File access auditing for ISO 27001 compliance
- Cleaver Fulton Rankin
- Legal
- United Kingdom
)
As law can apply to virtually any area of our professional lives, those working in the corporate legal profession such as Cleaver Fulton Rankin have perhaps access to a broader array of sensitive information than any other sector. From intellectual property, to the finer points of a company merger, through to sensitive financial information.
As one of Northern Ireland’s leading corporate law firms, the importance of integrity and reputation rests on their ability to protect this sensitive information. The certification of compliance to ISO 27001 is a powerful indication to customers that it takes security seriously.
"FileAudit satisfies the need for an audit trail for ISO 27001 very easily. Simple reports bring it all together for me and alerts show auditors that we can control access into the most sensitive folders."
Paul Rickerby - IT Manager at Cleaver Fulton Rankin
At the core of the ISO 27001 compliance mandate is the desire to keep sensitive data secure, only allowing access to those who need it for business reasons. To both know and demonstrate that this is the case requires visibility into who has access, who is using access, and what actions are being taken upon this protected data.
Cleaver Fulton therefore needed a granular and detailed audit trail that they could present to any auditors to demonstrate proper access controls were in place to protect sensitive information against unwanted access.
"We were previously limited to the data found in Windows Security Event logs. It was an awfully large lump of data that took hours to dig through to find or report on anything of value."
Paul Rickerby - IT Manager
Paul wanted a solution that could make it easier to monitor and record all file access and also be alerted to potentially suspicious behavior.
Paul was looking for an intuitive third-party solution to provide the centralized monitoring and reporting of all file activity needed.
- Real-time logging of all access and access attempts to files and folders across the Windows system. 
- All audit log data needed to be easily accessible to be reviewed, filtered, searched etc. 
- Automatic alerts based on matching criteria to actions deemed suspicious, or any access to certain highly sensitive folders and files. 
- Ability to generate sharable reports that showed a granular and detailed audit trail. 
On testing FileAudit, the installation and configuration of the software took about 15 minutes.
In many cases, compliance requirements establish the security objective, and then provide details on how to test that the objective is being met. File auditing is your testing method to ensure the security you think you have around your protected data is actually doing its job.
Having FileAudit in place has helped Cleaver Fulton reach required appendices for the ISO standards.
FileAudit is used to demonstrate only approved access has occurred. Alerting and reporting can provide both real-time and historical detail, including identifiable factors like machine name, IP address, etc. Robust filtering capabilities help quickly answer questions auditors' questions.
FileAudit shows key insights on access to and usage of a particular data set.
The need to have access to and usage of sensitive data under close watch is critical to meeting these compliance objectives.
"It satisfies the need for an access audit trail for ISO 27001 very easily. Simple reports bring it all together for me and alerts show auditors that we can control access into the most sensitive folders. I would recommend FileAudit for compliance needs and better visibility on what’s going on your file servers."
Paul Rickerby - IT Manager
To learn more about how file auditing helps meet compliance objectives, read the whitepaper The Role of File Auditing in Compliance.
)
)
)