SharePoint Security Should Not Be An Afterthought

3y ago
9 Views
2 Downloads
732.03 KB
5 Pages
Last View : 1m ago
Last Download : 3m ago
Upload by : Randy Pettway
Transcription

SharePoint SecurityShould Not Be anAfterthought

SharePoint Security ShouldNot Be an AfterthoughtMany admins and IT managers mistakenly fail toContentsSharePoint SecurityShould Not Be anAfterthoughtproperly protect SharePoint. This e-guide, from our experts atSearchWinIT.com, explores four SharePoint security aspectsthat should not be overlooked.SharePoint Security Should Not Be an AfterthoughtMicrosoft SharePoint has been around for 10 years now and it seems everycompany I work with uses it in some fashion. However, I’m always surprisedat how frequently SharePoint security is an afterthought. Companies go togreat lengths to protect servers running Windows, IIS and SQL Server, yetSharePoint controls are often overlooked.Enterprises often see SharePoint as not quite a server and not quite a Webapplication. This view is the heart of the problem. Not only is SharePoint apublic/private Web system, but it is an entire collection of systems thatcontains an abundance of sensitive information. And most of these systemscan be accessed and exploited from inside your own network.SharePoint has plenty of built-in security controls, but that doesn’t mean it isinherently secure. Below I’ve listed the top security issues facing SharePointdeployments:1. Failure to take internal security policies and plans into accountI see lots of configuration and administration inconsistencies in SharePoint.And having a development team manage SharePoint systems -- which somany do --can create accountability problems. Be sure you always have theanswers to the following:Page 2 of 5 Who maintains SharePoint and its related systems? What security hardening standards do you use? Which Windows domain policies apply? How is data backed up?Sponsored by

SharePoint Security ShouldNot Be an Afterthought How does the system fit into existing business continuity and incidentresponse plans?ContentsSharePoint SecurityShould Not Be anAfterthought2. Failure to test the Web side of the systemIt’s easy to use a generic vulnerability scanner to scan the IP address of aSharePoint server -- and many do. However, many overlook the Web side ofthe equation.SharePoint environments have the same application vulnerabilities astraditional websites and applications. Don’t be scared to dig a little deeper tofind everything that matters. This is especially important with SharePointbecause there is so much custom code.3.Failure to properly maintain patchesNumerous server-side vulnerabilities have been uncovered in SharePoint. Infact, a simple search that uses the QualysGuard vulnerability scannerdatabase reveals a couple of dozen vulnerability checks that apply directly toSharePoint.Consider Windows, SQL Server and IIS-based flaws that can be exploited aswell. All it takes is a bored or unruly insider with a free vulnerability scannerand the free Metasploit tool to find and exploit missing patches andeffectively “own” your system. Adding insult to injury, odds are that you’llnever know the exploit happened.4. Failure to account for the mobile workforceIt’s one thing to have SharePoint data locked down in the data center or inthe cloud, but once you bring iOS, Android and Windows Mobile systems intothe equation, you’ve got an entirely new set of issues.Chances are your users access SharePoint remotely. But just how secureare their mobile devices? Do they have password protection or encryption setup? How is their data being backed up? Are they properly protected frommalware?Page 3 of 5Sponsored by

SharePoint Security ShouldNot Be an AfterthoughtMany agree that mobile devices are becoming the new desktop, so it’scritical to keep these issues in mind. I suspect we’ll will have a slew of newContentsSharePoint SecurityShould Not Be anAfterthoughtPage 4 of 5mobile security risks in the near future.Just because SharePoint sits behind a firewall, you cannot install it blindlyand assume all will be well. Dig in and see what’s at risk. You may surpriseyourself.Sponsored by

SharePoint Security ShouldNot Be an AfterthoughtContentsSharePoint SecurityShould Not Be anAfterthoughtFree resources for technology professionalsTechTarget publishes targeted technology media that address your need forinformation and resources for researching products, developing strategy andmaking cost-effective purchase decisions. Our network of technology-specificWeb sites gives you access to industry experts, independent content andanalysis and the Web’s largest library of vendor-provided white papers,webcasts, podcasts, videos, virtual trade shows, research reports and more—drawing on the rich R&D resources of technology providers to addressmarket trends, challenges and solutions. Our live events and virtual seminarsgive you access to vendor neutral, expert commentary and advice on theissues and challenges you face daily. Our social community IT KnowledgeExchange allows you to share real world information in real time with peersand experts.What makes TechTarget unique?TechTarget is squarely focused on the enterprise IT space. Our team ofeditors and network of industry experts provide the richest, most relevantcontent to IT professionals and management. We leverage the immediacy ofthe Web, the networking and face-to-face opportunities of events and virtualevents, and the ability to interact with peers—all to create compelling andactionable information for enterprise IT professionals across all industriesand markets.Related TechTarget WebsitesPage 5 of 5Sponsored by

Consider Windows, SQL Server and IIS-based flaws that can be exploited as well. All it takes is a bored or unruly insider with a free vulnerability scanner and the free Metasploit tool to find and exploit missing patches and effectively “own” your system. Adding insult to injury, odds are that you’ll never know the exploit happened. 4.

Related Documents:

Administration Guide For SharePoint 2019, SharePoint 2016, SharePoint Server 2013, SharePoint Foundation 2013, SharePoint Server 2010, SharePoint Foundation 2010 This manual has been produced by MAPILab and contains information essential for the successful installation of HarePoint HelpDesk for SharePoint on your computer. Product version 16.7 .

SharePoint kann sich auf ein oder mehrere Produkte aus der Microsoft SharePoint-Produktfamilie beziehen. SharePoint Foundation : Dies war die zugrunde liegende Technologie für alle SharePoint-Websites und steht für SharePoint 2016 nicht mehr zur Verfügung SharePoint Server : Dies ist die lokale Version von SharePoint. Sie können einen oder

Migrating from SharePoint 2007 to SharePoint 2013 SharePoint 2007 provides a great collaboration platform, but as the business matures, so should the platform. Now-a-days companies that invested heavily in SP 2007 are now developing a SharePoint strategy may be confused regarding migration to SharePoint 2010 and or 2013. Needless to say, an

Information Management for Everyone 7 SharePoint is a Visionary Leader SharePoint– SharePoint is Consolidating the ECM and RM Markets –135MM SharePoint Licensed Users* 65,000 Companies* –67% SharePoint to Enterprise* –700,000 SharePoint Developers* –70% of Gartner ECM inquiries –2012 2B b

SharePoint End User Everyone who has permissions to use the content of a site, other than the Site Owner. SharePoint Calendar A shared calendar for everyone in the SharePoint team to view. SharePoint Tasks Shared tasks for everyone in the SharePoint team. Can be used to keep track of group projects and assign tasks to a particular SharePoint user.

SharePoint Implement a SharePoint governance policy. Put in place security requirements when SharePoint instances go live. Don't trust native security features. Specify what kind of information can be put in SharePoint. Get ahead of all SharePoint deployments Use search capabilities to identify sensitive data.

Lack of Governance - A Reason for SharePoint Failure o Common Mistakes of SharePoint Implementations: -Not treating SharePoint like an enterprise application -Not providing SharePoint as a centralized service for the organization -Not defining policies on what and when to use SharePoint for (and what and when not to use it for)

Cloud & Hybrid Cloud Born Release Modern Platform SharePoint History No More Foundation Version . Configure SharePoint Workflow Manager for SharePoint Server. Office Online Server No Change (Business as Usual) . Minimum public update levels for SharePoint hybrid features. By using on-prem data gateway, SharePoint 2019 can use .