Service Overview
Sensitive Data Discovery Assessment involves a comprehensive enumeration of the organization’s data storage platforms. The goal is to provide insight into the current state of sensitive data management by identifying accessible data across the following environments:
OneDrive
SharePoint
Network shares
NAS devices
Employee workstations
Methodology
Using in-house tools and techniques, CYE team conducts keyword-based searches to locate and analyze sensitive data across accessible locations.
The activity can be executed using either:
A standard domain user account to explore authorization and data disclosure risks
A privileged domain user account to identify unprotected sensitive data
Deliverables
All discovered findings are shown in Hyver, CYE’s Continuous Threat Exposure Management (CTEM) platform
A comprehensive report detailing accessible data across each reviewed platform
Prerequisites
A domain-joined endpoint and domain-joined user account
Privileged network access to AD-connected devices
A list of organization-specific keywords to support targeted data probing and analysis
Customer Engagement
A point of contact from the organization might be required to support the assessment process, with expected involvement of no more than one hour per week.
Relevant Standards
The proprietary methodology is based on the following standards:
NIST Cybersecurity Framework
ISO/IEC 27001
ISO/IEC 27002
Security Domains Covered
Cross-organization policies, procedures, and governance
Sensitive data and information management
Identity management and remote access
