Creating an encrypted network share with Auditing

Dear Team,

I'm faced with a challenge in which I was asked to create a secure encrypted folder in one of our file servers. To this folder, only 4 users in our environment will have access and its needed to know via auditing or any 3rd party software who opens, modifies, deletes, moves, or access a file or folder within this share. Not sure how to go about this, I'm thinking for encryption maybe bit locker but for auditing is something I've never done before and these logs need to be easily accessible to our IT Department personnel.

Thank you.
LVL 2
exTechnologyAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Alexey KomarovChief Project EngineerCommented:
Hi,
BitLocker is designed to help protect all of the personal and system files on the drive Windows is installed on.
EFS is used to help protect individual files on any drive on a per-user basis.
You need to use EFS https://en.wikipedia.org/wiki/Encrypting_File_System

You can use the built-in file audit
https://blogs.technet.microsoft.com/mspfe/2013/08/26/auditing-file-access-on-file-servers/
0
McKnifeCommented:
Hi exTechnology.
Please explain, why you need encryption - what would it do for you, that cannot be done with NTFS permissions?
0
exTechnologyAuthor Commented:
Hello,

The reason for using bit locker or EFS encrytption is just to add an additional layer of security. This folder will contain very delicate information and we would like to protect it as much as possible (not sure if that would make a difference)
Now for the auditing part, the built-in feature in windows is great, but these reports need to be easy to read by someone that is not very technical, I was thinking it would have to be 3rd party. Not sure if there's anything out there.
0
KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

McKnifeCommented:
"The reason for using bit locker or EFS ..." - That's what I thought. But what scenario is behind your fears? Seen from the network, using EFS is not safer than using NTFS alone, not the slightest bit. Only when we think of thieves that steal the server (or let's say someone with physical access abusing that access) is when EFS is adding security.

From the network, bitlocker doesn't make a difference as well.

To give you good advice, I need to know the exact scenario that you fear and hope to protect against,
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Alexey KomarovChief Project EngineerCommented:
Look at software fileaudit http://www.isdecisions.com/products/fileaudit/
This is the software for track, audit, report and alert on all access to files and folders on Windows servers.
0
exTechnologyAuthor Commented:
The fear is someone copying the files to an external usb drive on their computers or other media. Would this carry over the encryption and not allow access unless they have the key?

Thank you.
0
Alexey KomarovChief Project EngineerCommented:
If you will be use EFS, anyone who has a key can decrypt the file and copy it to an external location.
0
McKnifeCommented:
"The fear is someone copying the files to an external usb drive on their computers or other media." - But where is that someone based? Is he admin on he server? Is he a user of another networked machine? Add these details, please, they make a difference for the answer.
0
exTechnologyAuthor Commented:
This would be a user on another machine that has access to the folder, this user is accessing the folder via the network.
We would like to allow them to copy to a usb driver or other media at some point, is just that we would like for this media to keep the files in an encrypted format in case the removable media gets lost or stolen.
0
Alexey KomarovChief Project EngineerCommented:
Maybe you will approach sharepoint with Information Rights Management
0
Alexey KomarovChief Project EngineerCommented:
Also you can use to encrypt files on USB disk
1 BitLocker
2 VeraCrypt
3 Hardware Encrypted USB Flash Drives
0
McKnifeCommented:
"This would be a user on another machine that has access to the folder" - so why would you grant access to the folder, then? If you setup a share, and you don't want people to access files in it, then move those files to a different folder and use NTFS permissions again. No need for encryption, here.
0
McKnifeCommented:
ExTechnology, please return to your question.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2012

From novice to tech pro — start learning today.