|
Distributing local information through unwanted channels is one of the largest problems that exist within a SharePoint environment. SharePoint is meant to provide users with large facilities in order to share and work with arbitrary business data, this can sometimes lead to users sharing information that should otherwise not be shared.
A major method to procure added assurance that will help to eliminate intentional and/or accidental redistribution of sensitive or classified business information is to persistently protect the business data under multiple circumstances, across multiple environments.
A common incident is when someone sends a piece of confidential information to the wrong person, through a mistake of choosing out of an address book or something similar. These situations are commonplace within an environment that builds out virtual teams focused on collaboration, when sensitive information in business information stored in such mediums such as Microsoft Office documents is easily shared accidentally or intentionally for whatever reason.
These types of information leaks can be costly because of:
- loss of revenue
- competitive advantage
- customer confidence
MOSS is tailored to controls access to various documentation, following usage once the document has been downloaded. For an organization that has to adhere to certain legal / business requirements, this can be an invaluable piece of functionality.
What is Information Rights Management and What Can It Protect?
Information Rights Management (IRM) is a component of the Microsoft Office SharePoint Server and Microsoft Office product suite. Although its base technology derives from Windows Right Management, it has heavy ties into the Microsoft Office product suite, and has direct hooks into the Microsoft Office SharePoint Server system. IRM allows document authors to specify who can read their document, what they are able to do with the document, and when they are able to do it. IRM can be applied to Outlook e-mails, Word documents, Excel spreadsheets, and PowerPoint presentations (along with others which implement a customized “protector”). While the Microsoft Office SharePoint Server environment is meant to promote collaboration of documents between virtual teams, IRM will provide offline methods of working with the arbitrary office documents.
Some of the key features that one should look to implement in an offline protection implementation is:
- Implement A Protection Scheme That Travels With An Arbitrary File
- Protection that exists at the file level
- Protection that will bind and travel with the file, wherever the file goes
- Controls Access To The Document, and How the Document Can be Used
- Leverages encryption methods that controls usage
- Implements usage policies bound to the document that translate to the native client application
- Expire relevant content when it is deemed no longer necessary
- The Protection System Should Be Easy For End Users
- Easy for clients to implement protection for business data
- Tightly integrated with Microsoft Office clients that in turn are relevant to SharePoint
- Policies That Are Managed By The Enterprise
- Permission Policies that are organizational consistent
- One organizational owns overall access
In a typical SharePoint environment, documents are controlled at a very granular level when stored at the web level, however once a client gets the chance to download the arbitrary document, the overall permission levels are lost. MOSS and IRM work together in order to translate roles on the SharePoint server, to permission levels as they are specified within IRM.
If a SharePoint environment if there is no IRM functionality implemented, documents circulated electronically are uncontrolled and can be printed, copied, and forwarded feasibly to anyone. Transmission of e-mails and documents over secure networks may protect the information in transit, but offer no control over what the recipients do with the information. Password security protection for documents can easily be circumvented if the password is also provided.
IRM can be used to prevent the printing or forwarding of e-mails and to make them inaccessible to the recipient after a specified expiry date. IRM can make documents unreadable by anyone other than the specified recipients.
Integration of SharePoint with information rights management enables content sharing with the confidence that information-use policies travel persistently with the content no matter where it goes. |