provides comprehensive data protection on all kinds of devices, including: laptops, desktops, removable media, PDAs, CDs, and email

»»Offers encryption and data leakage prevention (DLP) under a single management console.

»»Fully manages Windows Vista BitLocker Drive Encryption

»»Integrates quickly and effectively with existing security infrastructures and automates administrative tasks.

Emerging concerns

»»The threats are getting greater and are not likely to subside any time soon, if ever. One reason is that employee mobility continues to rise. The 2009 Total Employee Mobility Benchmarking Report, released by Runzheimer International, notes 51% of the workforce is mobile on any given day. However, many IT execs do not have control over the associated risks, costs or benefits. The annual report was developed through interviews with executives from 90 small, mid-sized and large organizations across the U.S.

»»SharePoint is among the easiest-to-use tools in the Windows suite, experts say. The problem is any user can set up a SharePoint site, and, often, there are no guidelines for who can access it or what data can be stored there. Some users assume that because it’s used on the company’s internal network, SharePoint data must be protected by the standard corporate security defenses.

3. Data leakage of the company’s competitive and business intelligence

Because SharePoint technology enables the easy exchange of files between users, even if you’ve deployed security policies on perimeter and mail servers, users might still try to use SharePoint to exchange files that would ordinarily be blocked by email security.

Recommendations

»»Look for a solution that specifically ensures sensitive data is not being leaked through SharePoint or Exchange.

»»Employ content control that prohibits users from uploading or downloading sensitive information.

»»Check to see that files can be controlled by file name and by content (words and phrases) within files.

4. Data tampering

According to a recent survey, one-quarter of 330 respondents lack confidence that their organizations’ electronic records or other digital content are protected when they are being shared within the SharePoint environment. Of the respondents whose organizations have suffered a data breach within their SharePoint systems, 67% indicated that the tampering was at the hands of a person with access to SharePoint from inside the organization.

Recommendations

»»Look for a modular information protection control solution that enforces policy-based security for PCs and mobile devices across mixed environments.

»»It should be fully transparent to end users and easy to administer from a single central console. Finally, its modular architecture provides comprehensive data security tailored to your organization’s needs and growth requirements.

»»In other cases, employees make the mistake of offering SharePoint access to business partners or contractors outside of the company, without taking steps to secure the exchange of data.

This article was provided by Sophos and is reproduced here with their full permission. Sophos provides full data protection services including: security software, encryption software, antivirus, and malware.


Related Blogs

Turning Problems And Challenges Into Opportunities And Successes!

An idea is just an idea unless it provides a solution. A creative solution is a bit like an idea with a purpose. It’s the stardust that turns problems and challenges into opportunities and successes.

Creative Solutions are ideas that serve a purpose and add value to create an opportunity.

Ideas are the currency of the new economy, But you can’t cash them unless their worth something to somebody. To make them worth something ideas have to generate a positive result.

A chemical engineer at the 3M Company invented a substance while working on another research project. It was an amazing idea – glue that would adhere, then be easily removed and then successfully be re-applied.

An incredible invention, it sat in the files for 30 years until someone found a use for it. It’s now called the Post-it note!

 Who had the big idea – and who had the creative solution?

 A Creative Solution must have value, clearly solve the stated problem and be the answer to a problem in order to benefit you or your business. It proposes a different outcome as a result of creating an opportunity out of a problem or challenge.

Lateral thinking and problem solving

“When you come to a roadblock, take a detour.” Mary Kay Ash

Lateral thinking can be a useful process when creating solutions to help in overcoming and solving problems.

“Sometimes the situation is only a problem because it is looked at in a certain way. Looked at in another way, the right course of action may be so obvious that the problem no longer exists”. Edward  de Bono

De Bono (the “father” of lateral thinking) also points out that the term implies that there is a problem to respond to and that it can be resolved. That eliminates situations where there is no problem or a problem exists that cannot be resolved.

It is logical to think about making a good situation, that has no problems, into a better situation. Sometimes a problem cannot be solved by removing its cause.

“We may need to solve some problems not by removing the cause but by designing the way forward even if the cause remains in place”. Said de Bono

Martin Povey owns buildingyourbusiness.ca and is a business and marketing coach who helps entrepreneurs and small businesses that need focus direction and creative solutions to build their business and achieve their goals. He can be contacted at: martin@buildingyourbusiness.ca or 403-529-9259 or visit http://www.buildingyourbusiness.ca/


Related Blogs

Vision Board for Teens Self Esteem Issues And Challenges

Self-esteem and confidence can go a long way during your teenage years and beyond. The question is how can this be accomplished? The answer is many faceted and it starts with the family/teachers/roll models, as these are the areas that are most active in a child’s life during the formative years. So this is where self-esteem gets its basis and roots for the teenager and beyond years.


Teen self-esteem is quite fragile; just having a feeling of being left out, or seeing themselves as weird, or to have feelings they can’t seem to make or keep friends, or they feel like they aren’t much of an athlete, or could have some learning problems, or just feels significantly different from their peers; whatever the situation they feel they have, it is real to them and contributes to how they see themselves and then this is how they view and feel their self-esteem.


Visualization has been around for years and been very active in the adult population and now it is being introduced into the teen and adolescent community as a powerful tool to assist them through their years of transition into adulthood.


Sometimes it is difficult to get the teens attention and get them to do productive habits to better their lives and perspective on life. One thing that grabs their attention is action formats; hence, Vision Map Videos, which have the action, the pictures, the positive affirmations and the music. These can be made to the persons individual wants, needs, music, images that they can individually relate to, and they will find them empowering and entertaining at the same time.


Vision boards have been around forever, and they are also a great tool, however, there is a real process to cutting out the images etc.; and then getting a teenager to visualize and concentrate on the board everyday, it takes a very motivated teenager to do and want to do this on a regular basis. But with the Vision Map Video the music can be their favorite kind, it can be pictures that interest them and affirmations that motivate them, so they will find it fun to watch this on a regular basis and when they find how good it makes them feel, it will be a fun task. Also they can watch it on any of their electronic devises and in privacy, only their eyes to see; not a board that is out for everyone to see.


There are so many in the teen population that have challenging issues, who could have been abused, teased and put down, mentally, emotionally, physically hurt; they deserve the chance to believe in themselves and to develop a sense of self confidence; self respect and self worth. It is so great that a tool has been made available that can break through all those attitudes, fears, barriers, resistance and help them to tell and feel a new story to build their self-esteem.


 It is our responsibility as parents/teachers/religious sectors/roll models to assist the teens to be all they can be and to use all the powerful tools that are out there to assist them to change the way they think, feel and behave. It is a challenge growing up and with all the peer pressure, possible self-doubt, feelings of low self worth and humiliation that can dominate our teens’ thoughts it is our job to give them all the tools we can to assist an easier transition into adulthood.


Some teens spend the majority of their day trying to be accepted. What if there were a way you could help your teen improve self-esteem and feel good about who they are, and the best part accomplish this in a fun and entertaining way, find and research these fun and effective ways to better a teens life.

Darlene has researched and practiced many spiritual and personal growth paths and now is presenting Vision Map Videos to further enlighten and enrich the life of others thru visual perceptions. Receive her f.ree Inspiration For Daily Lives Newsletter. This is where you can see her most current Vision Map Video Spirited Boutique Darlene Siddons

Global Leadership – 4 Challenges Facing It

Some surveys claim that a majority of leaders these days have no idea about the things they are perform, and whether they are working on them, in the correct manner. While several of the leaders are equipped to do a wonderful job, they however are devoid of the knowledge as to how develop into the type of leaders, which people want of them.
Without a doubt, there are innumerable up-and-coming prosperous companies. However, when you glance at their method of functioning, you will discern that a greater part of their achievement cannot be ascribed to leadership. Now, this is the test that leaders the world over are encountering.
To confront successfully the challenges put up by global leadership, you require the following fundamentals:
The Four Challenges that Global Leadership Encounters
1. Be aware of people’s requirements
Leaders are oblivious to the fact that the requirements of people are their first priority. It makes no difference as to what the leaders require. What is of concern is that people count on these leaders to address their needs. When this is not done, the people who encouraged you to have faith in yourself will tend to pull you down from your pedestal. Hence, it is of utmost importance that the leaders should focus on the people’s requirements and lead them on the course, which they have decided on.
2. Say what you mean
People are much smarter and perceptive these days. They can accurately judge a leader by discerning what is not explicitly stated in their speeches. People are capable of ascertaining whether the leader really is interested in what he is espousing or is just mouthing inanities.
When you really have trust and faith in what you talk about, this will definitely show in your behavior. If you mean what you say, it will touch the core of people’s hearts. You should possess the determination to convince and motivate people to trust in mutual objectives. This ensures that everyone works towards the same aim. This is the intention that you have instilled in them.
3. Get people to respond
Instructing and coaching people constitute the primary steps. The subsequent step is of extreme significance. This involves persuading them to take the necessary action so that they are able to realize the major goal.
Now this consists of the most demanding section since you have to monitor whether people are carrying out things in the proper manner and also if they are pursuing an effectual process, which will be of benefit to all concerned. The best way of achieving this is by constantly encouraging and instructing them about the things they have no knowledge of. Learn to exercise patience.
4. Endeavor to give your best
Each day, innovative and progressive methods are being initiated to enable leaders to perform effectively their role of leading people who look towards them for support. This is precisely the reason why leaders are motivated to persist in looking for ways to enhance the way they do things.
These leaders should concentrate on other areas rather that focusing their attention on what they specialize in. They should come up with more improved and unique ways, which would greatly benefit not just them but also the people they lead.
These then are the universal challenges that leaders of today face and the sort of leadership development which they need to undergo. To be conversant with them is to prime yourself for what you may likely to encounter in the future.

Abhishek is a Self-Improvement expert and he has got some great Self-Improvement Secrets up his sleeves! Download his FREE 81 Pages Ebook, “Self Improvement Made Easy!” from his website http://www.Positive-You.com/775/index.htm . Only limited Free Copies available.

Adventures in the Leaves

The other day, my wife Dawn and I did what many fall tourists in New England do. We took a leisurely drive around Vermont and watched the chlorophyll drain out of the leaves. The reds, yellows and oranges in early October are truly something to behold, and we enjoyed ourselves immensely: talking, laughing and oohing and aahing our way around a good section of what we call the “Northeast Kingdom.”

If you flattened out all the hills and mountains, Vermont would be a fairly good-sized state. But since it’s hardly flat, it ranks down with the smallest of the fifty. Nonetheless, there are myriad back roads-roads that are easy to find, but not always so easy to find your way out of. Now I have a fairly keen sense of direction, and I almost always knew-at least roughly-where we were. Regardless, there were a number of times that our exact location was unknown until we emerged onto a road or scene that was more familiar. It was fun.

It occurred to me that in life, even though it’s important to a plan as to where we’re going and equally important to have a sense of where we are, if we know exactly where we’re going, and precisely what’s going to happen, there’s no drama-no adventure.

In our trek around the highways and bi-ways of northern Vermont, we were willing to be a little lost because it added to the wonder of the experience. The objective was clear, but the plan was flexible. In other words, “set your goals in concrete and your plans in sand.”

I fear that too many people-myself included-have our lives so well scheduled and so tightly controlled, that we forsake some of the spontaneous things that could add more spice, adventure and enjoyment. As I look back over my life, many of the things I labeled catastrophes turned out to be the proverbial blessing in disguise. Many of the things I initially looked upon as detours and delays added immeasurable quality to the journey.

I’m reminded of the story of the man who was discouraged and prayed that life would be easier and that he could win in every endeavor. One day, he was visited by an angel and his prayers were answered. Everything he touched turned to gold. No matter what he tried, it worked. Everything he wanted, he received-with no struggle and no fear of the end result. But, alas, he found himself miserable. Life was too predictable-like watching a taped football game to which you already know the outcome, it lacks excitement.

In a short while, the man prayed again-this time to be relieved of his wish. A second time he was visited by the angel, and the man said he would rather go to hell than continue with this “curse.” The angel replied, “My son, hell is where you’ve been since we were last together.”

We need to welcome the challenges and unknowns that come our way. They’re what make us stronger and build our character. They are what provide the drama-the comedies and the tragedies-of our lives.

Michael Angier is founder and CIO (Chief Inspiration Officer) of SuccessNet.org and helps people and businesses grow and prosper. By being a Diamond Club Member of SuccessNet you can expect to reach new heights of achievement by creating the support structure you need to accomplish your objectives. SuccessNet Diamonds SuccessNet.org