Skip to main content

SharePoint Security Configuration Review

Updated over 5 months ago

Service Overview

SharePoint is a web-based collaboration and document management platform developed by Microsoft. The SharePoint Security Configuration Review is an evaluation of the security posture of a SharePoint environment. The goal of the review is to identify potential threats, risks, and weaknesses in the SharePoint system.


Methodology

CYE performs a thorough examination of the SharePoint environment’s business functionality and general design concept. CYE evaluates configuration settings, access controls, user permissions, authentication methods, and software integrations.

The review is conducted by a senior cyber architect using a white-box approach, with full access to the system granted for analysis.

CYE provides a detailed report outlining the identified findings and their corresponding recommendations and the remediation steps required to improve the security of the SharePoint environment.


Deliverables

  • All discovered findings are shown in Hyver, CYE’s Continuous Threat Exposure Management (CTEM) platform

  • A maturity level representing the organization’s security posture is determined

  • The maturity level is derived using the NIST Cybersecurity Framework and based on the findings and insights gathered during the review


Prerequisites

Access to the following is required:

  • SharePoint Administrator or an equivalent role with read permissions

  • Relevant internal policies


Customer Engagement

  • A point of contact for SharePoint administration should be available during the engagement to support access and answer environment-specific questions


Relevant Standards

The assessment methodology is based on:

  • NIST Cybersecurity Framework


Security Domains Covered

  • Cross-organization policies, procedures, and governance

  • Identity management and remote access

  • Sensitive data and information management

Did this answer your question?