SlideShare uma empresa Scribd logo
1 de 15
®
   Auditing SharePoint Activity
   for Compliance and Security

 Made possible by:

                          © 2012 Monterey Technology Group Inc.
Brought to you by:

                         LOG & EVENT MANAGER
www.logbinder.com         www.solarwinds.com
Randy Franklin Smith           Rob Johnson
Creator of LOGbinder        Sr. Sales Engineer




                                  © 2012 Monterey Technology Group Inc.
Preview of Key Points

Risks of not auditing SharePoint
Native SharePoint audit foundation
Building on the foundation
            ®
 SolarWinds Log & Event Manager
 LOGbinder SP




                                  © 2012 Monterey Technology Group Inc.
Risks of not auditing
                                  SharePoint
Customer information disclosure
 Liability, notification costs, loss of good will
Trade secrets and intellectual property
Human resources data
Regulatory penalties and liability
 SOX
 PCI
 HIPAA
 GLBA

                                           © 2012 Monterey Technology Group Inc.
Native SharePoint
                              audit foundation
Available in
                      ®
 Window Server System (WSS) 3.0
   • Not exposed in the interface
 SharePoint 2007
 SharePoint Foundation
   • Not exposed in the interface
 SharePoint 2010




                                    © 2012 Monterey Technology Group Inc.
Native SharePoint
                                       audit foundation
 Audit policy defined
  Site collection level
  List/Library level
  No way to set global audit policy or automatically audit new site
   collections
 What can you audit?
  Changes to audit policy
  Permission changes
  Group membership changes
  View
  Check in/out
  Delete/Update
  Schema changes
  Workflow
  Search


                                                        © 2012 Monterey Technology Group Inc.
Native SharePoint
                            audit foundation
Where is the SharePoint audit log?
 Stored in the content database
 Accessible via Audit Reports under Site Collection
  Administration
Can you rely on the native audit log?
 Provides an accurate audit trail
 But limitations exist




                                       © 2012 Monterey Technology Group Inc.
Native SharePoint
                           audit foundation
Audit records written to internal table within
 content database
 Inaccessible to log management solutions
                            ®
 Consumes SQL/SharePoint storage
 Stores audit logs on same system where they are
  generated




                                     © 2012 Monterey Technology Group Inc.
Native SharePoint
                                audit foundation
 Rudimentary Excel® reports available
  Audit codes, object ID numbers, user and group ID
   numbers not translated
Native SharePoint
                         audit foundation
No alerting

Audit log purging introduced with SP2010




                                  © 2012 Monterey Technology Group Inc.
Native SharePoint
                            audit foundation
Limitations in WSS and Foundation
 Audit engine present

 Auditing only possible through application that
  interfaces with SharePoint API




                                       © 2012 Monterey Technology Group Inc.
Building on the foundation


SharePoint


                           LOG & EVENT MANAGER


               Windows
               Event Log
                                        Alerts           Reports          Archive




                                                 © 2012 Monterey Technology Group Inc.
Turn data into information
 LOGbinder SP Agent
                                     SharePoint
  Translates SharePoint audit
   records into human readable audit                          LOG & EVENT MANAGER
   trail
                                                  Windows


  Sends SharePoint audit events to
                                                  Event Log
                                                                           Alerts   Reports   Archive



   the Windows event log
  Purges events after export




                                                       © 2012 Monterey Technology Group Inc.
Take action
                                    on the information
 SolarWinds LEM                   SharePoint
  Built-in support for
   LOGbinder SP                                             LOG & EVENT MANAGER

  Secure, long term log                        Windows

   archival                                     Event Log
                                                                            Alerts    Reports   Archive



  Alerting
    • Recommended default
      alerts already implemented
  Reporting
    • Recommended reports
      already implemented
    • Schedule reports
      daily, weekly, monthly


                                                              © 2012 Monterey Technology Group Inc.
Bottom Line

 SharePoint increasingly
  used to store and process       Next steps
  sensitive information             Download evaluation copy
 Becoming an IT audit and
  compliance target                 Schedule a demo
 Auditing, alerting, reporting
  is a must for any
  technology like SharePoint       www.logbinder.com/sp
 SharePoint native auditing
  is a foundation technology       www.solarwinds.com
 SolarWinds LEM with
  LOGbinder SP builds on
  that foundation to provide
  fully managed audit and
  security monitoring for
  SharePoint



                                                © 2012 Monterey Technology Group Inc.

Mais conteúdo relacionado

Mais de SolarWinds

Mais de SolarWinds (20)

Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT Operations
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application Performance
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid Workforce
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges
 
Government and Education Webinar: SQL Server—Indexing for Performance
Government and Education Webinar: SQL Server—Indexing for PerformanceGovernment and Education Webinar: SQL Server—Indexing for Performance
Government and Education Webinar: SQL Server—Indexing for Performance
 
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
 
Government Webinar: RMF, DISA STIG, and NIST FISMA Compliance Using SolarWinds
Government Webinar: RMF, DISA STIG, and NIST FISMA Compliance Using SolarWindsGovernment Webinar: RMF, DISA STIG, and NIST FISMA Compliance Using SolarWinds
Government Webinar: RMF, DISA STIG, and NIST FISMA Compliance Using SolarWinds
 
Government Webinar: Preparing for CMMC Compliance Roundtable
Government Webinar: Preparing for CMMC Compliance Roundtable Government Webinar: Preparing for CMMC Compliance Roundtable
Government Webinar: Preparing for CMMC Compliance Roundtable
 

Último

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Último (20)

MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 

Log Auditing for SharePoint® with SolarWinds® LEM and LOGbinder SP

  • 1. ® Auditing SharePoint Activity for Compliance and Security  Made possible by: © 2012 Monterey Technology Group Inc.
  • 2. Brought to you by: LOG & EVENT MANAGER www.logbinder.com www.solarwinds.com Randy Franklin Smith Rob Johnson Creator of LOGbinder Sr. Sales Engineer © 2012 Monterey Technology Group Inc.
  • 3. Preview of Key Points Risks of not auditing SharePoint Native SharePoint audit foundation Building on the foundation ® SolarWinds Log & Event Manager LOGbinder SP © 2012 Monterey Technology Group Inc.
  • 4. Risks of not auditing SharePoint Customer information disclosure Liability, notification costs, loss of good will Trade secrets and intellectual property Human resources data Regulatory penalties and liability SOX PCI HIPAA GLBA © 2012 Monterey Technology Group Inc.
  • 5. Native SharePoint audit foundation Available in ® Window Server System (WSS) 3.0 • Not exposed in the interface SharePoint 2007 SharePoint Foundation • Not exposed in the interface SharePoint 2010 © 2012 Monterey Technology Group Inc.
  • 6. Native SharePoint audit foundation  Audit policy defined  Site collection level  List/Library level  No way to set global audit policy or automatically audit new site collections  What can you audit?  Changes to audit policy  Permission changes  Group membership changes  View  Check in/out  Delete/Update  Schema changes  Workflow  Search © 2012 Monterey Technology Group Inc.
  • 7. Native SharePoint audit foundation Where is the SharePoint audit log? Stored in the content database Accessible via Audit Reports under Site Collection Administration Can you rely on the native audit log? Provides an accurate audit trail But limitations exist © 2012 Monterey Technology Group Inc.
  • 8. Native SharePoint audit foundation Audit records written to internal table within content database Inaccessible to log management solutions ® Consumes SQL/SharePoint storage Stores audit logs on same system where they are generated © 2012 Monterey Technology Group Inc.
  • 9. Native SharePoint audit foundation  Rudimentary Excel® reports available  Audit codes, object ID numbers, user and group ID numbers not translated
  • 10. Native SharePoint audit foundation No alerting Audit log purging introduced with SP2010 © 2012 Monterey Technology Group Inc.
  • 11. Native SharePoint audit foundation Limitations in WSS and Foundation Audit engine present Auditing only possible through application that interfaces with SharePoint API © 2012 Monterey Technology Group Inc.
  • 12. Building on the foundation SharePoint LOG & EVENT MANAGER Windows Event Log Alerts Reports Archive © 2012 Monterey Technology Group Inc.
  • 13. Turn data into information  LOGbinder SP Agent SharePoint  Translates SharePoint audit records into human readable audit LOG & EVENT MANAGER trail Windows  Sends SharePoint audit events to Event Log Alerts Reports Archive the Windows event log  Purges events after export © 2012 Monterey Technology Group Inc.
  • 14. Take action on the information  SolarWinds LEM SharePoint  Built-in support for LOGbinder SP LOG & EVENT MANAGER  Secure, long term log Windows archival Event Log Alerts Reports Archive  Alerting • Recommended default alerts already implemented  Reporting • Recommended reports already implemented • Schedule reports daily, weekly, monthly © 2012 Monterey Technology Group Inc.
  • 15. Bottom Line  SharePoint increasingly used to store and process Next steps sensitive information  Download evaluation copy  Becoming an IT audit and compliance target  Schedule a demo  Auditing, alerting, reporting is a must for any technology like SharePoint www.logbinder.com/sp  SharePoint native auditing is a foundation technology www.solarwinds.com  SolarWinds LEM with LOGbinder SP builds on that foundation to provide fully managed audit and security monitoring for SharePoint © 2012 Monterey Technology Group Inc.