Sensitive Folder Security - Best Practice



I work for a compagny of 800 users.

We used to have 348 shares containing departmental data. No need to
say it was hell to manage rights and especially login scripts.

I've done a big clean-up and managed to bring everything into 1 share
and give specific ntfs rights to each departments, ie.: accounting, hr,
sales, etc. I'm mapping that drive to everyone in the company and
everyone has the "List" right at the root folder to see every
department name.

I'm also wrapping my permission in global security groups. IE.:
Security_Production_Read group has list permission on the root folder
and read permission on the Production folder. This way, admins don't
have to log on the server to give permission to a department folder to
a user.

Ex:
\\Server\Departments$\Accounting
\\Server\Departments$\Human Resources
\\Server\Departments$\Production

When I told the HR Director I wanted to move his data in the a share
that everyone in the compagny sees, he really didn't like that idea.
He's afraid that if a mistake is made assigning rights, it could go
unoticed and his data would be compromised.

So my question really is, Is it an acceptable security practice to map
a drive containing folders with sensitive data to all the company if
access to the sensitive folders is controlled with NTFS permissions.

Thanks for your input.

.



Relevant Pages

  • Re: Access Denied errors on Upload in Document library
    ... be a better description) he can specify different access rights for folders. ... to access a doc lib can not have rights to access a folder (see earlier ... cosmetic purposes and don't come with the functionality that libraries ... permissions on the Document Library, When I grant full permission to ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Samba with Windows XP client
    ... I must admit I don't understand the Windows XP Pro permission setup; ... sure your account has administrative rights. ... Doesn't the fact that I can browse through a folder on the Windows machine ...
    (Fedora)
  • Re: Question on permission of document library folders
    ... Here you have that the Group has more limited rights at the Document Library level than it has at the Folder Level. ... What I think you need to do is have Group1A and Group1B. ... I've a question on permission of document library folders. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Propagating folder rights in Windows 2003 server...
    ... with full access and gave the Everyone group "List Folder Contents" ... rights. ... propagating them down within the local branches sub-folders. ... "Replace permission entries on all child objects..." ...
    (microsoft.public.windows.server.general)
  • Re: Network shares cannot connect
    ... Changed value to 0 just waiting to re-boot the server and test logins. ... Workstation Name: - ... let's focus on the Users Shared Folder first. ... To check this permission, please click the Advanced button, select ...
    (microsoft.public.windows.server.sbs)