Solved

How to track data deletion in a Windows Domain?

Posted on 2014-07-21
5
331 Views
Last Modified: 2014-07-21
How to track data deletion in a Windows Domain? I have a client who is audited regularly. They have 2 Windows 2008 servers functioning as domain controllers for Windows 7 workstations. Is there a way to track and verify data deletion on the servers? Something that can be reported in someway to show that it actually happens? I would imagine there's some overhead to running something like this. I need to create a "Data Destruction Policy". Any thoughts would be greatly appreciated. Most of what I have found has been about full hard drive wiping on a single pc basis.
0
Comment
Question by:jsgould
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 96

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 250 total points
ID: 40209577
Enable File Access Auditing.  That information can then be recovered from the Security log.

If you have TONS of disk space to spare, you use a tool like DriveLock which can basically create copies of files that are deleted and note who deleted them when.  It's not free though.

http://www.drivelock.com/Solutions
0
 
LVL 4

Assisted Solution

by:Philip Portnoy
Philip Portnoy earned 250 total points
ID: 40209615
You can use File Server auditing, but it's audit logs are pretty hard to read.
One of the best non-freeware solutions is one from Quest: http://www.quest.com/changeauditor-for-windows-file-servers/
0
 

Author Comment

by:jsgould
ID: 40209656
Ok. I've reviewed both of these. DriveLock seems a bit too much and the additional space that would be required for that may be to costly.. Quest looks interesting but neither seem to assure of the data deletion portion just monitors what was deleted, moved, renamed. etc. and by whom.
0
 
LVL 96

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 250 total points
ID: 40209661
Auditing is the best, included method for doing what you want or close to it.  If you want anymore, it's going to cost you and it's probably not going to be cheap given the market for the products.
0
 
LVL 4

Accepted Solution

by:
Philip Portnoy earned 250 total points
ID: 40209666
You should use backups/shadow copying and other DR/HA solutions to provide restore capabilities.

Auditing tools are for auditing. B&R - for B&R.
0

Featured Post

SendBlaster Pro 4 - Bulk Email Sending Software

SendBlaster 4 Pro - Best Bulk Emailing Sending Software
Automatic Subscribe / Unsubscribe Processing
Great for Newsletters & Mass Mailings
Optional HTML & Text Composition
Integration with Google Features
Built in Spam Score Checking
Free Professional Templates - Feature Packed!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many businesses neglect disaster recovery and treat it as an after-thought. I can tell you first hand that data will be lost, hard drives die, servers will be hacked, and careless (or malicious) employees can ruin your data.
Keystroke loggers have been around for a very long time. While the threat is old, some of the remedies are new!
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question