33
3 Strategies to Secure Content with User Groups

How to Automatically Secure Content with User Groups

  • Upload
    opin

  • View
    94

  • Download
    0

Embed Size (px)

Citation preview

3 Strategies to Secure Content with

User Groups

What we’ll coverDocument Level Security

Page Level Security

How to implement security based on: Job position Work groups Geography

Most content is from the OPIN blog

Manual Security is BrokenThe pace of employee changeover and content creation makes manual updates unreliable.

Relying on an authoritative source like Active Directory makes security much tighter.

Manual Security is BrokenRisk increases as users grant access at their own discretion.

User-dictated updates may not align with corporate security protocol.

2 Types of Security

Document Level Page Level

Document Level SecurityShowing or hiding an entire document for a user based on their permissions

Document Level SecurityWhen using Document Level Security the document should not contain any information the users are not authorized to view.

Share this deck with your Information Security team!

Document Level Security ExampleThose processing payroll must see the whole report since they need all of the payroll information to perform their job.

Page Level SecurityRestricting access within a document based on page content.

Why is Page Level Security Helpful?

1. Keep sensitive data safe

2. Remove unhelpful content (more content isn’t always good)

3 Strategies forImplementing Security

Secure by Job PositionSecure by GroupSecure by Region

3 STRATEGIES

Securing content by job position lets you quickly give new hires or transfers access to relevant content.

Secure by Job Position

Only showing content relevant to the employees job promotes security & the bloat doesn’t get in the way of finding what they’re looking for.

Secure by Job Position

Job Position ExampleA member of the accounts payables team has access to all payables reports.

Like this deck? Checkout our blog for more document

security content!

OPIN.com/blog

Take AwayOnly showing reports that relate to a person’s job function keeps

unwanted viewers at bay and makes it easier to find helpful information.

A category for multiple job positions with in a functional group.

Secure by Groups

Group ExampleBusiness analysts are part of the marketing group and they should see all of the marketing group’s content in additional to what is shown to anyone who is a Business Analyst.

Take AwayGroups help you go beyond job

position to provide a wider set of content to a larger number of people.

Distributed offices and global teams means some content is only relevant to specific geographies

Secure by Geography

Having access to information from many geographies can make it too easy to look at the wrong report, and provide incorrect information.

Secure by Geography

Limiting what content is accessible reduces these errors and makes locating the correct information easy.

Secure by Geography

Geographic Region ExampleThe sales mangers for the Northeast and Midwest regions of the US only have access to their respective region’s reports.The North American Sales Manager should see all reports for regions in North America though.

Take AwayProperly securing content by

geography reduces misinformation and makes it easier to find the relevant data.

HOW DO I START?HOW DO I START?

Find the document with the biggest audience.

1:

2:Secure it at the document level; only making it accessible to relevant employees.

3:Find the document withthe smallest audience.

4:Secure it at the document level to keep it hidden from the masses.

5:Add more in-depth security by limiting which pages employees can see based on their geography or other permissions.

DOWNLOAD

This is slide deck is part of a larger ebook on document security.