Chat now with support
Chat with Support

Metalogix ControlPoint 8.5 - User Guide

Preface Getting Started with ControlPoint Using Discovery to Collect Information for the ControlPoint Database Cache Using ControlPoint Dashboards Searching for SharePoint Sites Managing SharePoint Objects Using ControlPoint Policies to Control Your SharePoint Environment Managing SharePoint User Permissions Data Analysis and Reporting
Specifying Parameters for Your Analysis Analysis Results Display Generating a SharePoint Summary Report Analyzing Activity Analyzing Object Properties Analyzing Storage Analyzing Content Generating a SharePoint Hierarchy Report Analyzing Trends Auditing Activities and Changes in Your SharePoint Environment Analyzing SharePoint Alerts Analyzing ControlPoint Policies Analyzing Users and Permissions The ControlPoint Task Audit Viewing Logged Errors
Scheduling a ControlPoint Operation Saving, Modifying and Running Instructions for a ControlPoint Operation Using the ControlPoint Governance Policy Manager Using Sensitive Content Manager to Analyze SharePoint Content for Compliance Using ControlPoint Sentinel to Detect Anomalous Activity Default Menu Options for ControlPoint Users About Us

Managing Quarantined Files

If you are a member of the ControlPoint Quarantine Administrators group, you can manage files that have been quarantined as a result of a Compliance Action.  When  a file is quarantined, it remains in the same location in the SharePoint list, but all permissions—except those of ControlPoint Quarantine Administrators—are removed.

Currently, members of the Quarantine Administrators group must

§be a Site Collection Administrator for each site collection containing quarantined content  (in order to invoke the Manage Quarantine Files page from the SharePoint Hierarchy)

OR

§also be a member of the Compliance Administrators Group.

To manage quarantined files:

1Use the information in the following table to determine the appropriate action to take.

If you are starting from ...

Then ...

the SharePoint Hierarchy

a)Select the object(s) containing the quarantined files you want to manage.

b)Choose Compliance > Manage Quarantined Files.

the Compliance Summary page

a)Make sure the Compliance Action jobs radio button is selected.

b)Select the Scan job containing the quarantined files you want to manage.

c)Click [Manage Quarantined Files].

Manage Quarantined Items

Manage Quarantined Files

2Select the quarantined file(s) you want to act on.

3If you want to review the content of a quarantined file before taking an action, click the Document link in the View column.

Now you can either:

·remove file from quarantine

NOTE:  When you remove a file from quarantine, it is restored in its original location with the same permissions it had before it was quarantined.

 

IMPORTANT:  You cannot remove an attachment from quarantine without also removing its parent item.

OR

·permanently remove the file(s) from SharePoint.

Managing Scanned Files

Use the Manage Scanned Files operation to review and act on files that have been scanned for compliance.  You can:

·apply filters to further refine the results that display in the grid

·choose to "ignore" (that is, hide from the grid) files that do not require review or action

·link to individual files to review their content

·remove files from SharePoint.

To manage scanned documents:

1.In the SharePoint Hierarchy, select the object(s) containing scanned documents that you want to review/act on.

2.Right-click and choose Compliance > Manage Scanned Files.

Manage Scanned Files

3.To filter items that display in the grid:

·Enter a full or partial file name in the File Name Contains field, and/or select specific Search Terms from the drop-down.

Manage Scanned Files FILTERS

·If you want to Include Ignored Files and/or Include Quarantined Files (which are hidden by default), check the applicable box(es).

REMINDER:  "Ignore" is a status that you can apply to files that you do not want to display in the grid by default (because, for example, they do not require further review or action).

·Click [Apply Filters].

Note that if you chose to include Ignored or Quarantined files, they will be labeled as such in the Status field.

TIP:  If you want to review quarantined and/or Ignored files specifically, sort on the Status column to group these files together.

Manage Scanned Files RESULTS

Now you can:

·open a file whose contents you want to review (by clicking the File Path link)

Manage Scanned Files LINK

AND/OR

·select files on which you want to perform an action, then click the appropriate action button: [Remove from SharePoint], [Ignore], [Unignore].

Note that when a file is removed from SharePoint it no longer displays in the grid.

Removing Scanned Files from SharePoint

If you attempt to remove one or more files from SharePoint, you will be prompted to confirm your selection.  Unlike the Sensitive Content Submission Maintenance feature, you can remove individual files which has been quarantined.

If you delete an item that has attachments, the attachments will automatically be deleted along with the item.

Analyzing Scanned Files

The Scanned Files by Search Term and Scanned Files by Scope analyses let you view all of the files that have been analyzed by SCM for sensitive content over a specified date range.

To generate a Scanned Files analysis:

1Select the object(s) you want to include in your analysis.

2Select the appropriate option, based on how you would like to have results grouped:

§Compliance > Scanned files by Scope

OR

§Compliance >Scanned files by Search terms.

3Specify the parameters for your analysis.

IMPORTANT:  

§Currently, you can only Filter by Search Terms if you enter one complete search term (that is, you cannot filter by multiple or partial search terms).

Filter by Search Term

If you leave the Filter by Search Terms field blank, all search terms within the scope of your analysis will be included.

4Under Advanced Parameters:

Manage Scanned Files ADVANCED PARAMETERS

·If you leave the Start Date and End Date blank (the default), the most recent scan performed on each scanned file will be included in analysis results.  If you enter a Start Date and End Date, results will include all scans performed within the date range.

·If you want to run the analysis on scans for which the permissions of users who performed the scans were collected since the last run of Discovery, check the Security trimming using cached permissions box. If you leave this box unchecked, the analysis will be run using real-time permissions, but processing time my increase significantly.

Now you can:

·run the operation immediately (by clicking the [Run Now] button)

OR

·schedule the operation to run at a later time or on a recurring basis.

OR

·save the operation as XML Instructions that can be run at a later time.

Results are grouped either by scope or search term (depending on the analysis selected).

Scanned Files by Scope

Scanned Files by Search Terms

 

Reporting on Sensitive Content Activity

If you are a member of the ControlPoint Compliance Administrators group, you can use the ControlPoint Sensitive Document Activity report to view detailed information about documents analyzed by Sensitive Content Manager that:

·have been identified as "sensitive content" (that is, have been assigned a Severity Level)

AND

·have been accessed by at least one SharePoint user.

NOTE:  This report includes sensitive content identified both from realtime scans and as a result of the enforcement of ControlPoint Policies.

Before you can report sensitive document activity:

·Auditing must be enabled for each list or library for which you want to report sensitive document activity.  You can enable these settings for individual site collections from within SharePoint or, for a larger scope, using the ControlPoint Manage Audit Settings action.

·At least one Compliance scan must have been returned by Sensitive Content Manager with items that have been assigned a Severity Level.

To report sensitive document activity:

1Select the object(s) for which you want to report sensitive document activity.

2Choose Compliance > Sensitive Document Activity.

Sensitive Document Activity Report

The tiles at the top of the report highlight the following statistics for the selected time period (by default, the past month):

·Total Number of SCM (Sensitive Content  Manager) Classified Documents

·Sensitive Documents Accessed (that is, the number of times a document identified as having sensitive content has been accessed by a SharePoint user)

NOTE:  The number of times the System Account has modified the Scan Results field for the item on the SharePoint list will be included in this value unless the Sensitive Content Manager Configuration Setting Add Scan Results Column to Scanned SharePoint List is set to false.  Details can be found in the ControlPoint Administration Guide.

·Users Accessing Sensitive Documents (that is, the number of unique SharePoint users who have accessed documents identified as containing sensitive content)

·Realtime Scanning (that is, the number of days since the last realtime scan was performed)

To filter results that display in the body of the report:

1.Choose a different severity level from the Filter drop-down and/or modify the default date range.

Sensitive Document Activity FILTERS

2.Click [Refresh].

Graph Tab

The Sensitive Document Activity report Graph tab illustrates the Activity Count by Sensitivity for the selected Severity Level(s) and date range.

Note that you can click a Severity Level in the legend at the right side of the page to hide/display it.

Sensitive Document Activity GRAPH 2

Files Tab

The Sensitive Document Activity report Files tab lists all of the documents the Content Sensitive Manager identified as "sensitive content" for the selected Severity Level(s), grouped by list or library.

Note that this tab displays all content sensitive classified documents for the selected Severity Level(s), regardless of whether they have been accessed, and the date range filter does not apply.

Sensitive document Activity FILES

Users Tab

The Users tab lists the SharePoint users who have accessed documents with sensitive content within the specified time period, along with the Number of Docs Accessed.

Activity Tab

The Activity tab lists each individual instance of sensitive content activity, including the User Name. Activity Type, document Severity Level and Activity Date.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating