ProblemÂ
This article addresses a crucial security investigation focused on data sharing outside of the school's domain and the associated file downloads.
The goal is to proactively monitor for potential data leakage and the presence of malicious or unauthorized files. This effort is essential to safeguard the privacy of our student and staff data and maintain the integrity of our network environment.
Steps
- Open the Investigation Tool.
Security > Security center > Investigation tool - Search for or select from the drop-down Drive log events as your data source.
- Click Add Condition.
- Add the following conditions:
Event > is > Download
Visibility > is > Shared externally - Click Search. The results appear at the bottom of the page.
- To take action, select the checkbox for one or more event.
- Click Actions at the top of the grid.
- Select the appropriate action: Add users, Audit file permissions, Change owner, Disable download, print, copy, Remove users.Â
- At the prompt, enter additional information based on your selected action including your justification for this action.
- If you are happy with the investigation you built and want to retain it, click Save Investigation, located on the right.
See our full list of Investigation tool recipes.Â
Comments
Please sign in to leave a comment.