Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 417
  • Last Modified:

Auditing

Hi

If you have a file server which has a folder with confidentail info, that only one group should be allowed to access

How would you maintain records of all attempts to access the folder.

I've been told you Enable Auditing of object access events on the server AND then on the folder it self you audit the Everyone group

My questions is this......I understand why you have to monitor the everyone group on the folder in question. but why do you have to enable auditing of object access events on the server. Cant you just do that on the folder itself?


0
LFC1980
Asked:
LFC1980
  • 4
  • 3
1 Solution
 
winsocCommented:
Could you specify what OS for which you require Auditing.
For tracking file access you should really be looking at "Tripwire"
0
 
LFC1980Author Commented:
It's something out of an MCSE study book, not something i am carrying out in real life.

The file server is a 2003
0
 
mahe2000Commented:
you have to do both.... the audit policy to tell the server that he has to audit objects and the audit configuration in the folder to tell him what he has to audit.
0
Managing Security Policy in a Changing Environment

The enterprise network environment is evolving rapidly as companies extend their physical data centers to embrace cloud computing and software-defined networking. This new reality means that the challenge of managing the security policy is much more dynamic and complex.

 
LFC1980Author Commented:
But why couldn't we just put the audit policy that has been put on the server on the folder instead, as thats what we want to monitor?
0
 
mahe2000Commented:
because the server audit policy is for "turning on" auditing.... then you have to configure what you want to audit. ask bill why they did it this way.... :)
0
 
LFC1980Author Commented:
So would this always be the case with auditing (i.e. always "turn it on" on the server first)
0
 
LFC1980Author Commented:
?
0
 
mahe2000Commented:
yes, that's the way to do it. first turning on auditing on objects and then tell him what to audit.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now