Skip to main content

Pro audit program · v1.0

File Share Permissions Audit

NTFS / SharePoint / Drive permissions silently drift over years. A focused audit on excess access, group cleanliness, owners and stale data.

  • General target area
  • CIS Controls framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

NTFS / SharePoint / Drive permissions silently drift over years. A focused audit on excess access, group cleanliness, owners and stale data.

Controls (6)

  1. No "Everyone" or open ACLs on shared paths

    Critical

    This control prohibits the use of open access control lists (ACLs) that grant permissions to overly broad groups such as 'Everyone', 'Authenticated Users', 'Domain Users', or anonymous access on shared network paths, file shares, and directories. Organizations must restrict share-level…

    How to test + evidence

    Testing procedure: Scan tool reports paths with overly permissive ACLs; spot-check 10.

    Evidence to collect: Scan output + ACL exports.

  2. Folder owner assigned + reviewed annually

    High

    This control mandates that every shared folder within the organization's file storage systems (network shares, cloud storage, document repositories) must have a designated owner responsible for managing access permissions, content integrity, and lifecycle. Ownership assignments must be documented in an…

    How to test + evidence

    Testing procedure: Top-level folders have a named owner accountable for access.

    Evidence to collect: Owner register.

  3. Permissions inherited from groups, not users

    High

    This control requires that access permissions to systems, applications, and data resources be assigned through group membership rather than directly to individual user accounts. When a user requires access, they are added to a group with the appropriate permissions rather…

    How to test + evidence

    Testing procedure: Explicit user ACLs are exceptions, not the norm.

    Evidence to collect: Scan output.

  4. Sensitive folders auditing on

    High

    This control requires that file system auditing is enabled on folders containing sensitive data such as customer records, financial documents, intellectual property, regulated data (PII, PHI, payment card data), or confidential business information. Auditing captures access events including read, write,…

    How to test + evidence

    Testing procedure: Object access auditing on critical paths; events forwarded to SIEM.

    Evidence to collect: Audit policy + SIEM source.

  5. Stale folders archived

    Low

    This control ensures that file system folders and directories containing inactive or unused data are identified based on defined retention criteria and systematically archived or removed from active storage. Organizations establish policies defining staleness thresholds (e.g., no file modifications in…

    How to test + evidence

    Testing procedure: Folders untouched >2 years flagged for archive / delete.

    Evidence to collect: Aging report.