Contents of This Paper Overview Key Functional Areas of SharePoint Where Varonis Helps And How A Project Plan for SharePoint with Varonis
Overview The purpose of this document is to explain the complementary nature of Varonis DatAdvantage software for data governance and Microsoft s SharePoint content management solution. The volume of intranet content is growing at rates of 70 percent or more annually compelling administrators and users to look for ways to manage the deluge of information. Microsoft and other application vendors have created solutions collectively recognized as content management products that allow their customers to aggregate intranet content into corporate portals. While SharePoint comprises a powerful portal and collaboration platform it was not designed to automate the computation and management of access controls to unstructured data. This is a Varonis core expertise. Further, SharePoint deployment and management is quite complex. It is therefore very important that enterprises understand the challenges with migration to SharePoint and draft a plan and phased approach for content management in order to ensure that security and seamless access to critical business assets contained on file shares are not compromised. Varonis data governance software can help expedite and streamline the migration of unstructured data from file shares to SharePoint servers and once complete, Varonis can continue to provide the recommendations for access controls that will ensure need to know based access that is in step with data growth. Key Functional Areas of SharePoint Microsoft Office SharePoint Server 2007 provides an integrated location where employees can collaborate with team members, find organizational resources, search for experts and corporate information, manage content and workflow, and leverage business insight to make decisions.
Key Functional Areas of SharePoint Cont d There are 6 major functional areas to SharePoint and they are listed below. 1. Collaboration allows teams to work together to publish documents, maintain task lists, implement workflows, and share information through the use of wikis and blogs. 2. Portals - web-based information sharing and a personalized user experience through the presentation of content based on the user s profile. 3. Enterprise Search - expedited content location 4. Enterprise Content Management Create and manage documents, records, and Web content. 5. Business Process and Forms allows the creation of workflows and electronic forms to gather information and automate some processes 6. Business Intelligence reports and dashboards that display access metrics Where Varonis Can Help and How Document Management is powerful technology that vastly improves the presentation and availability of company information to employees resulting in significant gains in productivity. However, in order to work consistently and pervasively systems like SharePoint require that all data to be management be centralized in proprietary repositories or databases. This is relatively easy to do for all new data but most enterprises have substantial stores of existing unstructured data in file severs. This data must be migrated to the document management system repository a process that is quite complex, lengthy and disruptive. The process begins with the indexing or classification of data. According to Microsoft the process can take a very long time for more than 100 gigabytes of data (http://technet2.microsoft.com/office/en-us/library/7d9c454c- 9300-42e5-a79f-1064266a23931033.mspx?mfr=true). Considering that most medium sized businesses have data stores measuring in the terabytes, migration to SharePoint means a significant time and resource commitment for nearly every enterprise.
Where Varonis Can Help and How Cont d In order to make the migration to SharePoint cost effective and efficient IT administrators must first draft a plan that answers the following questions: What data should be migrated? What data can be deleted? What data can be archived? Who owns the data to be migrated? Are the access controls of the data to be migrated accurate? Varonis helps by providing answers to these key questions. When deployed prior to the SharePoint application Varonis can give administrators the visibility to the information they need to make smart decisions about the migration, thereby increasing security and efficiency. The following paragraphs describe how. 1. Cleaning up existing file share access controls It is a fact that nearly 100% of companies suffer from data permission creep with the vast majority of files and folders being accessible by far too many people in the organization. In the case of a SharePoint migration this means perpetuating overly permissive access within the content management system. Varonis provides complete visibility to which users have access to which data. Most importantly Varonis DatAdvantage gives precise recommendations of who should be removed from having access. This results in access control settings that are based on business need to know. 2. Identifying stale data One of the biggest challenges in a SharePoint migration is identifying which data to move or migrate first. Naturally not all unstructured data on file shares is important or current. Some in fact might be appropriate for deletion or archiving rather than migration. This kind of intelligence can significantly impact the amount of time it will take to conduct the migration. Varonis DatAdvantage software tracks every user s every file touch and at a mouse click provides reports on which parts of a file system are active. Administrators know exactly which file share data is stale and which is vigorously accessed and can prioritize their migration priorities accordingly.
Where Varonis Can Help and How Cont d 3. Identify data business owners A migration to SharePoint requires coordination with the business owners of the data being moved into the content management system. This is a particularly challenging part of the migration since 2 terabytes of data means thousands of data folders and hundreds of thousands of files. Understanding who actually needs a particular piece of data for his job function is nearly impossible to accomplish without automation. Varonis DatAdvantage leverages its rich audit log of data use to produce a clear list of names of individuals who are the likely business owners of a file or folder. This saves IT administrators days to weeks by eliminating the need for mass company wide emails to identify the true stewards of file share data. A Project Plan for SharePoint Deployment with Varonis 1. Varonis deployment (1 day) 2. Audit (4-6 weeks) 3. Optimization (data volume dependent; typically one month) 4. Deployment / Migration (data volume dependent) 5. Monitoring (on-going)
The Five Phases To SharePoint Migration With Varonis Phase One: Deployment of Varonis DatAdvantage Installation of Varonis DatAdvantage software as a first step allows administrators to begin the process of access control clean up and data identification and prioritization prior to applying the invasive and lengthy SharePoint indexing function. DatAdvantage has three components: 1) Windows UI 2) analytics server 3) Probe. The analytics server installs easily via an install shield on a customer provided Windows server. A SQL license is also required. The probe(s) is ideally installed near the file servers to be monitored. One probe can support up to 75 file servers depending on size of content per server. A typical installation takes no longer than a few hours to one business day. Phase Two: Data Use Auditing DatAdvantage comprises powerful analytics algorithms that map users to the data they access. This mapping is created by monitoring and collecting all data access events and all active directory contents. The result of the analysis produces not only the existing access control picture but also recommendations on who should be removed from having access. This is an important step of the SharePoint migration because it will allow administrators to clean up unwarranted permissions prior to moving this information to the content management system. Varonis recommends that the DatAdvantage application be allowed to monitor access events for a period of one month. Doing so will result in very high (multiple nines) accuracy in the recommendations for permissions revocations. Phase Three: Unstructured Data Store Optimization During this phase IT administrators can generate reports of user to data activity on demand. Varonis recommends that the following reports be generated for the migration to SharePoint: 1) most active data sets 2) least active data sets 3) inactive users 4) business owner reports for folders: finance, HR and legal as well as any others considered sensitive or high priority. While the generation of these reports takes only seconds within DatAdvantage, administrators may require some time (days to weeks) to use the intelligence provided therein to delete or archive stale data and to coordinate with data business owners on the goals of the migration. Phase Four: SharePoint Installation and Data Migration During this phase it is assumed that administrators have used Varonis DatAdvantage software to reduce ACLs to business need to know and have drafted a plan for which data is to be migrated and in what order based on the data use auditing reports. The environment is now ready for the indexing and classification of the highest priority data to be moved into the SharePoint environment. Susbequent steps include moving down the priority list and contacting data business owners once the move is complete. Account creation and optimization also occur as part of this phase so the time it takes to complete varies greatly by data volume and user community size. Phase Five: Continuous Monitoring It is likely that migration to SharePoint will occur in phases. This means that the environment will contain unstructured data and SharePoint data. In fact this is a state that is likely to persist for some time since unstructured data is generated at an annual growth rate of 70% or more. It is important t unstructured data access be continuously monitored throughout the migration since user business needs to data and consequently security controls will change. Varonis DatAdvantage will update the recommendations for permissions revocations as those changes occur.