2013 SharePoint Data Security

Microsoft SharePoint 2013 encryption
By Paul Rummery, Securenet Consulting
Microsoft SharePoint Security

Microsoft SharePoint is a powerful tool for collaboration and content management, and there are inherent access and permissions controls, but 2013 SharePoint does not come pre-equipped with tools for manual or automated encryption of files, email and data.

Some companies have SharePoint 2013 implemented within its controlled network environment, but what about the many other companies receiving their SharePoint application from a hosting company. They have strong concerns about security and want to encrypt documents. How do you provide security when somebody else is hosting the application?


Documents are not always created by users from within the SharePoint environment. Normally user will create a documents on their laptop or desktop, work on it, and then upload it to SharePoint.

Historically encryption solutions have been notoriously difficult to implement, use and manage with many organisations hesitating to implement encryption solutions – times have changed.


Add-on solutions are available that offer the possibility to secure and encrypt SharePoint files, as well as enabling the end user to secure documents directly on the desktop and secure entire folders or a network drive. (this enables them to work securely with sensitive data even though the document is not stored on SharePoint) Encryption platforms empower end users to secure data easily. Whether information is in transit; email, flash drives, portable media, or stored on a corporate network or SharePoint intranet.

Ideally users want SharePoint encryption to be quick and easy. End users want to simply choose to secure a document.


Easy administration of SharePoint security

Administrators want to easily add access rights to users and groups. So the system needs to integrate with Microsoft Active Directory® and Microsoft SharePoint.

You don’t always want to rely on end users to encrypt documents. Organisations can opt to set up the solution to automatically encrypt documents. Based on pre-determined rules, documents will be automatically encrypted when they are uploaded to SharePoint. The rules can be based on document type, document owner, meta data tags, SharePoint columns, document list, etc.


"centralised management of file encryption rights, user access control and permissions rights"

OPT (One Time Password) support for document access. Organisations that have high security requirements can choose to activate OTP, so that when a user tries to access a secured document on a mobile device they will be requested to enter a One Time Password, sent as a text message to the user’s mobile phone. Only once the user has authenticated (entered the OTP) will they be able to access the document. 

Cross platform compatibility

Securing and encrypting documents can take place on any device without installing software. The user can access secured documents on iPad®, Android®, iPhone®, a Mac®, a PC, etc.

A document rarely exists in only one location or in one version. Documents tend to live in many environments and as the documents evolve, old versions are saved for later reference. Additionally, end users save local copies of a document or send the document to colleagues internally using email.

All data, where ever in their life-cycle with be protected, even file sent to backup.


Notes on regulatory compliance

Strong FIPS-certified AES 256 encryption complies with the Sarbanes Oxley Act (SOX), GLBA, HIPAA Hitech, PCI/DSS, FTC Red Flag Rules and many others. Security policies are automatically enforced for all users, and detailed reporting of user actions provides a comprehensive audit trail.

Summary

If your organisation is using Microsoft SharePoint® in 2013 to share sensitive and confidential information, you should be using encryption.

 

Also read
USB Device Encryption

-----------------------------------------------------------------------------------------------------------------------------------------------

WANT TO LEARN MORE? Contact SecureNet Consulting