Solved

How to track data deletion in a Windows Domain?

Posted on 2014-07-21
5
332 Views
Last Modified: 2014-07-21
How to track data deletion in a Windows Domain? I have a client who is audited regularly. They have 2 Windows 2008 servers functioning as domain controllers for Windows 7 workstations. Is there a way to track and verify data deletion on the servers? Something that can be reported in someway to show that it actually happens? I would imagine there's some overhead to running something like this. I need to create a "Data Destruction Policy". Any thoughts would be greatly appreciated. Most of what I have found has been about full hard drive wiping on a single pc basis.
0
Comment
Question by:jsgould
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 96

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 250 total points
ID: 40209577
Enable File Access Auditing.  That information can then be recovered from the Security log.

If you have TONS of disk space to spare, you use a tool like DriveLock which can basically create copies of files that are deleted and note who deleted them when.  It's not free though.

http://www.drivelock.com/Solutions
0
 
LVL 4

Assisted Solution

by:Philip Portnoy
Philip Portnoy earned 250 total points
ID: 40209615
You can use File Server auditing, but it's audit logs are pretty hard to read.
One of the best non-freeware solutions is one from Quest: http://www.quest.com/changeauditor-for-windows-file-servers/
0
 

Author Comment

by:jsgould
ID: 40209656
Ok. I've reviewed both of these. DriveLock seems a bit too much and the additional space that would be required for that may be to costly.. Quest looks interesting but neither seem to assure of the data deletion portion just monitors what was deleted, moved, renamed. etc. and by whom.
0
 
LVL 96

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 250 total points
ID: 40209661
Auditing is the best, included method for doing what you want or close to it.  If you want anymore, it's going to cost you and it's probably not going to be cheap given the market for the products.
0
 
LVL 4

Accepted Solution

by:
Philip Portnoy earned 250 total points
ID: 40209666
You should use backups/shadow copying and other DR/HA solutions to provide restore capabilities.

Auditing tools are for auditing. B&R - for B&R.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The conference as a whole was very interesting, although if one has to make a choice between this one and some others, you may want to check out the others.  This conference is aimed mainly at government agencies.  So it addresses the various compli…
Part One of the two-part Q&A series with MalwareTech.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question